Security Engineer
Sr. Manager, Security Compliance & Certification Program
Budapest
Apply on the employer's siteRole description
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
We are seeking a high-agency, strategic Senior Manager to serve as the enterprise execution lead for our security compliance and certification portfolio. This role directly supports our global assurance programs, focusing on translating complex regulatory requirements (NIS2, ISO/IEC 27001, EU CRA, and customer-driven mandates) into seamless enterprise execution.
You will work across product security, IT, engineering, and legal disciplines to build a continuously audit-ready organization. Your core objective is translating baseline regulatory interpretations into actionable, automated, and defensible engineering reality.
Job Responsibilities
- Portfolio Architecture: Direct the execution of a multi-framework security compliance portfolio. Engineer end-to-end operational traceability linking regulatory obligations directly to technical controls and automated systems.
- Operational Execution: Co-own the operationalization of compliance mandates with central GRC and Legal leadership. Translate legal interpretations into actionable engineering deliverables and actively manage cross-functional dependencies.
- Risk Escalation Governance: Govern the identification, quantification, and remediation tracking of compliance risks. Wield the authority to enforce SLAs and escalate material blockers directly to executive leadership.
- Audit Command Quality: Enforce stringent quality standards for technical system descriptions and continuous evidence generation. Command external audit operations to maintain a continuously audit-ready posture.
- Team Leadership: Manage, mentor, and scale a high-performing compliance team. Define clear accountability matrices, allocate workload dynamically, and establish rigorous execution standards.
Minimum Requirements
- Education: BSc/MSc in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline.
- Experience: 10+ years of progressive leadership experience in cybersecurity, enterprise risk, compliance, product security, or technical assurance domains.
- Portfolio Capability: Senior-level ability to architect and deliver multi-initiative compliance portfolios within highly regulated, certification-driven environments.
- Audit Leadership: Verifiable track record of commanding external audits, driving regulatory compliance initiatives, and successfully closing technical control gaps.
- People Management: Demonstrated team leadership expertise, characterized by high-agency decision-making, strict prioritization, and precise escalation judgment.
- Executive Communication: Elite written and verbal communication skills. Capable of synthesizing complex regulatory risks into executive-level briefings, telemetry dashboards, and decision frameworks.
Preferred Requirements
- Professional Certifications: Active credentials such as CISSP, CISM, CISA, PMP, or ISO/IEC 27001 Lead Implementer.
- Regulatory Specialization: Deep operational understanding of software security requirements, secure SDLC, vulnerability disclosure programs, and emerging global mandates (specifically EU Cyber Resilience Act).
- Operational Flexibility: Availability to support critical audit cycles and off-hours engagement, with occasional travel for on-site assessments and executive stakeholder alignment.
What Lenovo Can Offer You
- An open and stimulating environment within one of the most forward thinking IT companies
- Hybrid working model (3:2)
- Flat structures and fast decision-making processes
- A modern and flexible way of working to combine personal and professional life
- An international team with a high focus on Diversity Inclusion
- Attractive compensation package
The anticipated initial gross base monthly salary range for this position in Slovakia is 4,860 EUR – 7,140 EUR, depending on experience.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.