ASML logo

Security risk expert - AI & emerging technology

ASML

Veldhoven
Full-time
5-10 years experience
On-site

Key Skills

AI Security Risk Assessment
Threat Modeling
Attack-Path Analysis
Security-by-Design
AI Risk Analysis
Security Control Evaluation
Risk Treatment Planning
Exception Management
Security Frameworks
Stakeholder Management
Influencing and Interpersonal Skills
Security Standards Development
Mentoring
Information Security Management

Job Description

Introduction to the job As a Security risk expert - AI & emerging technology, you are responsible for executing security risk assessments and providing specialist security expertise for Artificial Intelligence (AI), Generative AI, Agentic AI, machine learning solutions, and other emerging technologies. You will perform detailed security analysis, identify risks, evaluate controls, and develop practical recommendations to support informed risk-based decisions. Role and responsibilities As a Security risk expert - AI & emerging technology, you will operate as a senior individual contributor under the direction and prioritization of the Security risk manager. In this function, you will join the first-line Corporate Sector Security Risk Management department. You will be part of the ASML Security community and work closely with sector Security Risk Management (SRM) teams, central security competence teams, AI and data governance, Information Technology, Privacy, Legal & Compliance, Internal Audit and business stakeholders. In this role, you will: Execute security risk assessments for AI and emerging technology initiatives, identifying threats, vulnerabilities, control gaps, and risk scenarios, and developing evidence-based findings and recommendations Perform detailed analysis of proposed technologies and architectures, including threat modelling, attack-path analysis, and evaluation of security controls and mitigations Assess AI-specific risks, including model compromise, prompt injection, data leakage, training data risks, supply chain vulnerabilities, agentic behaviour risks, and access control weaknesses Support security-by-design reviews throughout the technology lifecycle, provide subject matter expertise to project teams, advise stakeholders on security-by-design principles, and support solution design reviews Assist teams in understanding security expectations and requirements, validate implementation of agreed security controls, and review remediation activities and compensating measures Support exception management, risk treatment planning, and risk acceptance discussions, providing technical security expertise and recommendations Contribute to the improvement of assessment methodologies, security standards, control frameworks, procedures, and reporting mechanisms, share knowledge and mentor less experienced practitioners, and escalate material risks, novel technologies, risk appetite concerns, regulatory concerns, and significant disagreements or unresolved issues to the Security Risk Manager Education and experience Bachelor's or master's degree in a relevant discipline, e.g., business administration, information technology, cybersecurity, internal audit, IT management and/or data science & AI. 3-7 years professional experience with a focus on security, IT auditing, Information Security Management Systems (ISMS). AI specialization required Relevant certifications such as CISSP, CISM or CRISC. Experience with defining and running AI security baselines, assessments Proven track record in Security at tactical level Deep Knowledge of current security technologies, current and future developments for AI security, in-depth working knowledge of IT, Data and Information Risk/security frameworks and best practices, such as NIST Cyber security framework, ISF Standard of Good Practice for Information Security, IEC 62443, NIST SP 800 30 framework, NIS2 , ISO 27001/2 framework Skills To be successful in this role, you will need: Excellent influencing and interpersonal skills Ability to further develop Security Risk and Control Management within ASML by building trusting and long-term relationships Aability to overcome organizational resistance, as well as the ability to interact across all levels of the organization Solid foundation in internal and external stakeholder management as well as ability to understand different perspectives, act upon those and prioritize needs Self-starter mindset and ability to operate autonomously with little guidance Being comfortable in starting up several initiatives at the same time without losing the overview and bigger picture Other information A Certificate of Good Conduct “Verklaring Omtrent het Gedrag (VOG)” is required for this position. Inclusion and diversity ASML is an Equal Opportunity Employer that values and respects the importance of a diverse and inclusive workforce. It is the policy of the company to recruit, hire, train and promote persons in all job titles without regard to race, color, religion, sex, age, national origin, veteran status, disability, sexual orientation, or gender identity. We recognize that inclusion and diversity is a driving force in the success of our company. Need to know more about applying for a job at ASML? Read our frequently asked questions.

Core Responsibilities

Conduct security risk assessments and detailed technical analyses for AI and emerging technology initiatives, identifying threats, vulnerabilities, control gaps, and practical mitigations. Advise project teams and stakeholders on security-by-design, risk treatment, exceptions, and control implementation, while improving assessment methods and escalating material risks.

Requirements

A bachelor's or master's degree in a relevant discipline and 3–7 years of professional experience in security, IT auditing, or ISMS are requested, with an AI specialization and experience defining and running AI security baselines and assessments. The role also calls for strong knowledge of AI security and security frameworks such as NIST, ISO 27001/2, IEC 62443, and NIS2, relevant certifications such as CISSP, CISM, or CRISC, and strong stakeholder and influencing skills.

About ASML

Industry: Semiconductor Manufacturing

Company size: 10,001+ employees

Who are we? ASML is an innovation leader in the global semiconductor industry. We make machines that chipmakers use to mass produce microchips. Founded in 1984 in the Netherlands with just a handful of employees, we’ve now grown to over 40,000 employees, 143 nationalities and more than 60 locations around the world. What do we do? We provide chipmakers with hardware, software and services to mass produce patterns on silicon through lithography. Our lithography systems use ultraviolet light to create billions of tiny structures on silicon that together make up a microchip. We push our technology to new limits to enable our customers to create smaller, faster and more powerful chips. Who are our people? While you may think that only engineers and mathematicians work at ASML, you'll be surprised to find out that our people come from a wide variety of backgrounds. Across ASML, we have dedicated teams that manage customer support, communications and media, IT, software development and more. Every team in the company is essential for pushing our technology and the industry forward. If you love to tackle challenges and innovate in a collaborative, supportive and inclusive environment with all the flexibility and freedom to unleash your full potential, ASML is the place to be. Join us!

Added Today