<div class="content-intro"><p><span data-teams="true">Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs’ Intelligent Connectivity Platform integrates CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor-based technologies with the company’s COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company’s custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at <a id="menurhut" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" href="http://www.asteralabs.com/" target="_blank">www.asteralabs.com</a>.</span></p></div><p> </p>
<p> </p>
<h1 class="wnfdnti _1ibi0s33y _1ibi0s34u" data-pm-slice="1 3 []">Senior Principal Engineer, Offensive Security (2026-345)</h1>
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"><strong>Location:</strong> San Jose, CA</p>
<h2 class="wnfdnti _1ibi0s33y _1ibi0s34u">Role Overview</h2>
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Astera Labs is building the connectivity fabric powering rack-scale AI, and securing that fabric is mission-critical. As Senior Principal Engineer, Offensive Security, you'll be our most senior technical authority on adversarial testing — proactively finding, exploiting, and helping remediate weaknesses across our silicon, firmware, systems, cloud, and corporate environments before adversaries can.</p>
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">This is a hands-on, deeply technical role for a proven offensive security leader who wants outsized impact at a hyper-growth semiconductor company enabling the world's largest AI clusters. You'll set the technical direction for red teaming, penetration testing, and offensive research, partner closely with product and IT security teams, and help harden the platforms that hyperscalers rely on.</p>
<h2 class="wnfdnti _1ibi0s33y _1ibi0s34u">Key Responsibilities</h2>
<ul class="wnfdntf">
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"><strong>Offensive Security Strategy & Execution</strong></p>
<ul class="wnfdntf">
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Define and lead Astera Labs' offensive security strategy across hardware, firmware, software, cloud, and enterprise IT</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Establish scope, rules of engagement, and success metrics for offensive programs in partnership with security leadership</p>
</li>
</ul>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"><strong>Technical Depth & Research</strong></p>
<ul class="wnfdntf">
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Conduct advanced vulnerability research and exploit development across hardware/firmware, embedded systems, and cloud/SaaS environments</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world threat actors (e.g., MITRE ATT&CK)</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Prototype tooling and automation to scale offensive testing and continuous validation of controls</p>
</li>
</ul>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"><strong>Partnership & Remediation</strong></p>
<ul class="wnfdntf">
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Partner with product security, engineering, IT, and GRC teams to prioritize findings, drive remediation, and validate fixes</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Communicate complex technical risk clearly to engineering leaders and executives, translating exploits into actionable business impact</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Contribute to secure-by-design reviews, threat models, and architecture guidance for new products and platforms</p>
</li>
</ul>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"><strong>Leadership & Culture</strong></p>
<ul class="wnfdntf">
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Mentor security engineers and elevate offensive security capability across the organization</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Represent Astera Labs' security posture with customers, partners, and (as appropriate) the broader research community</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Champion a builder mindset that pairs rigorous adversarial testing with pragmatic, engineering-friendly remediation</p>
</li>
</ul>
</li>
</ul>
<h2 class="wnfdnti _1ibi0s33y _1ibi0s34u">Basic Qualifications</h2>
<ul class="wnfdntf">
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">12+ years of experience in offensive security, including red teaming, penetration testing, and/or vulnerability research</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Demonstrated expertise in at least two of the following domains: hardware/firmware security, embedded systems, cloud (Azure preferred) and SaaS security, network and application penetration testing, or Active Directory / Microsoft enterprise environments</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Proficiency with offensive tooling and exploit development in languages such as Python, C/C++, and assembly</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Deep understanding of modern attacker tradecraft, TTPs, and frameworks such as MITRE ATT&CK</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Proven track record of driving remediation and measurable security improvements in partnership with engineering teams</p>
</li>
</ul>
<h2 class="wnfdnti _1ibi0s33y _1ibi0s34u">Preferred Qualifications</h2>
<ul class="wnfdntf">
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Advanced degree (MS or PhD) in a security-related discipline</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Industry certifications such as OSCP, OSEP, OSED, GXPN, GPEN, or equivalent demonstrated experience</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Experience in the semiconductor, hardware, or hyperscale infrastructure industry, including exposure to PCIe, CXL, or high-speed connectivity technologies</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Published research, CVEs, conference talks (Black Hat, DEF CON, etc.), or notable open-source contributions</p>
</li>
<li class="wnfdnte _1ibi0s33w">
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea">Familiarity with secure development lifecycle, threat modeling methodologies, and product security programs<br><br></p>
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea" data-pm-slice="1 1 []">Salary range is $190,000 to $240,000 depending on experience, level, and business need. This role may be eligible for discretionary bonus, incentives and benefits.</p>
<p class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"> </p>
</li>
</ul>
<p> </p><div class="content-conclusion"><p>We know that creativity and innovation happen more often when teams include diverse ideas, backgrounds, and experiences, and we actively encourage everyone with relevant experience to apply, including people of color, LGBTQ+ and non-binary people, veterans, parents, and individuals with disabilities.</p></div>