Job
Description
As a member of the Lenovo team, you will play a crucial role in ensuring the security of Lenovo- and third party-developed software by working closely with software designers, developers, project managers, and testers. Your responsibilities will include reviewing, recommending changes, and providing solutions to address software security issues. You will act as a trusted advisor to product development and engineering teams, offering guidance on secure application design, development, and validation. In this role, you will define security requirements for Lenovo and third-party development teams, as well as identify and evaluate tools and processes to ensure security reviews are conducted effectively. Additionally, you will serve as a Secure Development Lifecycle evangelist, guiding and training development teams on secure development practices within the SSG. Your duties will also involve conducting product and service security assessments, analyzing weaknesses, formulating mitigation measures, documenting findings, and collaborating with global product and services teams to implement corrective actions. You will be responsible for identifying root causes of recurring issues, assessing risks, and prioritizing mitigation activities. As a security subject matter expert and technical leader, you will support internal and external product and services teams, suppliers, partners, security researchers, and business leaders. You will stay updated on threats, vulnerabilities, attack techniques, tools, and industry trends, while also customizing tools and procedures to enhance security assessment effectiveness. Your role will involve mentoring and collaborating with other security test engineers, supporting secure development lifecycle initiatives, and utilizing various security assessment tools. You will need to demonstrate expertise in technical security assessments, security foundations, networking protocols, security standards, and programming or scripting skills. Preferred skills and experience include performing code reviews, working with geo-diverse teams, technical consulting background, knowledge of Lenovo products and services, and security certifications such as CISSP, CSSLP, CEH, OSCP, or similar. Key personal traits for success in this role include being self-motivated, results-driven, a strong technical leader, critical thinker, problem solver, good communicator, and adept at multi-tasking in a high-pressure environment. Lenovo follows strict policies and legal compliance in the recruitment process, including role alignment, employment terms discussion, final selection, and offer approval. Interviews may be conducted via audio, video, or in-person, and it is important to verify job offers through the official Lenovo careers page or contact IndiaTA@lenovo.com to protect yourself from recruitment fraud. Stay informed and cautious, and report any suspicious activity to local authorities.,