Astera Labs Inc.
Senior Principal Engineer, Offensive Security
San Jose, California, United States · Principal
Stay score
odds of building a lasting career here
Sponsors, but it's cap-subject — you still face the weighted lottery (~61% per draw at Level IV). Good if you win; have a cap-exempt backup on your list.
Lottery odds assume a STEM candidate.
Personalize to your clock →Employer immigration record
from this employer's Department of Labor filings
Green-card filing pattern in this occupation
Files H-1B transfers
Sourced from Department of Labor LCA, PERM and prevailing-wage disclosure data. Employer matching is by name, so figures may be split across an employer's legal entities. Absence of a filing means none appears in our copy of the data, not that none exists.
Community outcomes
No reports yet — be the first to help the next applicant.
About the role
- This is a hands-on, deeply technical role for a proven offensive security leader who wants outsized impact at a hyper-growth semiconductor company enabling the world's largest AI clusters.
Responsibilities
- Define and lead Astera Labs' offensive security strategy across hardware, firmware, software, cloud, and enterprise IT
- Drive threat modeling, attack surface analysis, and adversary simulation aligned to real-world threat actors (e.g., MITRE ATT&CK)
- Partner with product security, engineering, IT, and GRC teams to prioritize findings, drive remediation, and validate fixes
- Contribute to secure-by-design reviews, threat models, and architecture guidance for new products and platforms
Requirements
- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field
- 12+ years of experience in offensive security, including red teaming, penetration testing, and/or vulnerability research
- Proficiency with offensive tooling and exploit development in languages such as Python, C/C++, and assembly
- Proven track record of driving remediation and measurable security improvements in partnership with engineering teams
Nice to have
- Advanced degree (MS or PhD) in a security-related discipline
- Industry certifications such as OSCP, OSEP, OSED, GXPN, GPEN, or equivalent demonstrated experience
- Experience in the semiconductor, hardware, or hyperscale infrastructure industry, including exposure to PCIe, CXL, or high-speed connectivity technologies
- Published research, CVEs, conference talks (Black Hat, DEF CON, etc.), or notable open-source contributions
- Familiarity with secure development lifecycle, threat modeling methodologies, and product security programs
Skills
- Offensive Security Strategy & Execution
- Plan and execute red team, penetration testing, and adversary emulation engagements against production and pre-production assets
- Establish scope, rules of engagement, and success metrics for offensive programs in partnership with security leadership
- Technical Depth & Research
- Conduct advanced vulnerability research and exploit development across hardware/firmware, embedded systems, and cloud/SaaS environments
- Prototype tooling and automation to scale offensive testing and continuous validation of controls
- Partnership & Remediation
- Communicate complex technical risk clearly to engineering leaders and executives, translating exploits into actionable business impact
- Leadership & Culture
- Mentor security engineers and elevate offensive security capability across the organization
- Champion a builder mindset that pairs rigorous adversarial testing with pragmatic, engineering-friendly remediation
Compensation
- Salary range is $190,000 to $240,000 depending on experience, level, and business need.
Company info
- Represent Astera Labs' security posture with customers, partners, and (as appropriate) the broader research community
This listing is sourced directly from Astera Labs Inc.'s careers page and normalized into a canonical job model.