This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Do you like Information and Cyber Security Controls, auditing and contract negotiating within a Strategic Sourcing & Procurement (SS&P) environment? Come join ASML as a Cyber Security Specialist to support Supplier Security and Security Risk Management Team. Supplier Security and Security Risk Management (the team) is a team that does support contracting security requirements, execute our part when security incidents happen at suppliers, risk based assessing of suppliers, gap closure/improvement of suppliers and mature information and cyber security in the eco-system (external focus). The team also does security for the sector SS&P like assessing applications, awareness, risk management, security incidents and more (internal focus). ASML has many different type of suppliers worldwide. Security maturity of these suppliers as also the security maturity of the SS&P sectors are important to protect ASML. By understanding our external supplier eco-system and our internal eco-system (example IT assets) , we identify security risks and together with suppliers/ASML IT we drive improvement.
Job Responsibility:
Update the supplier security policy and supplier security standard based on experience, relevant trends from outside and law/regulations
Continues improvement of process, people and technology
Dashboarding/reporting (update your part of the dashboards)
Reporting on progress by maintaining your part of the central overview on progress of the negotiations for security controls
Assessing IT Security Controls of suppliers as received in written form (self-assessment and onsite assessments)
Assessing risks related to IT Security Controls
Giving a final advice for the risks by writing an advice (residual risk)
Drive improvement of suppliers
Assessing and improving Cyber Security risks at suppliers identified by our Cyber Security Tool
Be the initial interface with the supplier and the Cyber Security Specialist in case of a security incident at suppliers
Use risks identified during information security assessment and cyber security at suppliers to develop master classes to improve suppliers in 1 to many events
Requirements:
Overall 10-15 years working experiences
8+ of relevant experience in Information Cyber Security and contracting strategy and/or execution, preferably in a corporate, technology-related environment
Master/Bachelor degree in an IT technical field or equivalent professional experience
IT auditor or equivalent certification (par example CISA)
Valid industry security related certifications such as the Certified Information Systems Security Professional (CISSP)
Overseeing the whole ISO27001 version 2021 with in-depth knowledge of each aspect is preferred
Having Information and Cyber Security knowledge on a management level and being able to be a counterpart for Subject Matter Experts
Having a pragmatic approach and can act differently depending on the specific situation
Knowledge and experience with security audit frameworks and standards
Analytical, precise, tenacious, autonomous
Process minded and Project Management skills
Diplomatic and good negotiations skills
Ability to interact with all levels including executives and senior managers
Ability to build a strong relationship with suppliers/stakeholders
Strong interpersonal, presentation, analytical and statistical sampling skills
Exceptional written and verbal communication skills are required