Security risk manager – AI & emerging technology
Key Skills
Job Description
Introduction to the job As Security risk manager - AI & emerging technology, you will lead a team of security specialists and manage a portfolio of AI-related security risk activities. You are responsible for risk oversight, stakeholder engagement, governance execution, and the leadership review and execution of complex security assessments within its assigned area of responsibility. Working as part of the broader Security Risk Management leadership team, you will ensure consistent application of risk management practices, support informed risk-based decision-making, and serve as an escalation point for significant security risks. Role and responsibilities As Security risk manager - AI & emerging technology, you are accountable for the effective management of security risks related to Artificial Intelligence (AI), Generative AI, Agentic AI, data science solutions, and emerging technologies across ASML. You will provide leadership, governance, oversight, and direction for the AI security risk management capability. You will lead a team of security specialists, own the AI security risk portfolio, ensure consistent and high-quality risk assessments, and serve as the primary point of escalation for significant security risks. Your function combines people leadership, security risk management, stakeholder engagement, and direct involvement in the most complex, high-impact, or strategically significant assessments. As Security risk manager - AI & emerging technology, you will join the first-line Corporate Sector Security Risk Management department. You will be part of the ASML Security community and work closely with sector Security Risk Management (SRM) teams, central security competence teams, AI and data governance, Information Technology, Privacy, Legal & Compliance, Internal Audit and business stakeholders. In this role, you will: Lead, coach, and develop a team of Security AI Experts, including performance management, career development, recruitment, onboarding, succession planning, and capacity management Own the AI and Emerging Technologies security risk portfolio, setting priorities based on business risk, regulatory requirements, and organizational objectives, and ensuring effective management of assessments, risk treatment plans, exceptions, remediation activities, and risk escalations Establish and maintain security risk assessment methodologies, standards, procedures, metrics, and reporting mechanisms, ensuring consistent application of security risk management practices across AI-related initiatives Lead, review, and challenge complex security risk assessments involving significant business impact, novel technologies, strategic programs, high residual risk, regulatory exposure, risk appetite concerns, and cross-sector dependencies Serve as the primary security risk advisor to senior management and collaborate with stakeholders across Business, IT, Enterprise Architecture, Data & AI, Privacy, Legal, Compliance, and Internal Audit to facilitate risk-based decision making Drive continuous improvement of AI security risk management practices by monitoring emerging threats, technologies, regulations, and market developments, and developing organizational security risk management maturity Ensure the quality and consistency of AI security assessments, security risk reporting and governance, portfolio visibility and health, prioritization of assessment activities, team performance and development, and escalation of material security risks Business risk owners remain accountable for risk acceptance decisions. Experience and education Demonstrated experience leading security risk assessments, treatment planning, exceptions, residual-risk escalation, control assurance and management reporting Experience influencing senior business, IT, Data, Architecture, Privacy, Legal, Compliance and Security stakeholders in a complex international environment Working knowledge of AI systems and lifecycle risks, including confidentiality, integrity and availability; model and supply-chain risks; prompt or data leakage; access control; monitoring; and agentic autonomy Deep working knowledge of NIST AI RMF, NIST CSF 2.0, ISO/IEC 27001/27002, ISO/IEC 27005, ISO/IEC 42001 and NIST SP 800-30; awareness of OWASP guidance for LLM applications and MITRE ATLAS is preferred Understanding of relevant regulatory obligations, including the EU AI Act and NIS2 Skills You are an experienced security risk professional who connects business objectives, technology choices, regulatory expectations and risk appetite. You can prioritize a portfolio, make evidence-based recommendations, operate autonomously and maintain oversight across concurrent initiatives. To be successful in this role, you will also need: Ability to prioritize a portfolio, make evidence-based recommendations, operate autonomously and maintain oversight across concurrent initiatives Ability to influence without relying on hierarchy, challenge constructively and communicate concisely with senior stakeholders Ability to lead functionally, coach experts, set priorities, overcome organizational resistance and assure the quality and consistency of risk work Other information A Certificate of Good Conduct (Verklaring Omtrent het Gedrag – VOG) is required for this position. Inclusion and diversity ASML is an Equal Opportunity Employer that values and respects the importance of a diverse and inclusive workforce. It is the policy of the company to recruit, hire, train and promote persons in all job titles without regard to race, color, religion, sex, age, national origin, veteran status, disability, sexual orientation, or gender identity. We recognize that inclusion and diversity is a driving force in the success of our company. Need to know more about applying for a job at ASML? Read our frequently asked questions.
Core Responsibilities
Lead and develop a team of security specialists while owning the security risk portfolio for AI and emerging technologies across the organization. Establish consistent assessment and governance practices, advise senior stakeholders, and oversee complex assessments, risk treatment, reporting, and escalation of significant risks.
Requirements
Requires substantial experience leading security risk assessments, treatment planning, control assurance, and reporting, along with the ability to influence senior stakeholders in a complex international environment. Candidates should understand AI lifecycle security risks, relevant security frameworks and standards, and regulatory obligations such as the EU AI Act and NIS2.
About ASML
Industry: Semiconductor Manufacturing
Company size: 10,001+ employees
Who are we? ASML is an innovation leader in the global semiconductor industry. We make machines that chipmakers use to mass produce microchips. Founded in 1984 in the Netherlands with just a handful of employees, we’ve now grown to over 40,000 employees, 143 nationalities and more than 60 locations around the world. What do we do? We provide chipmakers with hardware, software and services to mass produce patterns on silicon through lithography. Our lithography systems use ultraviolet light to create billions of tiny structures on silicon that together make up a microchip. We push our technology to new limits to enable our customers to create smaller, faster and more powerful chips. Who are our people? While you may think that only engineers and mathematicians work at ASML, you'll be surprised to find out that our people come from a wide variety of backgrounds. Across ASML, we have dedicated teams that manage customer support, communications and media, IT, software development and more. Every team in the company is essential for pushing our technology and the industry forward. If you love to tackle challenges and innovate in a collaborative, supportive and inclusive environment with all the flexibility and freedom to unleash your full potential, ASML is the place to be. Join us!