General Information

Req #
WD00039266
Career area:
Hardware Engineering
Country/Region:
United States of America
State:
North Carolina
City:
Morrisville
Date:
Tuesday, December 6, 2022
Working time:
Full-time
Additional Locations
* United States of America - North Carolina - Morrisville - Mobile

Why Work at Lenovo

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US$62 billion revenue global technology powerhouse, ranked #217 in the Fortune Global 500, employing 77,000 people around the world, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver smarter technology for all, Lenovo has built on its success as the world’s largest PC company by further expanding into growth areas that fuel the advancement of ‘New IT’ technologies (client, edge, cloud, network, and intelligence) including server, storage, mobile, software, solutions, and services.

This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

Description and Requirements

Product Security Analyst – ISG Product Security Office

Lenovo Infrastructure Solutions Group’s (ISG) Product Security Office is seeking a Product Security Analyst to support Lenovo ISG’s Secure Development Lifecycle activities and related processes for maintaining a high-level of security in the products and services we sell to our customers.  This position will join an established team of security architects, penetration testers, and security analysts in securing an expanding product and services portfolio and supporting the business’ evolving security needs.

This is a dynamic product security role, with the successful candidate having a solid security knowledge base to draw from; the ability to multi-task across several projects concurrently, adapt, and develop deeper expertise as needed; and be comfortable taking ownership of projects to ensure effective delivery.

Representative responsibilities:

         Analyzing industry standards, guidance, legislation, etc. for applicability, to identify gaps, and to recommend actions and solutions

         Supporting Software and Hardware Bill of Materials (SBOM and HBOM) activities

         Analyzing security weaknesses to identify patterns and root causes, then develop security guidance to address root causes

         Assessing products for compliance with security requirements

         Creating security guidance, compliance, and standards documentation

         Supporting product vulnerability management activities

         Supporting product security certification activities

         Supporting secure development lifecycle initiatives

Position Requirements

Basic Qualifications:

         Three-plus (3+) years of experience in one or more of the following areas: application security, hardware security, system security, security compliance, and/or secure development lifecycles

         Knowledge of secure software development fundamentals

         Experience with analyzing and developing security requirements

         Experience with industry and government security standards and compliance, ideally including one or more of the following: ISO 27000-series, NIST Risk Management Framework (RMF), FISMA, FedRAMP, NIST SP800-series, NIST Cybersecurity Framework, NIST Secure Software Development Framework, Building Security In Maturity Model (BSIMM), PCI-DSS, O-TTPS / ISO 20243, or similar

         Experience in vulnerability management and triage

Key Personal Traits:

         Team player and a self-starter

         Critical thinking, analytical ability, and problem solving

         Strong verbal and written communication skills

 

Education and Certification Requirements:

         BS in Information Security, Cybersecurity, Management Information Systems, or related degree

         Non-BS degree candidates with additional years of relevant work experience

         Security certification preferred, such as CompTIA Security+, SANS GSEC, or Associate of (ISC)2

Travel:

         5% (travel typically not needed, but possible on occasion post-COVID)

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
* United States of America
North Carolina

Additional Locations
* United States of America - North Carolina - Morrisville - Mobile
* United States of America - North Carolina - Morrisville - Mobile
* United States of America - North Carolina
* United States of America