Cloud Security Risk Manager

San Diego CA Offices, USA

ASML

ASML gives the world's leading chipmakers the power to mass produce patterns on silicon, helping to make computer chips smaller, faster and greener.

View company page

Introduction

ASML US, including its affiliates and subsidiaries, bring together the most creative minds in science and technology to develop lithography machines that are key to producing faster, cheaper, more energy-efficient microchips. We design, develop, integrate, market, and service these advanced machines, which enable our customers - the world’s leading chipmakers - to reduce the size and increase the functionality of their microchips, which in turn leads to smaller, more powerful consumer electronics. Our headquarters are in Veldhoven, Netherlands, and we have 18 office locations around the United States including main offices in Chandler, Arizona, San Jose and San Diego, California, Wilton, Connecticut, and Hillsboro, Oregon.

The mission of the Information Management department is to unleash R&D’s full potential by maximizing productivity. As Cloud Security Risk Manager, you will be part of a creative and dynamic team that collaborates to solve challenges that impact the R&D organization.

This role focuses on information security in the cloud (IaaS / PaaS), supporting Development & Engineering, Business Line Applications, Corporate Intellectual Property, Research & System Engineering. You will ensure that information security risks do not exceed our risk appetite by identifying and assessing risks in both existing and proposed applications – recommending mitigating controls from our cloud security framework.

Additionally, this role will have a wide range of internal interfaces with multiple IT teams, Customer Support, Operations and Risk & Business Assurance. You will also interface with other programs, projects and agile teams – as well as R&D team members based out of Europe.

This position requires access to controlled technology, as defined in the Export Administration Regulations (15 C.F.R. § 730, et seq.). Qualified candidates must be legally authorized to access such controlled technology prior to beginning work. Business demands may require ASML to proceed with candidates who are immediately eligible to access controlled technology.

Duties and Responsibilities

  • Perform information security risk assessments on new cloud initiatives; lead architectural design reviews, recommending mitigating controls and driving their implementation.
  • Routinely align with other cloud security competences within the security community on security matters linked to R&D information assets.
  • Ensure compliance with all security policies, standards and regulations for controlled technology.
  • Serve as an authority on AI security, advising the security risk management team, developers, and project managers on standard processes and security measures.
  • Work closely with Legal, Privacy and corporate AI committee to ensure a comprehensive security posture for all AI initiatives.
  • Perform generic risk assessments and/or arrange penetration tests on existing cloud-based applications; registering risks, recommending controls and driving the mitigation of those controls.
  • Contribute towards the improvement of business managed equipment policies, processes and organization within R&D.
  • Perform other duties as assigned.

Education and experience

  • Bachelor’s degree in Information Security, Audit, Cloud Computing or combination of education and/or equivalent related work experience.
  • Master’s degree is a plus.
  • 3-5 years proven experience in cloud security with a firm understanding of architecture, design and concepts.
  • 2-3 years of AI security experience preferred but not essential.
  • Solid understanding of AI technologies and their security implications.
  • Proven experience with the ISO27001 framework; familiarity with related cloud security frameworks and best practices.
  • Solid knowledge on IaaS and PaaS (information) security risks pertaining to Microsoft Azure and Google Cloud Platform.
  • Preferred security certifications include (but not required) are CCSP, CISSP/CISM or CRISC.
  • Experience with hybrid multi cloud a plus.
  • Knowledge of US export regulations a plus.
     

Skills

  • Results driven. Demonstrates ownership and accountability, following through on assignments with minimal supervision
  • Strong communications skills, with the ability to influence, negotiate and build consensus with key stakeholders
  • Strong analytical and problem-solving skills with attention to detail
  • Ability to understand and translate information security threats and vulnerabilities into business risk for stakeholders
  • Ability to work both independently and in a team environment where flexibility, creativity, and commitment are important
  • Ability to think strategically for long-term vision in terms of culture, behavior, business processes and tools, yet can tailor solutions to be fit-for-purpose and deliver quick wins
  • Continuous learner with a passion for staying ahead of security trends and technologies

Other Information

  • This position is located in San Diego, CA and works on a hybrid schedule; 3 days onsite, 2 days remote.
  • Routinely required to sit; walk; talk; hear; use hands to keyboard, finger, handle, and feel; stoop, kneel, crouch, twist, reach, and stretch. Occasionally required to move around the campus.
  • Occasionally lift and/or move up to 20 pounds.
  • Specific vision abilities required by this job include close vision, color vision, peripheral vision, depth perception, and ability to adjust focus.
  • Must be willing to work in a clean room environment, wearing coveralls, hoods, booties, safety glasses and gloves for entire duration of shift.
  • While performing the duties of this job, the employee routinely is required to sit; walk; talk; hear; use hands to keyboard, finger, handle, and feel; stoop, kneel, crouch, twist, reach, and stretch.

EOE AA M/F/Veteran/Disability

Potential candidates will meet the education and experience requirements provided on the above job description and excel in completing the listed responsibilities for this role.   All candidates receiving an offer of employment must successfully complete a background check and any other tests that may be required.            

The current base annual salary range for this role is currently $115,125-$191,875. Pay scales are determined by role, level, location and alignment with market data. Individual pay is determined through interviews and an assessment of several factors that that are unique to each candidate, including but not limited to job-related skills, relevant education and experience, certifications, abilities of the candidate and pay relative to other team members. Our recruiters can share more information about our bonus program, benefits and equity during the hiring process.

Diversity and inclusion

ASML is an Equal Opportunity Employer that values and respects the importance of a diverse and inclusive workforce. It is the policy of the company to recruit, hire, train and promote persons in all job titles without regard to race, color, religion, sex, age, national origin, veteran status, disability, sexual orientation, or gender identity. We recognize that diversity and inclusion is a driving force in the success of our company.

Need to know more about applying for a job at ASML? Read our frequently asked questions.

Apply now Apply later
  • Share this job via
  • or

Tags: Agile Azure C CCSP CISM CISSP Cloud Compliance CRISC GCP IaaS ISO 27001 PaaS Privacy R&D Risk assessment Risk management Vulnerabilities

Perks/benefits: Equity Gear Salary bonus

Region: North America
Country: United States
Job stats:  9  2  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.