
Country Security Lead
- Shanghai
- Permanent
- Full-time
- Overall: responsible for managing the China security organization on behalf of the CISO of ASML, driving the development and delivery of security services in China. Challenge and verify the adequate performance of security controls in China, against ASML and China risk appetite and as executed by the first line of responsibility in the sectors in China.
- Strategy: execute the central security strategy as determined by the CISO and adding country specific aspects to it to improve security maturity.
- Risk management: Collaboration with the 1st line sector SRMs to identify, assess and mitigate security risks, overseeing and reporting via the China Virtual Security Team (VST). Identify improvement opportunities together with the 1st line sector SRMs’ and the 2nd line team in terms of processes and activities. The CSL provides necessary support for improvements and will act in a pivotal role to bring (security) teams together where needed
- Incident response: overseeing the development of country specific response plans, assuring the timely and thorough handling of security indents under coordination of the central Security Operations Centre
- Compliance oversight: ensuring adherence to centrally determined or country specific laws and regulations related to information security.
- Team leadership & capability building: act on behalf of the CISO of ASML and work closely together with the 1st line country SRM’s to define and execute a joined security roadmap for China. Assure the capabilities as required by the central Second Line Security, Intelligence Fusion Centre and Security Operations Center teams are developed and maintained, as well as organizing Security activities related to risk culture and awareness initiatives. Will drive the preparation of a uniform reporting out to the China Country Management Team and align with the CISO and the VST team the agenda for these meetings.
- Stakeholder engagement: Providing regular updates, in alignment with the local first line sector Security Risk Managers of the VST, to senior management in China on the status of information security in China and the central information security program. Considering the given governance, this will always be in alignment with the respective 1st line SRM.
- Providing the general security training to all China staff to improve their awareness
- Some travel will be required to other ASML offices in China, and abroad (+/- 15%)
- External: Security Vendors, Customers, Suppliers, (always in alignment with local account management and procurement teams, Industry Peers and Forums)
- Internal: ASML China IT, local ASML Sector Security Functions, RBA&S, Legal, Sectors
- Minimum of 10 years (Information) Security experience
- Minimum of 8 years experience with physical security
- Minimum of 5 years IT working experience.
- Able to engage with Senior Leadership in China
- Ability to build strong, trusting relationships with technical and non-technical user base;
- Highly-motivated, with a strong work ethic and able to work effectively under minimal supervision
- Excellent verbal and written communication skills in English and Mandarin.
- Excellent multi-tasking skills.
- Enterprise Security risk expertise: Strong understanding of risk frameworks, strategic security risk mgt, policy management, and business continuity management.
- Security Risk mitigation & advisory: Ability to identify, assess, manage and monitor security risk mitigation strategies at a country level
- Business acumen: Deep understanding of ASML business context, priorities, processes, and dependencies in China or related to China
- Security leadership: Strong knowledge and leadership in Security Risk and Compliance, including regulatory requirements, governance, security control (frameworks) and risk management
- Stakeholder management: Ability to engage, influence, and advise key stakeholders in the business
- Strategic thinking: Anticipate future security risks and opportunities, translating them into effective strategies
- Collaborate – proven ability to build strong relationships, establish and foster interactions across levels and across teams, working closely with business leaders and risk owners to ensure security risk management is an integrated function
- Inspire: Proven ability to set a compelling security vision, motivate teams into actions, and act as a role model for all people leaders
- Ensure accountability: Act with a clear sense of ownership and ensures risk accountabilities are clear, accepted and acted upon
- Communicate effectively: Ensure transparency in risk reporting, effectively communicating risk insights to senior leadership
- Master’s degree in Information Science/Security or equivalent experience
- Valid industry certifications such as the Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), , Certified Cloud Security Professional (CCSP), etc.
- Experience with multiple frameworks (e.g. ISO 27001, NIST)Knowledge on country specific laws and regulations related to information security.