Product Security Expert

Veldhoven, Building 46, Netherlands

ASML

ASML gives the world's leading chipmakers the power to mass produce patterns on silicon, helping to make computer chips smaller, faster and greener.

View company page

As Product Security Subject Matter Expert, you hold a key position in our RBA (Risk & Business Assurance) Expertise Security sector, ensuring Product security capabilities are defined, implemented and monitored.

Role and responsibilities

ASML brings together the most creative minds in science and technology to develop lithography machines that are key to producing faster, cheaper, more energy-efficient microchips. We design, develop, integrate, market and service these advanced machines, which enable our customers - the world’s leading chipmakers - to reduce the size and increase the functionality of their microchips, which in turn leads to smaller, more powerful consumer electronics.

As the Product Security Subject Matter Expert, you will support secure design, development and maintenance of ASML’s products by ensuring Product security capabilities are defined, implemented and monitored. You shall also verify the appropriateness (sufficiency) and performance of the controls in the Product domain across ASML.

The Product Security Subject Matter Expert is responsible for monitoring compliance against our security frameworks and customer requirements. In this position, you have these main focus points:

  • Develop product security risk and control framework with product security requirements and controls, monitoring dashboard.

  • Partners with development teams to proactively communicate product security requirements, promoting control frameworks to ensure secure goals are met.

  • Implement and embed our product security standards and policies throughout our sectors. Building bridges with your (internal and where needed external) business stakeholders is key to achieve success in implementing our policies and standards.

  • Keep updated on the latest trends, standards, regulations on product security and embed them in ASML policies, standards, control framework.

  • Guide and prepare ASML sectors to comply with the regulatory requirements on Product Security.

  • Explain product security risks to business leaders, and business positions/risk to technical leaders to achieve appropriate security outcomes.

  • Pro-actively enable knowledge management within RBA and ASML sectors.

You work together with a team of security professionals, Product architects and sector security managers to drive the Product security capability and framework. The Security Community has approx. 250 FTE across ASML. Together with the rest of the community, you protect ASML’s assets and you’re at the center of everything that’s digitally exchanged.

Education and experience

Ideally, we are looking for someone who brings a strong technical background and drive security program and project execution across multiple security teams; design and engineering, manufacturing, sales and customer support in situations where authority is not a given. Someone who is open to challenges and can think outside the box, able to bridge between higher level abstraction and detailed design choices.

Besides product security technical knowledge, excellent communication and collaboration skills are essential for this role. You take ownership and lead initiative to results, take responsibility and act decisively whilst collaborating well with other teams, technical and non-technical peers. You have strong stakeholder management skills, able to build solid relationships of trust at different levels.

Some key competences that come natural to you in this position:

  • 10+ years of experience in designing and implementing internal control framework and solving challenges, preferably in a multinational corporate security environment in two or more of the following areas: product security (preferred) or application security, information security or digital platform security.

  • In-depth knowledge or experience in Product Security by design.

  • Proven experience with product security risk assessments.

  • In-depth knowledge of compliance standards in security domain, such as NIST, CIS, ISO 27000, IEC67443, SEMI.

  • BSc/MSc/PhD in Cyber security, Software Engineering, Computer Science, Information Technology or equivalent through certification and or training.

  • Either a GICSP, CISM, CISSP, or CISA certificate is considered as a must.

Other information

If you still feel your profile is a great match with this job description, please apply and we’d like to get in touch.

This position requires access to controlled technology, as defined in the Export Administration Regulations (15 C.F.R. § 730, et seq.). Qualified candidates must be legally authorized to access such controlled technology prior to beginning work. Business demands may require ASML to proceed with candidates who are immediately eligible to access controlled technology.

EOE AA M/F/Veteran/Disability

Diversity and inclusion

ASML is an Equal Opportunity Employer that values and respects the importance of a diverse and inclusive workforce. It is the policy of the company to recruit, hire, train and promote persons in all job titles without regard to race, color, religion, sex, age, national origin, veteran status, disability, sexual orientation, or gender identity. We recognize that diversity and inclusion is a driving force in the success of our company.

Need to know more about applying for a job at ASML? Read our frequently asked questions.

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Application security C CISA CISM CISSP Compliance Computer Science GICSP ISO 27000 Monitoring NIST PhD Product security Risk assessment

Region: Europe
Country: Netherlands
Job stats:  3  1  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.