Senior Principal Engineer, Security Architect (2026- 346)
Astera LabsBase Salary
$190k - $240k/yr
Responsibilities
- Define and own end-to-end security architecture across product and enterprise domains.
- Establish security reference architectures, design patterns, and standards across teams and product lines.
- Lead threat modeling, attack surface analysis, and security design reviews for products, features, and platforms.
- Drive secure development lifecycle practices across requirements, design, implementation, and validation.
- Evaluate cryptography, key management, secure boot, attestation, and supply chain integrity approaches for hardware and firmware.
- Architect zero-trust, identity, network, and data protection controls across Azure, Entra, M365, and the SaaS ecosystem.
- Guide secure design of build, CI/CD, developer, and EDA/tooling environments.
- Define standards for logging, telemetry, and detection engineering inputs in partnership with security operations.
- Advise engineering, product, IT, and GRC leadership on complex security trade-offs.
- Translate architectural direction into prioritized roadmaps and measurable outcomes.
- Mentor engineers and architects across the organization.
Requirements
- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field.
- 12+ years of progressive experience in security engineering and architecture across product and/or enterprise domains.
- Expertise designing secure architectures spanning hardware/firmware, software, cloud, and enterprise IT.
- Deep knowledge of cryptography, identity and access management, network security, and modern threat models such as MITRE ATT&CK.
- Hands-on experience with cloud security architecture, preferably Azure, and Microsoft enterprise environments including Entra, M365, and Active Directory.
- Ability to influence engineering and executive stakeholders and drive complex, cross-functional security initiatives.
- Advanced degree in a security-related discipline is preferred.
- Industry certifications such as CISSP-ISSAP, SABSA, TOGAF, Azure Security Engineer/Architect, or equivalent demonstrated experience are preferred.
- Experience in the semiconductor, hardware, or hyperscale infrastructure industry and familiarity with PCIe, CXL, or high-speed connectivity technologies are preferred.
- Experience with secure boot, hardware root of trust, attestation, confidential computing, and supply chain security is preferred.
- Familiarity with SOC 2, ISO 27001, NIST, and data privacy regulations is preferred.
Benefits
- Potential eligibility for discretionary bonus, incentives, and benefits.
- On-site role located in San Jose, California.
About Astera Labs
Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs’ Intelligent Connectivity Platform integrates CXL®, Ethernet, NVLink™ Fusion, PCIe®, and UALink™ semiconductor-based technologies with the company’s COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company’s custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at www.asteralabs.com.