We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Product Supply Chain Security Auditor

Lenovo
United States, North Carolina, Morrisville
Aug 06, 2026


General Information
Req #
WD00102309
Career area:
Hardware Engineering
Country/Region:
United States of America
State:
North Carolina
City:
Morrisville
Date:
Thursday, August 6, 2026
Working time:
Full-time
Additional Locations:
* United States of America - North Carolina - Morrisville

Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

Description and Requirements
The Product Supply Chain Security Auditor is responsible for assessing, monitoring, and improving supplier security practices throughout the product supply chain. This role supports the Trusted Supplier Program (TSP) by conducting supplier security audits, evaluating cybersecurity risks, reviewing remediation activities, and ensuring compliance with industry security standards. The ideal candidate combines cybersecurity expertise, audit experience, and strong stakeholder management skills to help strengthen supplier security governance and reduce supply chain risk.
Key Responsibilities:
  • Conduct supplier security audits and reassessments under the Trusted Supplier Program (TSP).
  • Review supplier audit questionnaires, supporting documentation, and audit evidence.
  • Identify, classify, and document audit findings, including observations, recommendations, and non-conformities.
  • Track supplier corrective action plans and validate remediation evidence through closure.
  • Support supplier re-evaluations and maintain accurate audit records and documentation.
  • Monitor supplier security incidents, vulnerability disclosures, regulatory changes, and industry security alerts.
  • Prepare audit reports, risk assessments, evidence packages, executive summaries, and management updates.
  • Collaborate with Procurement, Product, Legal, Business, and Security teams to enhance supplier security governance and risk management practices.
  • Evaluate component-level security risks and provide support to the Product Security Incident Response Team (PSIRT).
Basic Qualifications:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
  • 3 to 5 years of experience in one or more of the following areas: Cybersecurity, Third-party risk management, Security auditing, Product security, Supply chain security
Preferred Qualifications:
  • Strong understanding of: PC architecture and IT systems, Security auditing methodologies, Third-party risk assessments, Evidence review and validation, Vulnerability management, Remediation tracking and verification
  • Knowledge of industry standards and frameworks such as: ISO/IEC 27001, ISO/IEC 27036, ISO 20243 (Open Trusted Technology Provider Standard), NIST SP 800-161
  • Ability to analyze technical findings and translate them into clear, risk-based conclusions and actionable remediation recommendations.
  • Strong project management, documentation, communication, and stakeholder management skills.
  • Ability to work independently and collaborate effectively with global cross-functional teams in a fast-paced environment.
  • Master's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
  • Experience supporting supplier assurance programs, product security initiatives, or supply chain risk management activities.
  • Experience working with global suppliers and cross-functional business stakeholders.
  • Professional certifications such as: CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), ISO/IEC 27001 Lead Auditor
  • Familiarity with product security incident response processes and vulnerability disclosure programs.
  • Advanced knowledge of cybersecurity governance, compliance, audit reporting, and risk management best practices.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
Additional Locations:
* United States of America - North Carolina - Morrisville
* United States of America
* United States of America - North Carolina
* United States of America - North Carolina - Morrisville

Applied = 0

(web-77cf7d65c7-zl2tx)