Manager, Offensive Security

SiTime Corp
  • Santa Clara, CA
    10 days ago

    Job Description

    About SiTime

    SiTime is the Precision Timing company.

    Timing is the heartbeat of all electronics, ensuring performance, resilience and scalability. For decades, quartz devices, non-silicon technology, have kept systems in sync, but they struggle in harsher, more demanding environments. MEMS-based Precision Timing delivers greater accuracy, smaller size and resilience. Today, MEMS timing powers over 400 applications, including high-growth ones in AI datacenters, automated driving, industrial and humanoid robots, wearables and IoT.

    Our semiconductor MEMS programmable solutions offer a rich feature set that enables customers to differentiate their products with higher performance, smaller size, lower power, and better reliability. With more than 4 billion devices shipped, SiTime is changing the timing industry. For more information, visit: www.sitime.com.

    Job Summary

    Reporting to the CISO, this role leads SiTime's Offensive Security function. It owns penetration testing, red and purple team exercises, vulnerability disclosure and bug bounty, and validation that the controls SiTime has bought and built actually work.

    This is a build role. The candidate will design a recurring testing program that covers the enterprise, cloud, SaaS, application and laboratory estates, establish adversary simulation against realistic objectives, and create the feedback loop that turns findings into improved detection and hardening rather than a report that is filed away.

    It is also a people-leadership role. The candidate starts hands-on, personally running the first cycle of testing, then scales through a mix of full-time testers and specialist firms engaged where independence or niche capability is required.

    This is an accountable owner role, not an advisory one. Findings are owned through to verified closure in partnership with Security Engineering, Vulnerability Management and Security Operations, Security Architecture, IT and Engineering.

    We value diverse experiences, perspectives, and career paths, and welcome candidates who are excited to contribute to our mission.

    Responsibilities:

    Offensive Testing Program

    • Run a recurring penetration testing program across enterprise, cloud, SaaS, application, network and laboratory environments, covering both grey box and black box engagements.
    • Scope, plan and execute internal testing, and manage external testing firms where specialist capability or independence is required.
    • Prioritize testing around the paths that reach design data, source code repositories, laboratory and test networks, and partner and OSAT connectivity.
    • Own the finding lifecycle end to end: severity, named owner, remediation service level, retest and closure with evidence.
    • Move the program from point-in-time assessment toward continuous validation of the controls that matter most.

    Red Team, Purple Team and Detection Validation

    • Design and run threat-informed red team exercises against realistic objectives, with clear rules of engagement and authorization.
    • Run purple team exercises jointly with Security Operations to validate and improve detection coverage, mapping results to MITRE ATT&CK.
    • Validate that deployed controls detect and prevent, and route the gaps to Security Engineering and Security Operations with reproducible evidence.
    • Simulate insider and data exfiltration scenarios to test data loss prevention, access controls and monitoring on the design environment.
    • Contribute technical injections and scenarios to ransomware and crisis tabletop exercises.
    • Track adversary tradecraft relevant to semiconductors, hardware and intellectual property theft, including state-linked activity, and translate it into test scenarios.

    Disclosure, Bug Bounty and Program Scaling

    • Stand up and run vulnerability disclosure and bug bounty programs, including scope definition, triage, reward policy and researcher relations.
    • Define the rules, authorization and safety controls that keep offensive activity inside agreed boundaries and out of production impact.
    • Build the internal testing capability over time, and manage the specialist firms that supplement it.
    • Support customer-facing security assurance by providing independent evidence of testing coverage and remediation.
    • Feed recurring themes back into the security roadmap, architecture standards and awareness content.

    Qualifications & Requirements :

    • 6+ years in offensive security, penetration testing or red teaming, including 2+ years leading a program or a team.
    • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field - or equivalent practical experience.
    • At least one of the following certifications: OSCP, OSEP, OSCE, , or equivalent.
    • Demonstrated hands-on exploitation capability across network, cloud, application, identity and endpoint.
    • Experience designing and running red and purple team exercises and mapping coverage to MITRE ATT&CK.
    • Experience managing external testing vendors and running a vulnerability disclosure or bug bounty program.
    • Ability to write findings that engineers can act on and executives can understand.
    • People leadership or technical lead experience.
    • English proficiency is required, including the ability to effectively communicate, collaborate, and perform job responsibilities in a professional business environment.

    Preferred:

    • Experience in a semiconductor, hardware, embedded or OT-adjacent environment.
    • Hardware and firmware testing experience, including secure boot and debug interface exposure.
    • Cloud exploitation and identity attack path analysis in Azure and AWS.
    • Source code review and application security testing capability.
    • Experience testing engineering, design or laboratory environments without disrupting them.

    Desired Characteristics & Attributes:

    • Strong ethics and judgment: operates within authorization, documents everything, and knows when to stop.
    • Evidence-driven and measured on risk reduced and detections improved
    • Constructive with the teams being tested; builds partnership rather than an adversarial dynamic.
    • Able to work effectively with a U.S.-based CISO and U.S. stakeholders across time zones.

    Compensation Range:

    At SiTime, we believe great work deserves great rewards. We offer a comprehensive and highly competitive compensation package designed to attract top talent.

    In addition to base salary, this role is eligible for a quarterly bonus tied to the achievement of innovation goals-reflecting our commitment to recognizing meaningful impact. We also offer equity grants, providing a meaningful opportunity to share in the company's future growth and success.

    SiTime is an Equal Opportunity Employer. We treat each person fairly and we do not tolerate discrimination or harassment against anyone on the basis of any protected characteristics, including race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, pregnancy, political affiliation, protected veteran status, protected genetic information, or marital status or other characteristics protected by law. SiTime participates in the E-Verify program.

    Learn More about SiTime: Review the Get to Know SiTime section of our career page to explore our culture, values, and what makes us unique.

    • Innovation on Top - Philosophies of Innovation with Rajesh Vashist
    • Fabrication Knowledge - An Interview with Rajesh Vashist
    • SiTime Corporation - YouTube

    Numbers & Facts

    LocationSanta Clara, CA

    Skills

    • Access Controlunmatched
    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Autonomous Driving Systemsunmatched
    • Black Box Testingunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Communication Skillsunmatched
    • Computer Firmwareunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Customer Relationsunmatched
    • Customer Support/Serviceunmatched
    • Debugging Skillsunmatched
    • E Programming Languageunmatched
    • Electronicsunmatched
    • Embedded Hardwareunmatched
    • English Languageunmatched
    • Establish Prioritiesunmatched
    • Geneticsunmatched
    • Hardware Quality Assuranceunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Injectionsunmatched
    • Intellectual Property (IP)unmatched
    • Internet of Thingsunmatched
    • Laboratory Testingunmatched
    • Leadershipunmatched
    • Loss Preventionunmatched
    • Microsoft Windows Azureunmatched
    • Network Operations Centerunmatched
    • Network Testingunmatched
    • Operations Security (OPSEC)unmatched
    • Penetration Testingunmatched
    • Ransomwareunmatched
    • Reliability Engineeringunmatched
    • Research Skillsunmatched
    • Risk Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Semiconductorsunmatched
    • Simulationunmatched
    • Software Testingunmatched
    • Software as a Service (SaaS)unmatched
    • Source Code/Configuration Management (SCM)unmatched
    • Technical Leadershipunmatched
    • Test Dataunmatched
    • Test Designunmatched
    • Test Programunmatched
    • Test Scenariounmatched
    • Testingunmatched
    • Vendor/Supplier Managementunmatched
    • Wearablesunmatched
    • Writing Skillsunmatched
    • YouTubeunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder