This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As Product Security Subject Matter Expert, you hold a key position in our RBA (Risk & Business Assurance) Expertise Security sector, ensuring Product security capabilities are defined, implemented and monitored. You will support secure design, development and maintenance of ASML’s products by ensuring Product security capabilities are defined, implemented and monitored. You shall also verify the appropriateness (sufficiency) and performance of the controls in the Product domain across ASML. The Product Security Subject Matter Expert is responsible for monitoring compliance against our security frameworks and customer requirements.
Job Responsibility:
Develop product security risk and control framework with product security requirements and controls, monitoring dashboard
Partners with development teams to proactively communicate product security requirements, promoting control frameworks to ensure secure goals are met
Implement and embed our product security standards and policies throughout our sectors
Keep updated on the latest trends, standards, regulations on product security and embed them in ASML policies, standards, control framework
Guide and prepare ASML sectors to comply with the regulatory requirements on Product Security
Explain product security risks to business leaders, and business positions/risk to technical leaders to achieve appropriate security outcomes
Pro-actively enable knowledge management within RBA and ASML sectors
Requirements:
10+ years of experience in designing and implementing internal control framework and solving challenges, preferably in a multinational corporate security environment in two or more of the following areas: product security (preferred) or application security, information security or digital platform security
In-depth knowledge or experience in Product Security by design
Proven experience with product security risk assessments
In-depth knowledge of compliance standards in security domain, such as NIST, CIS, ISO 27000, IEC67443, SEMI
BSc/MSc/PhD in Cyber security, Software Engineering, Computer Science, Information Technology or equivalent through certification and or training
Either a GICSP, CISM, CISSP, or CISA certificate is considered as a must
Nice to have:
Strong technical background and drive security program and project execution across multiple security teams
design and engineering, manufacturing, sales and customer support in situations where authority is not a given
Open to challenges and can think outside the box, able to bridge between higher level abstraction and detailed design choices
Excellent communication and collaboration skills
Take ownership and lead initiative to results, take responsibility and act decisively whilst collaborating well with other teams, technical and non-technical peers
Strong stakeholder management skills, able to build solid relationships of trust at different levels