Within ASML, security capabilities are organized centrally, and security risk management is embedded within each of the sectors. For Customer Solutions and Support (CS&S), we are looking for a CS &S Security Architect to further strengthen our ability to protect the confidential information of both ASML and our customers. A unique opportunity to focus on cyber security while experiencing ASMLs business and way of working.
Role and responsibilitiesYour task as CS &S Security Architect is to provide architecture-level security direction and assurance across applications, AI solutions, products and services. In close collaboration with Capability Architects, Solution and Infrastructure Architects, product and service teams, security experts and IT, you will evaluate solution designs, identify technical risks and security gaps, define appropriate controls, and align security improvements with business and IAS technology roadmaps. This means:
- Architecture-level technical risk assessments, including defining proportionate controls for new applications, AI solutions, products and services.
- Secure solution design assurance, covering data flows, trust boundaries, integrations, identity, operational dependencies and residual risks.
- Strong architectural understanding of secure SDLC, application security, cloud security, AI security and product security.
- The ability to translate technical findings into business exposure, delivery choices, remediation priorities and investment decisions.
- Development of security capability and service roadmaps aligned with product portfolios, infrastructure roadmaps and IT operations.
- Engagement with CS&S infrastructure, solutions, product and operations architects to embed security consistently across their roadmaps.
- Support for both IAS product teams releasing solutions to the field and service teams operating business-critical capabilities.
- Interpretation of penetration-test, vulnerability, threat-model, code-review and compliance assessment findings into an actionable remediation plan.
- Contribution to broader operational security decisions, architecture deviations and recurring security improvement initiatives.
- Conduct Security Control Gap Assessments (Risk Scoping) for new and existing solutions to identify control deficiencies, evaluate associated risks, and ensure alignment with enterprise governance, risk, and compliance (GRC) requirements.
Education and experience
- Master's degree in information security, cyber security or equivalent.
- You prove to have at least 10+ years’ experience in security architecture, design and requirements collection.
- Worked in multi-disciplinary projects; Dealt with customers.
- Deep knowledge of security technologies, architecture principles, risk management practices and industry best practices.
- Experience with security assessments and assessing security implications; Affinity with various security frameworks and current EU legislations, including CRA and NIS 2.0.
- Experience coordinating and managing information security risks in partnership with business and technology stakeholders.
- Strong ability to communicate technical risks and security requirements in business language and influence decision-making at all levels.
- Proven track record of creating, managing and delivering security roadmaps and step-ups in infrastructure, products and services.
- Experience within a high-tech, engineering or semiconductor environment is considered a strong advantage.
- Relevant certifications such as CISSP, CCSP, ISSAP, SABSA, TOGAF or equivalent are required; however, demonstrated practical experience, architectural judgement and delivery of security outcomes are valued more highly than certifications alone.
- Strong communication and listening skills
- Strong problem solving capabilities
- Ability to influence and manage different stakeholders on multiple levels
- Strong motivation on finding creative solutions for complex multi system, multiple customers problems.
- Translate security requirements and business goals into detailed specifications and designs that are accepted by stakeholders at many levels in the organizations.
Other information
As a CS&S Security Architect, you are part of the CS&S Security & Risk Management department positioned within Customer Solutions & Support and will report to the CS&S Security Lead.
You will be based in Veldhoven, the Netherlands. You will be a member of the ASML Security community; working closely together with the security risk management teams in other sectors and the central security competence teams.
Inclusion and diversityASML is an Equal Opportunity Employer that values and respects the importance of a diverse and inclusive workforce. It is the policy of the company to recruit, hire, train and promote persons in all job titles without regard to race, color, religion, sex, age, national origin, veteran status, disability, sexual orientation, or gender identity. We recognize that inclusion and diversity is a driving force in the success of our company.
Need to know more about applying for a job at ASML? Read our frequently asked questions.
Skills Required
- Master's degree in information security, cybersecurity, or equivalent
- At least 10 years of experience in security architecture, security design, and requirements collection
- Experience working in multidisciplinary projects and dealing with customers
- Deep knowledge of security technologies, architecture principles, risk management practices, and industry best practices
- Experience conducting security assessments and evaluating security implications
- Familiarity with security frameworks and current EU legislation, including CRA and NIS2.0
- Experience coordinating and managing information security risks with business and technology stakeholders
- Ability to communicate technical risks and security requirements in business language and influence decision-making
- Track record of creating, managing, and delivering security roadmaps and improvements across infrastructure, products, and services
- Relevant certification such as CISSP, CCSP, ISSAP, SABSA, TOGAF, or equivalent
- Experience in a high-tech, engineering, or semiconductor environment
- Strong communication, listening, problem-solving, stakeholder management, and influencing skills
ASML Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ASML and has not been reviewed or approved by ASML.
-
Healthcare Strength — Health coverage is broad and employer‑funded to a significant degree, with multiple plan options plus mental health and wellness resources. Complementary offerings like onsite/virtual care, HSA contributions, and a gym subsidy strengthen the overall medical package.
-
Parental & Family Support — Family‑forming benefits include paid parental leave, adoption assistance, IVF coverage, and practical supports like lactation rooms and milk‑shipment for travel. These provisions indicate substantial caregiving support across life stages.
-
Leave & Time Off Breadth — Paid time off can reach a high ceiling when combining vacation and company holidays, with accruals increasing by tenure. Flexible workplace policies and a vacation sell‑back option add usability to the time‑off program.
ASML Insights
What We Do
ASML is a high-tech company, headquartered in the Netherlands. We manufacture the complex lithography machines that chipmakers use to produce integrated circuits, or computer chips. Over 30 years, we have grown from a small startup into a multinational company with over 60 locations across Europe, Asia and the US. Behind ASML’s innovations are engineers who think ahead. The people who work at our company include some of the most creative minds in physics, electrical engineering, mathematics, chemistry, mechatronics, optics, mechanical engineering, computer science and software engineering. Because ASML spends more than €2 billion per year on R&D, our teams have the freedom, support and resources to experiment, test and push the boundaries of technology. They work in close-knit, multidisciplinary teams, listening to and learning from each other.








