LE
Manager, Cyber Resilience Act Compliance
Lenovo
Publiée le
28/07/2026
Contrat
CDD / Temporaire · 1-3 mois
Localisation
, , ,
Taille équipe
Inconnue emp.
Rémunération
55 000 € - 65 000 €
Missions clés
Promouvoir l'utilisation de la cybersécurité dans les produits et services internes · Résoudre problèmes complexes liés aux exigences réglementaires
Profil recherché
Bac +8 (Doctorat) · 5-10 ans d'expérience · Communication · Esprit d'analyse
Outils & compétences
Cybersécurité, Product Security
Le poste en détail
Description and Requirements
We are seeking a high-agency Manager, CRA Compliance Program to operationalize the EU Cyber Resilience Act (CRA) framework across our product and service portfolios. Operating within the enterprise security organization, this role bridges the gap between regulatory mandates and engineering execution.
While legal teams define baseline regulatory interpretations, you are strictly accountable for translating these interpretations into continuous operational outcomes. You will drive execution across cross-functional engineering and security teams to ensure precise product lifecycle coverage, applicability, and audit defensibility.
Job Responsibilities:
Program Operationalization: Drive assigned EU CRA compliance workstreams across product lifecycles. Ensure execution meets strict regulatory deadlines and internal service level agreements (SLAs) while embedding requirements into design, development, and post-market phases.
Cross-Functional Alignment: Direct compliance deliverables across Product Security, IT, Legal, Privacy, and Supply Chain. Eliminate operational silos and enforce stakeholder accountability for required evidence.
Artifact Engineering & Traceability: Architect and maintain defensible CRA documentation, including technical system descriptions and compliance records. Enforce end-to-end traceability between regulatory mandates and implemented controls within the enterprise system of record.
Risk & Escalation Governance: Identify, document, and quantify CRA-specific technical and operational risks. Formulate risk treatment plans and escalate material blockers to security leadership with proposed remediation paths.
Audit Command: Orchestrate audit preparation and evidence coordination. Serve as the primary operational point of contact for CRA regulatory inquiries and transition assigned areas to a state of continuous audit readiness.
Executive Telemetry: Synthesize complex compliance metrics into actionable leadership briefings. Deliver precise status updates to drive rapid cross-functional alignment.
Minimum Requirements:
Education: Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline.
Experience: 7 to 10 years of applied experience in cybersecurity, product security, enterprise risk, or regulatory compliance roles.
Domain Expertise: Proven capability in executing complex cyber compliance frameworks. Verifiable experience with product-centric regulations (CRA) or major enterprise frameworks (NIS2, ISO/IEC 27001) is required.
Execution Capability: Demonstrated ability to manage complex, multi-stakeholder initiatives and translate abstract regulatory text into discrete, actionable engineering tasks.
Communication Mastery: Exceptional written and verbal communication skills. Capable of bridging the lexicon gap between legal, engineering, and executive stakeholders.
Preferred Requirements:
Professional Certifications: Active professional credentials such as CISSP, CISM, CISA, or ISO/IEC 27001 Lead Implementer.
Operational Flexibility: Availability to support critical audit cycles during business hours with occasional off-hours engagement. Intermittent travel is required for regulatory assessments and stakeholder alignment.
What Lenovo can offer you:
Opportunities for career development & growth
Performance based rewards
Hybrid working model (homeoffice/office)
Up to 3 paid Personal Days annually
Additional vacation days
100% sick leave compensation up to 2 months per year
A broad selection of soft / hard skills trainings and individual mentoring
Employer contribution to the Third Pillar Pension System
Life & life events insurance, fully covered by company
The anticipated initial gross base monthly salary range for this position is 3,150 EUR – 4,620 EUR, depending on experience + variable part 12% of your annual earnings.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.