Senior Principal Engineer, Offensive Security 2026-345

Astera Labs Inc
  • San Jose, CA
  • $190,000–$240,000 Per Year
23 days ago

Job Description

Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs' Intelligent Connectivity Platform integrates CXL, Ethernet, NVLink, PCIe, and UALink semiconductor-based technologies with the company's COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company's custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at www.asteralabs.com.

Senior Principal Engineer, Offensive Security (2026-345)

Location: San Jose, CA

Role Overview

Astera Labs is building the connectivity fabric powering rack-scale AI, and securing that fabric is mission-critical. As Senior Principal Engineer, Offensive Security, you''ll be our most senior technical authority on adversarial testing - proactively finding, exploiting, and helping remediate weaknesses across our silicon, firmware, systems, cloud, and corporate environments before adversaries can.

This is a hands-on, deeply technical role for a proven offensive security leader who wants outsized impact at a hyper-growth semiconductor company enabling the world''s largest AI clusters. You''ll set the technical direction for red teaming, penetration testing, and offensive research, partner closely with product and IT security teams, and help harden the platforms that hyperscalers rely on.

Key Responsibilities

  • Offensive Security Strategy & Execution

  • Define and lead Astera Labs'' offensive security strategy across hardware, firmware, software, cloud, and enterprise IT

  • Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets

  • Establish scope, rules of engagement, and success metrics for offensive programs in partnership with security leadership

  • Technical Depth & Research

  • Conduct advanced vulnerability research and exploit development across hardware/firmware, embedded systems, and cloud/SaaS environments

  • Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world threat actors (e.g., MITRE ATT&CK)

  • Prototype tooling and automation to scale offensive testing and continuous validation of controls

  • Partnership & Remediation

  • Partner with product security, engineering, IT, and GRC teams to prioritize findings, drive remediation, and validate fixes

  • Communicate complex technical risk clearly to engineering leaders and executives, translating exploits into actionable business impact

  • Contribute to secure-by-design reviews, threat models, and architecture guidance for new products and platforms

  • Leadership & Culture

  • Mentor security engineers and elevate offensive security capability across the organization

  • Represent Astera Labs'' security posture with customers, partners, and (as appropriate) the broader research community

  • Champion a builder mindset that pairs rigorous adversarial testing with pragmatic, engineering-friendly remediation

Basic Qualifications

  • Bachelor''s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field

  • 12+ years of experience in offensive security, including red teaming, penetration testing, and/or vulnerability research

  • Demonstrated expertise in at least two of the following domains: hardware/firmware security, embedded systems, cloud (Azure preferred) and SaaS security, network and application penetration testing, or Active Directory / Microsoft enterprise environments

  • Proficiency with offensive tooling and exploit development in languages such as Python, C/C++, and assembly

  • Deep understanding of modern attacker tradecraft, TTPs, and frameworks such as MITRE ATT&CK

  • Proven track record of driving remediation and measurable security improvements in partnership with engineering teams

Preferred Qualifications

  • Advanced degree (MS or PhD) in a security-related discipline

  • Industry certifications such as OSCP, OSEP, OSED, GXPN, GPEN, or equivalent demonstrated experience

  • Experience in the semiconductor, hardware, or hyperscale infrastructure industry, including exposure to PCIe, CXL, or high-speed connectivity technologies

  • Published research, CVEs, conference talks (Black Hat, DEF CON, etc.), or notable open-source contributions

  • Familiarity with secure development lifecycle, threat modeling methodologies, and product security programs

Salary range is $190,000 to $240,000 depending on experience, level, and business need. This role may be eligible for discretionary bonus, incentives and benefits.

We know that creativity and innovation happen more often when teams include diverse ideas, backgrounds, and experiences, and we actively encourage everyone with relevant experience to apply, including people of color, LGBTQ+ and non-binary people, veterans, parents, and individuals with disabilities.

Numbers & Facts

LocationSan Jose, CA
Salary$190,000–$240,000 Per Year

Skills

  • Analysis Skillsunmatched
  • Artificial Intelligence (AI)unmatched
  • Assembly Languageunmatched
  • Automationunmatched
  • C Programming Languageunmatched
  • C++ Programming Languageunmatched
  • Cloud Computingunmatched
  • Computer Engineeringunmatched
  • Computer Firmwareunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Diversityunmatched
  • Ecosystemsunmatched
  • Electrical Engineeringunmatched
  • Embedded Systemsunmatched
  • Establish Prioritiesunmatched
  • Ethernetunmatched
  • GPEN - GIAC Penetration Testerunmatched
  • Information Technology & Information Systemsunmatched
  • Leadershipunmatched
  • Machine Toolunmatched
  • Mentoringunmatched
  • Metricsunmatched
  • Model Reviewunmatched
  • PCI Express (PCI-E)unmatched
  • Penetration Testingunmatched
  • Product Engineeringunmatched
  • Product Lifecycleunmatched
  • Product Programsunmatched
  • Prototypingunmatched
  • Python Programming/Scripting Languageunmatched
  • Research Skillsunmatched
  • Riskunmatched
  • Semiconductorsunmatched
  • Simulationunmatched
  • Software as a Service (SaaS)unmatched
  • Surface Modelingunmatched
  • Technical Researchunmatched
  • Testingunmatched
  • Threat Modelingunmatched
  • Validation Testingunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder