Senior Principal Engineer, Security Architect (2026- 346)

Find out how well you fit this job.

Job updated about 19 hours ago
The employer was active about 21 hours ago

Job Description

Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs’ Intelligent Connectivity Platform integrates CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor-based technologies with the company’s COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company’s custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at www.asteralabs.com.

 

Senior Principal Engineer, Security Architect (2026- 346)

Location: San Jose, CA

Role Overview

Astera Labs is building the connectivity backbone of the AI era, and the platforms we ship power the world's largest AI clusters. As Senior Principal Engineer, Security Architect, you'll be the most senior technical authority defining how security is designed into everything we build — from silicon and firmware to the cloud services, tools, and enterprise systems that support them.

This is a hands-on, deeply technical architect role for someone who wants to shape security at a hyper-growth semiconductor company enabling rack-scale AI infrastructure. You'll set architectural direction, drive threat modeling and secure-by-design reviews across product and IT, and partner with engineering, product security, GRC, and IT leadership to raise the security bar in a fast-moving environment.

Key Responsibilities

  • Security Architecture & Strategy

    • Define and own the end-to-end security architecture across product (silicon, firmware, systems) and enterprise (cloud, SaaS, IT) domains

    • Establish security reference architectures, design patterns, and standards that scale across teams and product lines

    • Partner with engineering and IT leaders to align architectural direction with business, product, and compliance priorities

  • Threat Modeling & Secure-by-Design

    • Lead threat modeling, attack surface analysis, and security design reviews for new products, features, and platforms

    • Drive secure development lifecycle (SDL) practices, including requirements, design, implementation, and validation gates

    • Evaluate cryptography, key management, secure boot, attestation, and supply chain integrity approaches for hardware and firmware

  • Enterprise & Cloud Architecture

    • Architect zero-trust, identity, network, and data protection controls across the Microsoft-centric enterprise (Azure, Entra, M365) and SaaS ecosystem

    • Guide secure design of build, CI/CD, developer, and EDA/tooling environments

    • Define standards for logging, telemetry, and detection engineering inputs in partnership with security operations

  • Partnership & Technical Leadership

    • Serve as a trusted advisor to engineering, product, IT, and GRC leadership on complex security trade-offs

    • Translate architectural direction into pragmatic, prioritized roadmaps and measurable outcomes

    • Mentor engineers and architects across the organization, elevating security capability company-wide

Basic Qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field

  • 12+ years of progressive experience in security engineering and architecture across product and/or enterprise domains

  • Demonstrated expertise designing secure architectures spanning hardware/firmware, software, cloud, and enterprise IT

  • Deep knowledge of cryptography, identity and access management, network security, and modern threat models (e.g., MITRE ATT&CK)

  • Hands-on experience with cloud security architecture (Azure preferred) and Microsoft enterprise environments (Entra, M365, Active Directory)

  • Proven ability to influence engineering and executive stakeholders and drive complex, cross-functional security initiatives

Preferred Qualifications

  • Advanced degree (MS or PhD) in a security-related discipline

  • Industry certifications such as CISSP-ISSAP, SABSA, TOGAF, Azure Security Engineer/Architect, or equivalent demonstrated experience

  • Experience in the semiconductor, hardware, or hyperscale infrastructure industry, including familiarity with PCIe, CXL, or high-speed connectivity technologies

  • Experience with secure boot, hardware root of trust, attestation, confidential computing, and supply chain security

  • Familiarity with regulatory and industry frameworks such as SOC 2, ISO 27001, NIST, and data privacy regulations

Salary range is $190,000 to $240,000 depending on experience, level, and business need. This role may be eligible for discretionary bonus, incentives and benefits.

We know that creativity and innovation happen more often when teams include diverse ideas, backgrounds, and experiences, and we actively encourage everyone with relevant experience to apply, including people of color, LGBTQ+ and non-binary people, veterans, parents, and individuals with disabilities.

View all jobs

Find out how well you fit this job.

View all jobs

Find out how well you fit this job.

Find out how well you fit this job.

Personal Invitation Link
This is your personal referral link for job invitation. You'll receive an email notification when someone applied for the position via your job link.
Share this job

About us

||About Astera Labs||

Astera Labs is a global leader in purpose-built connectivity solutions for rack-scale AI, redefining the future of data center infrastructure. Our pioneering software-defined architecture delivers unmatched scalability and customization to meet the evolving demands of AI workloads. By leveraging advanced PCIe®, CXL®, Ethernet, and UALink semiconductor-based technologies, we eliminate critical data, memory, and networking bottlenecks with exceptional efficiency. Trusted by hyperscalers and deeply integrated within the data center ecosystem, we empower next-generation performance and innovation at scale.

||Our coporate values||

Act With Intent
Take ownership with a day-one mindset and entrepreneurial spirit.

Stay Customer Focused
Relentlessly prioritize the customer’s needs, perspective and their trust in us.

Deliver Results
Have a strong bias for action, stay flexible and embrace change to relentlessly drive success.

Invent & Simplify
Innovate with a platform mindset, exponentially rather than incrementally.

Nurture Trust
Operate with integrity and the highest ethical standards to uphold trust.

Raise the Bar Together
Support, empower, and collaborate to continuously elevate expectations.