Lenovo
Product Security Engineer – PSIRT
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Lenovo
Lenovo is a multinational technology company founded in 1984 in Beijing, China. Originally named "Legend,"it started with a focus on IT product distribution and has grown to become the world's largest PC manufacturer. The company offers a wide range of products, including desktop computers, laptops, smartphones, tablets, servers, storage devices, printers, scanners, and televisions. Lenovo is known for its ThinkPad and IdeaPad laptop lines, which are recognized for their innovation and reliability. The company also provides enterprise solutions, including servers and networking products, and is involved in emerging technologies like augmented reality and artificial intelligence. With a presence in over 60 countries and products sold in more than 160 countries, Lenovo serves a diverse customer base that includes individual consumers, small and medium businesses, large enterprises, and government organizations. The company emphasizes sustainability and innovation in its mission.
Security at Lenovo
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Lenovo's AppSec philosophy centers on product security as a top priority, driven by a "Security by Design"approach.
- This includes software testing and approval by a Software Security Review Board (SSRB) before integration, ensuring security is "built into our products, not 'bolted on'."The Product Security Program aims to embed security from the start, supported by an ethical hacking program to identify potential customer issues.
Security Team
- Doug Fisher serves as Senior Vice President & Chief Security and AI Officer at Lenovo, reporting to the CEO.
- Publicly available information does not explicitly detail the AppSec team's specific organizational structure (e.g., centralized or embedded) or its reporting lines beyond the executive security leadership.
Key Initiatives
Lenovo maintains a public policy for receiving and handling security vulnerability reports, directing them to the Lenovo Security Response Center. However, public sources do not provide explicit details on a Security Champions program, its structure, or responsibilities. Similarly, specific AppSec vulnerability triage SLAs, MTTR targets, ticketing ownership, or recent AppSec-specific initiatives (within the last six months) are not publicly available.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.