Security Risk Manager @ ASML

Sterksen

Veldhoven

On-site

EUR 95,000 - 135,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sterksen in the Netherlands seeks a Senior Information Security Risk Manager – R&D to lead information security risk and compliance within its IP‑driven R&D environment. You will assess cloud and on‑premise initiatives, translate security requirements into actionable controls, and partner with DevOps and engineering teams to embed security by design.

The role emphasizes cloud initiatives (IaaS/PaaS/SaaS) with SAFe/Agile collaboration, a strong risk management background, and a track record with

Qualifications

  • 8+ years of experience in information security risk management.
  • Experience with ISO 27001 risk management framework.
  • Strong knowledge of IaaS, PaaS and SaaS security risks (Azure, GCP).
  • Affinity with R&D processes and culture.
  • Bachelor degree or higher in Information Security, Audit or Cloud.
  • Certifications: CISM, CISA, CISSP, CRISC, CCSP.
  • Experience in Agile (SAFe) environments.
  • Experience with GenAI solutions or willingness to develop this.
  • Valid work permit for the Netherlands.

Responsibilities

  • Perform information security risk management and compliance for cloud and on‑premise projects.
  • Provide risk mitigating controls and guidance to DevOps teams.
  • Report residual risk to risk owners.
  • Drive secure by design practices within R&D.
  • Collaborate with IT security and risk/business assurance teams.
  • Engage in agile and SAFe ceremonies with security emphasis.

Skills

Information security risk management
IT security domain knowledge
ISO 27001 risk management
Cloud security (IaaS/PaaS/SaaS)
Azure and GCP familiarity
Agile SAFe experience
GenAI awareness
Export controls knowledge
PLM/related tooling knowledge
Netherlands work permit

Education

Bachelor's degree in Information Security / Cloud / Audit

Tools

Azure
Google Cloud Platform (GCP)

Job description

Senior Information Security Risk Manager – R&D

PROFILE

Our client is an international, strongly R&D driven technology organisation active in high-end industrial engineering and manufacturing. Intellectual property is the organisation's core asset, and safeguarding it is a top priority.

As Senior Security Risk Manager you manage information security and compliance risks within the R&D domain, a challenging position in an IP driven enterprise.

Within the organisation's security governance model, information security risk management is embedded in the sectors themselves through sector Security Risk Management.

The Security and Compliance team you join operates within the Research & Development domain, covering Design & Engineering, System Engineering, intellectual property and the business lines. The team supports R&D teams in integrating new (public cloud) services into their business processes by providing architectural guidance, controlling costs and ensuring the organisation operates within the R&D risk appetite.

In this role you are responsible for:

  • Assessing and advising R&D (cloud / AI) initiatives on information security and compliance risks.
  • Delivering and monitoring security requirements in line with the sensitivity and importance of the subject.
  • Communicating and advising security risk management, projects, business and IT partners on information security improvements and requirements while ensuring business agility.
  • Driving the absorption of a security and compliance mindset, processes, policies and standards within larger R&D departments.

The majority of the work focuses on R&D cloud initiatives, with some on-premise projects as well.

RESPONSIBILITIES

Ensure security risks do not exceed the risk appetite by timely identification and assessment of risks, and by proposing mitigating controls in line with best practice, policies and standards. Identify gaps, propose improvements and update or create policies, standards, means and methods. Monitor and report on adherence to required security controls. Drive business awareness of security processes and initiatives, and define key guidelines to resolve recurring gaps.

The role focuses on information security within the engineering related departments, among other things by performing information security risk management activities in cloud initiatives across the various project phases to ensure security by design. Alongside these domains you are expected to perform or assist in generic security risk assessments and to support the Information Management department as a whole. Stakeholder management across the R&D business is essential in order to gather security priorities, present the risk portfolio and secure firm commitment to mitigate. You drive and shape Design & Engineering information management security and compliance initiatives for business absorption, and are influential in adhering to secure by design principles.

JOB DESCRIPTION

  • Performing information security risk management and compliance activities in cloud and on-premise environments, projects and initiatives.
  • Providing risk mitigating controls and guidance to DevOps teams.
  • Reporting to risk owners on residual risk at operational and tactical level.
  • Contributing to the improvement of means and methods related to the focus domains.
  • Actively participating in agile and SAFe ceremonies, ensuring security considerations are part of the continuous improvement cycle.
  • Aligning with other security competences (IT and business) within the security community.
  • Performing, advising on and following up on generic risk assessments and identified risks.
  • Driving mitigation of agreed controls.
  • Ensuring compliance with security policies and standards.
  • Aligning with IT (security) and the Risk & Business Assurance department on controls.
  • Defining and driving security maturity.
  • Acting as trusted partner for key decision makers on security demands, advice and influence.

EXPERIENCE

  • 8+ years of relevant experience in information security risk management.
  • Proven understanding, knowledge and experience in the IT security domain.
  • Proven experience with the ISO 27001 risk management framework.
  • Solid knowledge of IaaS, PaaS and SaaS (information) security risks, preferably Azure and GCP.
  • Affinity with Research and Development processes, ways of working and culture.
  • At least a bachelor degree and/or relevant education in Information Security, Audit or Cloud.
  • Valid industry certification (for example CISM, CISA, CISSP, CRISC, CCSP).
  • Pro: knowledge of Product Lifecycle Management (PLM) processes and tooling.
  • Pro: knowledge of export control regulations.
  • Pro: experience working in Agile (SAFe) environments.
  • Pro: able to understand and translate IT threats and vulnerabilities into business risk.
  • Pro: experience with or affinity for traditional or GenAI solutions, or willingness to develop this.
  • In possession of a valid work permit for the Netherlands.

PERSONAL SKILLS

  • Strong analytical skills.
  • Able to deal with resistance and reluctance.
  • Pro-active and self-motivated, with a proven ability to drive results.
  • Team player.
  • Pragmatic.
  • Excellent communication, influencing and negotiating skills.
  • Stakeholder management skills at different levels of the organisation and with external vendors and service providers.
  • Fluent English, written and verbal.

OTHER INFORMATION

The position is based in the south of the Netherlands. You will be part of a Security and Compliance team within the Development and Engineering Information Management department, working in an agile team and reporting to the Group Lead Cloud Enablement. You are part of the organisation's wider security community and collaborate with Security Risk Managers in other sectors.

This position may require access to technology that falls under applicable export control regulations. Qualified candidates must be legally authorised to access such technology prior to starting the assignment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior R&D Cloud Security Risk Manager
Senior R&D Cloud Security Risk Manager

Sterksen • Veldhoven

On-site
EUR 95,000 - 135,000
Senior Security Risk Manager – Sensitive Intellectual Property Domain
Senior Security Risk Manager – Sensitive Intellectual Property Domain

ASML • Veldhoven

On-site
EUR 110,000 - 150,000
Security Exposure Management Specialist
Security Exposure Management Specialist

ASML • Veldhoven

On-site
EUR 90,000 - 130,000
Senior Security Risk Manager - Sensitive Intellectual Property Domain
Senior Security Risk Manager - Sensitive Intellectual Property Domain

ASML • Netherlands

On-site
EUR 120,000 - 170,000
Information manager
Information manager

Sterksen • Veldhoven

On-site
EUR 90,000 - 130,000
Advanced security analyst - incident coordinator
Advanced security analyst - incident coordinator

ASML • Netherlands

Hybrid
EUR 90,000 - 130,000
Technical Information Security Officer
Technical Information Security Officer

Qabird • Delft

On-site
EUR 70,000 - 100,000
Profit sharing
Flexible hours
Vacation add-on
+2
Advanced security analyst – incident coordinator
Advanced security analyst – incident coordinator

ASML • Veldhoven

Hybrid
EUR 90,000 - 130,000
Application security specialist
Application security specialist

ASML • Netherlands

On-site
EUR 90,000 - 130,000
Senior IT Risk Officer - Amsterdam Region
Senior IT Risk Officer - Amsterdam Region

Improven • Amsterdam

On-site
EUR 70,000 - 90,000
16.33% individual choice budget
Over 5 weeks of holidays
€3,000 personal development budget per 3 years