- Astera Labs is building the connectivity fabric powering rack-scale AI, and securing that fabric is mission-critical
- As Senior Principal Engineer, Offensive Security, you’ll be our most senior technical authority on adversarial testing — proactively finding, exploiting, and helping remediate weaknesses across our silicon, firmware, systems, cloud, and corporate environments before adversaries can
- This is a hands-on, deeply technical role for a proven offensive security leader who wants outsized impact at a hyper-growth semiconductor company enabling the world’s largest AI clusters
- You’ll set the technical direction for red teaming, penetration testing, and offensive research, partner closely with product and IT security teams, and help harden the platforms that hyperscalers rely on
- Offensive Security Strategy & Execution
- Define and lead Astera Labs’ offensive security strategy across hardware, firmware, software, cloud, and enterprise IT
- Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets
- Establish scope, rules of engagement, and success metrics for offensive programs in partnership with security leadership
- Technical Depth & Research
- Conduct advanced vulnerability research and exploit development across hardware/firmware, embedded systems, and cloud/SaaS environments
- Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world threat actors (e.g., MITRE ATT&CK)
- Prototype tooling and automation to scale offensive testing and continuous validation of controls
- Partnership & Remediation
- Partner with product security, engineering, IT, and GRC teams to prioritize findings, drive remediation, and validate fixes
- Communicate complex technical risk clearly to engineering leaders and executives, translating exploits into actionable business impact
- Contribute to secure-by-design reviews, threat models, and architecture guidance for new products and platforms
- Leadership & Culture
- Mentor security engineers and elevate offensive security capability across the organization
- Represent Astera Labs’ security posture with customers, partners, and (as appropriate) the broader research community
- Champion a builder mindset that pairs rigorous adversarial testing with pragmatic, engineering-friendly remediation
Benefits
- Flexible time off in the US
- Parental leave
- 401K
- Retirement and pension plans
- Competitive medical, dental and vision plans
Proficiency with offensive tooling and exploit development in languages such as Python, C/C++, and assembly12+ years of experience in offensive security, including red teaming, penetration testing, and/or vulnerability researchDemonstrated expertise in at least two of the following domains: hardware/firmware security, embedded systems, cloud (Azure preferred) and SaaS security, network and application penetration testing, or Active Directory / Microsoft enterprise environmentsDeep understanding of modern attacker tradecraft, TTPs, and frameworks such as MITRE ATT&CKProven track record of driving remediation and measurable security improvements in partnership with engineering teamsBachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical fieldAdvanced degree (MS or PhD) in a security-related disciplineIndustry certifications such as OSCP, OSEP, OSED, GXPN, GPEN, or equivalent demonstrated experienceExperience in the semiconductor, hardware, or hyperscale infrastructure industry, including exposure to PCIe, CXL, or high-speed connectivity technologiesPublished research, CVEs, conference talks (Black Hat, DEF CON, etc.), or notable open‑source contributionsFamiliarity with secure development lifecycle, threat modeling methodologies, and product security programs
#J-18808-Ljbffr