Job SummaryReporting to the CISO, this role leads SiTime's Offensive Security function. It owns penetration testing, red and purple team exercises, vulnerability disclosure and bug bounty, and validation that the controls SiTime has bought and built actually work.
This is a build role. The candidate will design a recurring testing program that covers the enterprise, cloud, SaaS, application and laboratory estates, establish adversary simulation against realistic objectives, and create the feedback loop that turns findings into improved detection and hardening rather than a report that is filed away.
It is also a people-leadership role. The candidate starts hands-on, personally running the first cycle of testing, then scales through a mix of full-time testers and specialist firms engaged where independence or niche capability is required.
This is an accountable owner role, not an advisory one. Findings are owned through to verified closure in partnership with Security Engineering, Vulnerability Management and Security Operations, Security Architecture, IT and Engineering.
We value diverse experiences, perspectives, and career paths, and welcome candidates who are excited to contribute to our mission.
Responsibilities:Offensive Testing Program- Run a recurring penetration testing program across enterprise, cloud, SaaS, application, network and laboratory environments, covering both grey box and black box engagements.
- Scope, plan and execute internal testing, and manage external testing firms where specialist capability or independence is required.
- Prioritize testing around the paths that reach design data, source code repositories, laboratory and test networks, and partner and OSAT connectivity.
- Own the finding lifecycle end to end: severity, named owner, remediation service level, retest and closure with evidence.
- Move the program from point-in-time assessment toward continuous validation of the controls that matter most.
Red Team, Purple Team and Detection Validation- Design and run threat-informed red team exercises against realistic objectives, with clear rules of engagement and authorization.
- Run purple team exercises jointly with Security Operations to validate and improve detection coverage, mapping results to MITRE ATT&CK.
- Validate that deployed controls detect and prevent, and route the gaps to Security Engineering and Security Operations with reproducible evidence.
- Simulate insider and data exfiltration scenarios to test data loss prevention, access controls and monitoring on the design environment.
- Contribute technical injections and scenarios to ransomware and crisis tabletop exercises.
- Track adversary tradecraft relevant to semiconductors, hardware and intellectual property theft, including state-linked activity, and translate it into test scenarios.
Disclosure, Bug Bounty and Program Scaling- Stand up and run vulnerability disclosure and bug bounty programs, including scope definition, triage, reward policy and researcher relations.
- Define the rules, authorization and safety controls that keep offensive activity inside agreed boundaries and out of production impact.
- Build the internal testing capability over time, and manage the specialist firms that supplement it.
- Support customer-facing security assurance by providing independent evidence of testing coverage and remediation.
- Feed recurring themes back into the security roadmap, architecture standards and awareness content.
Qualifications & Requirements : - 6+ years in offensive security, penetration testing or red teaming, including 2+ years leading a program or a team.
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field - or equivalent practical experience.
- At least one of the following certifications: OSCP, OSEP, OSCE, , or equivalent.
- Demonstrated hands-on exploitation capability across network, cloud, application, identity and endpoint.
- Experience designing and running red and purple team exercises and mapping coverage to MITRE ATT&CK.
- Experience managing external testing vendors and running a vulnerability disclosure or bug bounty program.
- Ability to write findings that engineers can act on and executives can understand.
- People leadership or technical lead experience.
- English proficiency is required, including the ability to effectively communicate, collaborate, and perform job responsibilities in a professional business environment.
Preferred:- Experience in a semiconductor, hardware, embedded or OT-adjacent environment.
- Hardware and firmware testing experience, including secure boot and debug interface exposure.
- Cloud exploitation and identity attack path analysis in Azure and AWS.
- Source code review and application security testing capability.
- Experience testing engineering, design or laboratory environments without disrupting them.
Desired Characteristics & Attributes:- Strong ethics and judgment: operates within authorization, documents everything, and knows when to stop.
- Evidence-driven and measured on risk reduced and detections improved
- Constructive with the teams being tested; builds partnership rather than an adversarial dynamic.
- Able to work effectively with a U.S.-based CISO and U.S. stakeholders across time zones.
Compensation Range:At SiTime, we believe great work deserves great rewards. We offer a comprehensive and highly competitive compensation package designed to attract top talent.
In addition to base salary, this role is eligible for a quarterly bonus tied to the achievement of innovation goals-reflecting our commitment to recognizing meaningful impact. We also offer equity grants, providing a meaningful opportunity to share in the company's future growth and success.
Learn More about SiTime: Review the Get to Know SiTime section of our career page to explore our culture, values, and what makes us unique.
- Innovation on Top - Philosophies of Innovation with Rajesh Vashist
- Fabrication Knowledge - An Interview with Rajesh Vashist
- SiTime Corporation - YouTube