Why Work at Lenovo
Description and Requirements
Lenovo is looking for a Senior Product Security Engineer to join our PCSD Product Security team. In this role, you will help drive the secure design, development, and operation of Lenovo's cloud-based products and SaaS offerings, working closely with global Engineering and Product teams.
This position combines Cloud Security, Application Security, DevSecOps, and Secure Architecture, helping ensure security is embedded throughout the entire software development lifecycle.
What you'll do
- Assess and improve the security posture of cloud-based products, applications, APIs, and architectures.
- Perform threat modeling and security design reviews for cloud and SaaS solutions.
- Evaluate authentication, authorization, encryption, and secure communication mechanisms.
- Support and enhance DevSecOps practices and CI/CD security implementations.
- Define and implement cloud security controls including IAM, encryption, logging, monitoring, and incident response.
- Partner with Engineering and Product teams to drive Secure-by-Design and Security-by-Default practices.
- Conduct application security reviews and identify potential security weaknesses before production release.
- Contribute to cloud and product security strategy, training, tooling, and awareness initiatives.
What we're looking for
- 3+ years of experience in Product Security, Application Security, Cloud Security, or DevSecOps.
- Hands-on experience securing cloud environments such as AWS and/or Azure.
- Strong understanding of Secure SDLC, SaaS security, threat modeling, and secure architecture principles.
- Knowledge of authentication and authorization technologies such as OAuth, OpenID Connect, SAML, JWT, and modern identity systems.
- Working knowledge of encryption, PKI, TLS, certificates, and secure communication protocols.
- Familiarity with OWASP principles and common application security risks.
- Strong collaboration, communication, and stakeholder management skills.
- Advanced English is required.
Nice to have
- Experience with SAST, DAST, IAST, SCA, and other DevSecOps security tools.
- Container and Kubernetes security.
- Infrastructure as Code security (Terraform, CloudFormation, Ansible).
- Security certifications such as CISSP, CCSP, CCSK, CSSLP, or Security+.
- Knowledge of GDPR, LGPD, and global privacy regulations.
Work arrangement: Hybrid model with in-office attendance 3 times a week.
Diversity & Inclusion: We are an equal opportunity employer and do not discriminate against any employee or job applicant on the basis of race, color, sex, age, national origin, religion, sexual orientation, gender identity, veteran status, disability, or any other class protected by federal, state, or local law.