Lenovo
Manager, Cyber Resilience Act Compliance

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
We are Lenovo
We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Manager, CRA Compliance Program
We are seeking a high-agency Manager, CRA Compliance Program to operationalize the EU Cyber Resilience Act (CRA) framework across our product and service portfolios. Operating within the enterprise security organization, this role bridges the gap between regulatory mandates and engineering execution.
While legal teams define baseline regulatory interpretations, you are strictly accountable for translating these interpretations into continuous operational outcomes. You will drive execution across cross-functional engineering and security teams to ensure precise product lifecycle coverage, applicability, and audit defensibility.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Job Responsibilities
- Program Operationalization: Drive assigned EU CRA compliance workstreams across product lifecycles. Ensure execution meets strict regulatory deadlines and internal service level agreements (SLAs) while embedding requirements into design, development, and post-market phases.
- Cross-Functional Alignment: Direct compliance deliverables across Product Security, IT, Legal, Privacy, and Supply Chain. Eliminate operational silos and enforce stakeholder accountability for required evidence.
- Artifact Engineering Traceability: Architect and maintain defensible CRA documentation, including technical system descriptions and compliance records. Enforce end-to-end traceability between regulatory mandates and implemented controls within the enterprise system of record.
- Risk Escalation Governance: Identify, document, and quantify CRA-specific technical and operational risks. Formulate risk treatment plans and escalate material blockers to security leadership with proposed remediation paths.
- Audit Command: Orchestrate audit preparation and evidence coordination. Serve as the primary operational point of contact for CRA regulatory inquiries and transition assigned areas to a state of continuous audit readiness.
- Executive Telemetry: Synthesize complex compliance metrics into actionable leadership briefings. Deliver precise status updates to drive rapid cross-functional alignment.
Minimum Requirements
- Education: Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline.
- Experience: 7 to 10 years of applied experience in cybersecurity, product security, enterprise risk, or regulatory compliance roles.
- Domain Expertise: Proven capability in executing complex cyber compliance frameworks. Verifiable experience with product-centric regulations (CRA) or major enterprise frameworks (NIS2, ISO/IEC 27001) is required.
- Execution Capability: Demonstrated ability to manage complex, multi-stakeholder initiatives and translate abstract regulatory text into discrete, actionable engineering tasks.
- Communication Mastery: Exceptional written and verbal communication skills. Capable of bridging the lexicon gap between legal, engineering, and executive stakeholders.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Preferred Requirements
- Professional Certifications: Active professional credentials such as CISSP, CISM, CISA, or ISO/IEC 27001 Lead Implementer.
- Operational Flexibility: Availability to support critical audit cycles during business hours with occasional off-hours engagement. Intermittent travel is required for regulatory assessments and stakeholder alignment.
What Lenovo Can Offer You
- Opportunities for career development growth
- Performance-based rewards
- Hybrid working model (3:2)
- Up to 3 paid Personal Days annually
- Additional vacation days
- 100% sick leave compensation up to 2 months per year
- A broad selection of soft / hard skills trainings and individual mentoring
- Employer contribution to the Third Pillar Pension System
- Life events insurance, fully covered by company
The anticipated initial gross base monthly salary range for this position in Slovakia is 3,150 EUR – 4,620 EUR, depending on experience + variable part 12% of your annual earnings.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills