Responsibilities
- Perform security testing, vulnerability discovery, and risk analysis for Android/iOS applications and Android smart devices.
- Identify mobile security issues including injection, privilege escalation, sensitive-data leakage, exposed components, insecure storage, and communication-security weaknesses.
- Produce actionable remediation recommendations and drive risk closure with product, development, and testing teams.
- Participate in security activities across requirements reviews, technical design reviews, validation, and product release.
- Optimize mobile-security processes including security reviews, testing, vulnerability grading, risk admission/release controls, and security baselines.
- Explore large language models and AI agents for vulnerability analysis, code auditing, risk identification, and test automation.
Requirements
- Bachelor's degree or higher, preferably in computer science, information security, software engineering, or a related field.
- Experience in mobile security, security business partnering, or security project management; candidates may focus on mobile security or security BP work but should understand the other area.
- For the mobile-security track, familiarity with Android/iOS architecture, Native, Hybrid, H5, mini-programs, Jadx, IDA, and Apktool, plus APK decompilation, code analysis, vulnerability localization, or mobile security testing experience.
- For the security-BP track, communication, coordination, project advancement, risk closure, and security-process optimization skills, along with the ability to work with product, development, and testing teams.
- Ability to read English technical documentation, security advisories, and vulnerability-analysis articles; English communication and technical-material writing are preferred.
- Strong documentation and presentation skills for security reports, risk explanations, technical proposals, process specifications, and project reports.
- Preferred qualifications include combined mobile-security and security-BP experience, mobile vulnerability research results, CVE/CNVD/CNNVD identifiers, security research articles, or public technical presentations.
Tech Stack
Categories
About Lenovo
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Guided by its vision of “Smarter Technology for All”, Lenovo is executing a Hybrid AI strategy that spans Personal AI – one personal AI, multiple devices; and Enterprise AI – helping customers turn data into insights and value. This strategy is delivered through the Group’s commitment to world-class innovation and a full-stack AI portfolio, including devices (PCs, workstations, smartphones, tablets, accessories), infrastructure solutions (server, storage, edge, high performance computing and software defined infrastructure), as well as software, solutions, and services. With a global footprint spanning 21 research and development locations in 11 markets, and a global supply chain including more than 30 manufacturing sites across 10 markets, Lenovo is widely recognized for its operational excellence, including ranking #8 in the Gartner Supply Chain Top 25. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY). To find out more visit https://www.lenovo.com, and read about the latest news via our StoryHub at https://news.lenovo.com/. To learn more about our career opportunities, visit our careers page at http://jobs.lenovo.com/.
