This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a corporate risk expert, you will help ASML to further strengthen our ability to manage our information security risks. The Corporate sector includes a wide variety of specific departments including Finance, HR, Communication, Legal, Strategy, Risk and Business Assurance and Quality. You will ensure that information security risks do not exceed the organization risk appetite by timely identifying and assessing risks, driving risk mitigation, maintaining the security risk register and monitoring and reporting on progress.
Job Responsibility:
Perform intakes on new programs, projects and changes, determine the information security impact and provide relevant security requirements
Where relevant, liaise with the Privacy Office on privacy related topics and with Compliance on other regulatory requirements
Depending on the risk and nature of the project, you provide guidance and advice to realize ‘security by design’, and you validate requirements prior to Go-Live
you define remaining risks, validate them with business stakeholders and recommend mitigations, register those and follow up on progress
Support the structured assessment of key applications and processes, applying ISO27001/2 and ASML policies and standards
Execute/support risk assessments as well as defining and implementing improvements for services where you have assigned responsibility within the Corporate sector
Align with other sectors, stakeholders and clients to ensure appropriate level of control across the Corporate landscape
Focus on business usage aspects, like Access Control, Communication Security, Incident Management, Supplier Relationship, Training & Awareness, Asset Management, Business Continuity Management, Operations Security and System Acquisition, Dev & Maintenance
Requirements:
Master's degree or equivalent combination of education and experience (e.g., in a technical area, business administration, industrial engineering)
Minimum 5 years of relevant experience in information security
Experience and exposure in relevant, global corporate environments
A solid understanding of the IT security domain
Certification in CISM, CISA, CISSP or CCSP
Strong communication skills and ability to advise business stakeholders
Pragmatic mindset, putting actions to work
Business acumen
Solid technical background related to the ISO2700x and/or NIST standards