(LPS) Senior Cybersecurity Consultant
Lenovo Hong Kong, Hong Kong Island, Hong Kong S.A.R.
IT Services and IT Consulting · 10,001+ employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The consultant will conduct comprehensive risk and control assessments, penetration testing, and red/purple team operations to identify and mitigate security vulnerabilities. They will also facilitate audit reviews and collaborate with internal and external teams to strengthen the overall security posture.
What they look for
Requirements
Candidates must hold a Bachelor’s or Master’s degree in a relevant field and possess at least 5 years of hands-on experience in penetration testing and DevSecOps. Additionally, at least 1 year of experience with Hong Kong SRAA engagements and alignment with HKSAR security policies is required.
Full description
Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
To find out more visit www.lenovo.com and read about the latest news via our StoryHub.
Description and Requirements
Job Duties:
- Conduct comprehensive risk and control assessments to identify, evaluate, monitor, and mitigate risks across IT systems, applications, and network operations.
- Conduct red/purple team operation and penetration testing to identify vulnerabilities and assess the effectiveness of security controls.
- Implement remediations based on test findings to strengthen the security posture.
- Support security teams in defining, assessing, and managing security operations through appropriate policies, procedures, and control frameworks.
- Proactively evaluate IT control processes and activities to ensure the control environment is effectively designed and functioning.
- Facilitate audit and security control reviews with internal teams and external parties, prioritizing and mitigating risks to acceptable levels.
- Enhance security measures such as threat detection, attack penetration, and mitigation based on current and emerging threats.
- Promote communication and collaboration between internal teams and external parties on risk and cybersecurity matters.
Requirements:
- Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Software Engineering, or related fields.
- 5+ years of hands-on experience in red/purple team exercises, penetration testing, and DevSecOps.
- 1+ year of hands-on experience conducting Hong Kong SRAA engagements, including security risk assessment, vulnerability assessment, and penetration testing aligned with the HKSAR Baseline IT Security Policy and G3 Practice Guide.
- Hands-on experience in manual penetration testing across web applications, APIs, and mobile applications.
- Sound knowledge in Information Security, Business Continuity, Project Management, Application Security and industry best practices.
- Holder of one or more of the following certifications is a plus: CISSP, CISA, AAIA, CISM, CISP, OSCP, GPEN, CEH, CRTP, and CRT.
#LPS
Additional Locations:
* Hong Kong
General Information
Req #
100017712
Career area:
Information Technology
Country/Region:
Hong Kong
City:
Hong Kong
Date:
Friday, October 9, 2026
Additional Locations:
* Hong Kong
Similar roles
-
Cybersecurity Analyst
Kahana & Feld LLP New York, New York, United States
-
Cybersecurity Analyst
Valiant Solutions, LLC Dayton, Ohio, United States
-
Cybersecurity Analyst
Edgewater Federal Solutions, Inc. District of Columbia, United States · $190K–$200K/yr
-
Sr. Security Engineer - GRC APAC Fintech & Financial Services
SpaceXAI Tokyo, Japan
-
Security Engineer, Modern Workplace Technology, Security Services Remote
BCD Pune, Maharashtra, India
-
Graduate Application Security Analyst
NextGen Sydney, New South Wales, Australia