Product Supply Chain Security Auditor

Lenovo Group Ltd
  • Morrisville, NC
    4 days ago

    Job Description

    General Information

    Req #

    WD00102309

    Career area:

    Hardware Engineering

    Country/Region:

    United States of America

    State:

    North Carolina

    City:

    Morrisville

    Date:

    Thursday, August 6, 2026

    Working time:

    Full-time

    Additional Locations:

    • United States of America - North Carolina - Morrisville

    Why Work at Lenovo

    We are Lenovo. We do what we say. We own what we do. We WOW our customers.

    Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

    This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

    Description and Requirements

    The Product Supply Chain Security Auditor is responsible for assessing, monitoring, and improving supplier security practices throughout the product supply chain. This role supports the Trusted Supplier Program (TSP) by conducting supplier security audits, evaluating cybersecurity risks, reviewing remediation activities, and ensuring compliance with industry security standards. The ideal candidate combines cybersecurity expertise, audit experience, and strong stakeholder management skills to help strengthen supplier security governance and reduce supply chain risk.

    Key Responsibilities:

    • Conduct supplier security audits and reassessments under the Trusted Supplier Program (TSP).
    • Review supplier audit questionnaires, supporting documentation, and audit evidence.
    • Identify, classify, and document audit findings, including observations, recommendations, and non-conformities.
    • Track supplier corrective action plans and validate remediation evidence through closure.
    • Support supplier re-evaluations and maintain accurate audit records and documentation.
    • Monitor supplier security incidents, vulnerability disclosures, regulatory changes, and industry security alerts.
    • Prepare audit reports, risk assessments, evidence packages, executive summaries, and management updates.
    • Collaborate with Procurement, Product, Legal, Business, and Security teams to enhance supplier security governance and risk management practices.
    • Evaluate component-level security risks and provide support to the Product Security Incident Response Team (PSIRT).

    Basic Qualifications:

    • Bachelor''s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
    • 3 to 5 years of experience in one or more of the following areas: Cybersecurity, Third-party risk management, Security auditing, Product security, Supply chain security

    Preferred Qualifications:

    • Strong understanding of: PC architecture and IT systems, Security auditing methodologies, Third-party risk assessments, Evidence review and validation, Vulnerability management, Remediation tracking and verification
    • Knowledge of industry standards and frameworks such as: ISO/IEC 27001, ISO/IEC 27036, ISO 20243 (Open Trusted Technology Provider Standard), NIST SP 800-161
    • Ability to analyze technical findings and translate them into clear, risk-based conclusions and actionable remediation recommendations.
    • Strong project management, documentation, communication, and stakeholder management skills.
    • Ability to work independently and collaborate effectively with global cross-functional teams in a fast-paced environment.
    • Master''s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
    • Experience supporting supplier assurance programs, product security initiatives, or supply chain risk management activities.
    • Experience working with global suppliers and cross-functional business stakeholders.
    • Professional certifications such as: CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), ISO/IEC 27001 Lead Auditor
    • Familiarity with product security incident response processes and vulnerability disclosure programs.
    • Advanced knowledge of cybersecurity governance, compliance, audit reporting, and risk management best practices.

    We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.

    Additional Locations:

    • United States of America - North Carolina - Morrisville
    • United States of America
    • United States of America - North Carolina
    • United States of America - North Carolina - Morrisville

    Numbers & Facts

    LocationMorrisville, NC

    Skills

    • Artificial Intelligence (AI)unmatched
    • Auditingunmatched
    • Best Practicesunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Computer Softwareunmatched
    • Corrective Actionunmatched
    • Cross-Functionalunmatched
    • Documentationunmatched
    • ISO (International Organization for Standardization)unmatched
    • Incident Responseunmatched
    • Industry Standardsunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Infrastructure Softwareunmatched
    • International Electro-Technical Commission (IEC)unmatched
    • Internet Securityunmatched
    • Legalunmatched
    • Maintain Complianceunmatched
    • Product Programsunmatched
    • Product Supportunmatched
    • Project/Program Managementunmatched
    • Purchasing/Procurementunmatched
    • Record Keepingunmatched
    • Regulationsunmatched
    • Reporting Skillsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Security Analysisunmatched
    • Security Auditingunmatched
    • Security Complianceunmatched
    • Security Monitoringunmatched
    • Smartphonesunmatched
    • Stock Marketunmatched
    • Supply Chainunmatched
    • Supply Chain Managementunmatched
    • Technical Analysisunmatched
    • Technical Deliveryunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vendor/Supplier Evaluationunmatched
    • Vendor/Supplier Planningunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder