Senior Principal Engineer, Offensive Security

Astera Labs

San Jose (CA)

On-site

USD 220,000 - 320,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible time off
Parental leave
401K
Retirement and pension plans
Medical, dental and vision plans

Job summary

Astera Labs in California seeks a Senior Principal Engineer, Offensive Security to shape red teaming, penetration testing, and adversary research across hardware, firmware, software, cloud, and enterprise IT.

You will mentor security engineers, define engagement rules, drive remediation with product and engineering teams, and communicate risk to executives, customers, and the broader security community.

Qualifications

  • 12+ years of offensive security experience including red teaming, penetration testing, and vulnerability research.
  • Experience in hardware/firmware security, embedded systems, cloud or SaaS security, and network/application penetration testing.
  • Knowledge of attacker tradecraft and MITRE ATT&CK.
  • Certifications such as OSCP, OSEP, OSED, GXPN, GPEN.

Responsibilities

  • Define and lead offensive security strategy across hardware, firmware, software, cloud, and enterprise IT.
  • Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets.
  • Mentor security engineers and drive remediation with product engineering teams.
  • Communicate security posture to customers, executives, and partners; contribute to secure-by-design reviews.

Skills

Offensive security leadership
Threat modeling
Adversary emulation
Mentoring security engineers
Communicating risk to executives

Education

Bachelor's degree in CS/CE/EE
MS/PhD in security

Tools

Python
C/C++
Assembly

Job description

  • Astera Labs is building the connectivity fabric powering rack-scale AI, and securing that fabric is mission-critical
  • As Senior Principal Engineer, Offensive Security, you’ll be our most senior technical authority on adversarial testing — proactively finding, exploiting, and helping remediate weaknesses across our silicon, firmware, systems, cloud, and corporate environments before adversaries can
  • This is a hands-on, deeply technical role for a proven offensive security leader who wants outsized impact at a hyper-growth semiconductor company enabling the world’s largest AI clusters
  • You’ll set the technical direction for red teaming, penetration testing, and offensive research, partner closely with product and IT security teams, and help harden the platforms that hyperscalers rely on
  • Offensive Security Strategy & Execution
  • Define and lead Astera Labs’ offensive security strategy across hardware, firmware, software, cloud, and enterprise IT
  • Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets
  • Establish scope, rules of engagement, and success metrics for offensive programs in partnership with security leadership
  • Technical Depth & Research
  • Conduct advanced vulnerability research and exploit development across hardware/firmware, embedded systems, and cloud/SaaS environments
  • Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world threat actors (e.g., MITRE ATT&CK)
  • Prototype tooling and automation to scale offensive testing and continuous validation of controls
  • Partnership & Remediation
  • Partner with product security, engineering, IT, and GRC teams to prioritize findings, drive remediation, and validate fixes
  • Communicate complex technical risk clearly to engineering leaders and executives, translating exploits into actionable business impact
  • Contribute to secure-by-design reviews, threat models, and architecture guidance for new products and platforms
  • Leadership & Culture
  • Mentor security engineers and elevate offensive security capability across the organization
  • Represent Astera Labs’ security posture with customers, partners, and (as appropriate) the broader research community
  • Champion a builder mindset that pairs rigorous adversarial testing with pragmatic, engineering-friendly remediation
Benefits
  • Flexible time off in the US
  • Parental leave
  • 401K
  • Retirement and pension plans
  • Competitive medical, dental and vision plans

Proficiency with offensive tooling and exploit development in languages such as Python, C/C++, and assembly12+ years of experience in offensive security, including red teaming, penetration testing, and/or vulnerability researchDemonstrated expertise in at least two of the following domains: hardware/firmware security, embedded systems, cloud (Azure preferred) and SaaS security, network and application penetration testing, or Active Directory / Microsoft enterprise environmentsDeep understanding of modern attacker tradecraft, TTPs, and frameworks such as MITRE ATT&CKProven track record of driving remediation and measurable security improvements in partnership with engineering teamsBachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical fieldAdvanced degree (MS or PhD) in a security-related disciplineIndustry certifications such as OSCP, OSEP, OSED, GXPN, GPEN, or equivalent demonstrated experienceExperience in the semiconductor, hardware, or hyperscale infrastructure industry, including exposure to PCIe, CXL, or high-speed connectivity technologiesPublished research, CVEs, conference talks (Black Hat, DEF CON, etc.), or notable open‑source contributionsFamiliarity with secure development lifecycle, threat modeling methodologies, and product security programs

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Principal Engineer, Offensive Security (2026-345)
Senior Principal Engineer, Offensive Security (2026-345)

Asteralabs • San Jose (CA)

On-site
USD 190,000 - 240,000
Senior Principal Engineer, Security Architect
Senior Principal Engineer, Security Architect

Astera Labs • San Jose (CA)

On-site
USD 210,000 - 320,000
Flexible time off in the US
Parental leave
401K
+2
Senior Principal Engineer, Security Architect (2026- 346)
Senior Principal Engineer, Security Architect (2026- 346)

Asteralabs • San Jose (CA)

On-site
USD 190,000 - 240,000
Senior Principal Offensive Security Engineer — Hardware & Cloud
Senior Principal Offensive Security Engineer — Hardware & Cloud

Astera Labs • San Jose (CA)

On-site
USD 220,000 - 320,000
Flexible time off
Parental leave
401K
+2
Senior Offensive Security Architect – Hardware & Cloud
Senior Offensive Security Architect – Hardware & Cloud

Asteralabs • San Jose (CA)

On-site
USD 190,000 - 240,000
Senior Principal Security Architect (Hardware & Cloud)
Senior Principal Security Architect (Hardware & Cloud)

Astera Labs • San Jose (CA)

On-site
USD 210,000 - 320,000
Flexible time off in the US
Parental leave
401K
+2
Sr. Principal – Server Firmware & System Architecture
Sr. Principal – Server Firmware & System Architecture

Asteralabs • North Carolina

On-site
USD 150,000 - 200,000
Senior Associate, Offensive Security
Senior Associate, Offensive Security

Jobtailor • New York (NY)

Hybrid
USD 120,000 - 160,000
Senior Principal Cybersecurity Engineer
Senior Principal Cybersecurity Engineer

Jobtailor • Troy (MO)

On-site
USD 120,000 - 170,000
Managing Principal, Red Team Operator
Managing Principal, Red Team Operator

Armadin • Palo Alto (CA)

On-site
USD 200,000 - 320,000
Full Health, Dental, & Vision Coverage
Meaningful Equity Ownership
In-Office Meals
+3