$190,000 - $240,000 USD yearly
Originally posted 31 July 2026 by the employer — open 41 days.
This role focuses on security architecture for CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor technologies.
About the role
This Senior Principal Engineer, Security Architect role defines how security is integrated into Astera Labs products, spanning silicon and firmware to cloud services, tools, and enterprise systems. The position involves shaping security for rack-scale AI infrastructure, focusing on CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor technologies.
What you'll do
- Define and own end-to-end security architecture across product (silicon, firmware, systems) and enterprise (cloud, SaaS, IT) domains.
- Establish security reference architectures, design patterns, and standards.
- Lead threat modeling, attack surface analysis, and security design reviews for products.
- Drive secure development lifecycle (SDL) practices, including requirements, design, implementation, and validation gates.
- Evaluate cryptography, key management, secure boot, attestation, and supply chain integrity approaches for hardware and firmware.
- Architect zero-trust, identity, network, and data protection controls across Microsoft-centric enterprise (Azure, Entra, M365) and SaaS ecosystem.
What you'll need
- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field.
- 12+ years of progressive experience in security engineering and architecture across product and/or enterprise domains.
- Expertise designing secure architectures spanning hardware/firmware, software, cloud, and enterprise IT.
- Deep knowledge of cryptography, identity and access management, network security, and modern threat models (e.g., MITRE ATT&CK).
- Hands-on experience with cloud security architecture (Azure preferred) and Microsoft enterprise environments (Entra, M365, Active Directory).
- Ability to influence engineering and executive stakeholders and drive complex, cross-functional security initiatives.
Nice to have
- Advanced degree (MS or PhD) in a security-related discipline.
- Industry certifications such as CISSP-ISSAP, SABSA, TOGAF, Azure Security Engineer/Architect.
- Experience in the semiconductor, hardware, or hyperscale infrastructure industry, including familiarity with PCIe, CXL, or high-speed connectivity technologies.
- Experience with secure boot, hardware root of trust, attestation, confidential computing, and supply chain security.
- Familiarity with regulatory and industry frameworks such as SOC 2, ISO 27001, NIST, and data privacy regulations.
Skills: security architecture, silicon, firmware, threat modeling, secure boot, supply chain integrity
This role has been open 40 days — well below the 50-day median for Hardware Security Engineering roles.
Hardware Security Engineering · Hardware Security
|
Open roles in category
148
|
Median days open
50 d
|
Median salary
$220k
|
See the full market breakdown ▾Category comparison, skills in demand, and who else is hiring
| Metric | Astera Labs | All employers we track in this specialty (148 roles · 40 employers) |
|---|---|---|
| Open roles in this specialty | 1 | 148 |
| Median days open | 40 d | 50 d (−10 d vs this employer) |
| Median salary (USD postings) | — | $220k |
Skills observed across this category: security architecture, silicon, firmware, threat modeling, secure boot, supply chain integrity
Who's hiring in this category
- NXP Semiconductors · 21 open roles · median 77 d
- Qualcomm · 19 open roles · median 86 d
- NVIDIA · 14 open roles · median 29 d
- Arm Holdings · 13 open roles · median 64 d
- AMD · 10 open roles · median 22 d
- Intel Corporation · 7 open roles · median 97 d
How we counted: 148 open Hardware Security Engineering (Hardware Security) roles from 40 employers tracked in the SemiconductorJobs index, counted 10 Sept 2026. Specialty figures count only roles carrying this exact specialty label, so an employer's related work in neighbouring specialties is not included there. Figures refresh nightly.