Senior Principal Engineer, Offensive Security (2026-345)
Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs’ Intelligent Connectivity Platform integrates CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor-based technologies with the company’s COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company’s custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at www.asteralabs.com. Senior Principal Engineer, Offensive Security (2026-345) Location: San Jose, CA Role Overview Astera Labs is building the connectivity fabric powering rack-scale AI, and securing that fabric is mission-critical. As Senior Principal Engineer, Offensive Security, you'll be our most senior technical authority on adversarial testing — proactively finding, exploiting, and helping remediate weaknesses across our silicon, firmware, systems, cloud, and corporate environments before adversaries can. This is a hands-on, deeply technical role for a proven offensive security leader who wants outsized impact at a hyper-growth semiconductor company enabling the world's largest AI clusters. You'll set the technical direction for red teaming, penetration testing, and offensive research, partner closely with product and IT security teams, and help harden the platforms that hyperscalers rely on. Key Responsibilities Offensive Security Strategy & Execution Define and lead Astera Labs' offensive security strategy across hardware, firmware, software, cloud, and enterprise IT Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets Establish scope, rules of engagement, and success metrics for offensive programs in partnership with security leadership Technical Depth & Research Conduct advanced vulnerability research and exploit development across hardware/firmware, embedded systems, and cloud/SaaS environments Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world threat actors (e.g., MITRE ATT&CK) Prototype tooling and automation to scale offensive testing and continuous validation of controls Partnership & Remediation Partner with product security, engineering, IT, and GRC teams to prioritize findings, drive remediation, and validate fixes Communicate complex technical risk clearly to engineering leaders and executives, translating exploits into actionable business impact Contribute to secure-by-design reviews, threat models, and architecture guidance for new products and platforms Leadership & Culture Mentor security engineers and elevate offensive securit...