L

(LPS) Senior Cybersecurity Consultant

Lenovo Hong Kong, Hong Kong Island, Hong Kong S.A.R.

IT Services and IT Consulting · 10,001+ employees

8 h ago
security Senior (5-10 yrs) Full-time Hong Kong S.A.R.
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The consultant will conduct comprehensive risk and control assessments, penetration testing, and red/purple team operations to identify and mitigate security vulnerabilities. They will also facilitate audit reviews and collaborate with internal and external teams to strengthen the overall security posture.

What they look for

Cybersecurity Risk Assessment Penetration Testing Red Teaming Purple Teaming DevSecOps Vulnerability Assessment IT Control Processes Threat Detection Information Security Business Continuity Project Management Application Security HKSAR Baseline IT Security Policy G3 Practice Guide

Requirements

Candidates must hold a Bachelor’s or Master’s degree in a relevant field and possess at least 5 years of hands-on experience in penetration testing and DevSecOps. Additionally, at least 1 year of experience with Hong Kong SRAA engagements and alignment with HKSAR security policies is required.

Full description

Why Work at Lenovo

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

To find out more visit www.lenovo.com and read about the latest news via our StoryHub.

Description and Requirements

Job Duties:

  • Conduct comprehensive risk and control assessments to identify, evaluate, monitor, and mitigate risks across IT systems, applications, and network operations.
  • Conduct red/purple team operation and penetration testing to identify vulnerabilities and assess the effectiveness of security controls.
  • Implement remediations based on test findings to strengthen the security posture.
  • Support security teams in defining, assessing, and managing security operations through appropriate policies, procedures, and control frameworks.
  • Proactively evaluate IT control processes and activities to ensure the control environment is effectively designed and functioning.
  • Facilitate audit and security control reviews with internal teams and external parties, prioritizing and mitigating risks to acceptable levels.
  • Enhance security measures such as threat detection, attack penetration, and mitigation based on current and emerging threats.
  • Promote communication and collaboration between internal teams and external parties on risk and cybersecurity matters.

Requirements:

  • Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Software Engineering, or related fields.
  • 5+ years of hands-on experience in red/purple team exercises, penetration testing, and DevSecOps.
  • 1+ year of hands-on experience conducting Hong Kong SRAA engagements, including security risk assessment, vulnerability assessment, and penetration testing aligned with the HKSAR Baseline IT Security Policy and G3 Practice Guide.
  • Hands-on experience in manual penetration testing across web applications, APIs, and mobile applications.
  • Sound knowledge in Information Security, Business Continuity, Project Management, Application Security and industry best practices.
  • Holder of one or more of the following certifications is a plus: CISSP, CISA, AAIA, CISM, CISP, OSCP, GPEN, CEH, CRTP, and CRT.

#LPS

Additional Locations:

* Hong Kong

General Information

Req #

100017712

Career area:

Information Technology

Country/Region:

Hong Kong

City:

Hong Kong

Date:

Friday, October 9, 2026

Additional Locations:

* Hong Kong

Similar roles