We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Manager, Security Risk Controls

Lenovo
Jul 24, 2026


General Information
Req #
WD00102879
Career area:
Information Technology
Country/Region:
United States of America
State:
North Carolina
City:
Morrisville
Date:
Thursday, July 23, 2026
Working time:
Full-time
Additional Locations:
* United States of America - North Carolina - Morrisville

Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

Description and Requirements

The Manager, Security Controls Management is responsible for the execution, governance, assurance, and continuous improvement of the enterprise security controls program. This role serves as the process owner for security controls, ensuring controls are defined, documented, implemented, measured, and maintained consistently across the organization.

Operating as an individual contributor and process leader, this role partners closely with Security, Risk, Compliance, Internal Audit, Privacy, and business stakeholders to drive effective control management practices. The Manager is accountable for the health and maturity of the security controls program, including control lifecycle management, control effectiveness validation, issue remediation tracking, and audit readiness.

This position does not have direct people management responsibilities but requires strong leadership through influence, coordination, and stakeholder engagement across multiple functions.

Key Responsibilities:

Security Controls Governance & Management

  • Own and manage the lifecycle of security controls, including control definition, implementation, maintenance, review, and retirement.
  • Establish and maintain a centralized inventory of security controls and associated control documentation.
  • Ensure security controls remain aligned with corporate security requirements, policies, standards, and regulatory obligations.
  • Define and maintain control ownership, accountability, and governance processes.
  • Drive continuous improvement of the security controls framework and supporting methodologies.
  • Lead continuous improvement initiatives that enhance governance, standardization, reporting, and overall control maturity.

Control Design & Effectiveness

  • Partner with control owners and subject matter experts to establish scalable, risk-based security controls that support evolving business, regulatory, and security requirements.
  • Assess control design and operating effectiveness to ensure intended objectives are achieved.
  • Identify control gaps, weaknesses, and opportunities for improvement.
  • Coordinate periodic control reviews and validation activities.
  • Support development of compensating controls when necessary to address identified risks or operational constraints.

Cross-Functional Coordination

  • Collaborate with various security teams, Risk Management, Compliance, Privacy, and Internal Audit teams to ensure consistent control implementation and operation.
  • Facilitate discussions regarding control ownership, responsibilities, remediation activities, and control performance.
  • Coordinate control-related initiatives across multiple stakeholders and business functions.
  • Drive accountability for completion of control-related deliverables and commitments.
  • Build trusted partnerships across security, compliance, privacy, audit, and business organizations to drive governance, accountability, and successful execution of security assurance activities.

Documentation & Evidence Management

  • Ensure security control documentation is accurate, complete, and maintained within designated systems of record.
  • Maintain traceability between security requirements, controls, procedures, and supporting evidence.
  • Establish documentation standards to support consistency, audit readiness, and operational effectiveness.
  • Validate the quality and completeness of evidence supporting control operation.
  • Support the development and maintenance of control narratives, procedures, standards, and process documentation.
  • Establish documentation and evidence management practices that support repeatable assurance activities and audit readiness.

Issue, Risk & Remediation Management

  • Identify, document, and track control deficiencies, gaps, and improvement opportunities.
  • Partner with stakeholders to develop remediation plans and corrective actions.
  • Monitor remediation progress and escalate issues that may impact control effectiveness or compliance obligations.
  • Assess the potential risk impact associated with identified control weaknesses.
  • Support risk acceptance and exception management processes when applicable.
  • Prioritize remediation efforts based on risk and provide governance oversight to ensure timely resolution of control deficiencies.

Metrics, Reporting & Continuous Improvement

  • Develop and maintain key performance indicators (KPIs) and key risk indicators (KRIs) for the security controls program that measure program health.
  • Establish reporting that provides meaningful visibility into governance assurance, compliance initiatives, remediation progress, and overall program health.
  • Analyze program data and trends to identify improvement opportunities.
  • Provide regular status reporting and executive-level program updates.
  • Drive initiatives that improve efficiency, automation, and overall control maturity.

Assessment Support

  • Support internal and external audits by facilitating evidence collection and validating control documentation.
  • Coordinate responses to assessment findings and recommendations.
  • Maintain the enterprise security assurance posture through ongoing assessment and remediation tracking.
  • Support regulatory, customer, and third-party assessments involving security controls.

Basic Qualifications:

  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Business, Engineering, or a related field.
  • 7+ years of experience in cybersecurity, security governance, risk management, compliance, internal controls, audit, or related disciplines.
  • Demonstrated experience managing security controls, control frameworks, or governance programs.
  • Experience supporting audits, assessments, and remediation activities.
Preferred Qualifications:
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer, or similar.
  • Strong knowledge of cybersecurity controls, governance, and risk management principles.
  • Experience managing security control frameworks and control lifecycle processes.
  • Strong understanding of security standards and frameworks such as ISO 27001, NIST CSF, NIST 800-53, or similar.
  • Ability to assess control design and operating effectiveness.
  • Demonstrated ability to lead enterprise governance and security assurance initiatives through cross-functional collaboration and influence.
  • Strong organizational and program management skills.
  • Experience coordinating cross-functional initiatives in matrixed environments.
  • Strong analytical and problem-solving capabilities.
  • Ability to influence stakeholders and drive accountability without direct authority.
  • Excellent written, verbal, and presentation skills.
  • Experience developing metrics, reporting, and executive-level communications.
  • Limited travel may be required for business, audit, or stakeholder engagements.

The base salary budgeted range for this position is $130k - 150K. Individuals may also be considered for bonus and/or commission.

Lenovo's various benefits can be found on www.lenovobenefits.com.

In compliance with Colorado's EPEWA, the expected application deadline for this position is August 27, 2027. This applies to both external and internal candidates.

#LI-FL1

#LI-Remote

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
Additional Locations:
* United States of America - North Carolina - Morrisville
* United States of America
* United States of America - North Carolina
* United States of America - North Carolina - Morrisville

Applied = 0

(web-77cf7d65c7-wz29x)