Manager, Offensive Security

SiTime Corporation•Santa Clara, CA

About The Position

SiTime is the Precision Timing company. Timing is the heartbeat of all electronics, ensuring performance, resilience and scalability. For decades, quartz devices, non-silicon technology, have kept systems in sync, but they struggle in harsher, more demanding environments. MEMS-based Precision Timing delivers greater accuracy, smaller size and resilience. Today, MEMS timing powers over 400 applications, including high-growth ones in AI datacenters, automated driving, industrial and humanoid robots, wearables and IoT. Our semiconductor MEMS programmable solutions offer a rich feature set that enables customers to differentiate their products with higher performance, smaller size, lower power, and better reliability. With more than 4 billion devices shipped, SiTime is changing the timing industry.

Requirements

  • 6+ years in offensive security, penetration testing or red teaming, including 2+ years leading a program or a team.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field — or equivalent practical experience.
  • At least one of the following certifications: OSCP, OSEP, OSCE, , or equivalent.
  • Demonstrated hands-on exploitation capability across network, cloud, application, identity and endpoint.
  • Experience designing and running red and purple team exercises and mapping coverage to MITRE ATT&CK.
  • Experience managing external testing vendors and running a vulnerability disclosure or bug bounty program.
  • Ability to write findings that engineers can act on and executives can understand.
  • People leadership or technical lead experience.
  • English proficiency is required, including the ability to effectively communicate, collaborate, and perform job responsibilities in a professional business environment.

Nice To Haves

  • Experience in a semiconductor, hardware, embedded or OT-adjacent environment.
  • Hardware and firmware testing experience, including secure boot and debug interface exposure.
  • Cloud exploitation and identity attack path analysis in Azure and AWS.
  • Source code review and application security testing capability.
  • Experience testing engineering, design or laboratory environments without disrupting them.

Responsibilities

  • Run a recurring penetration testing program across enterprise, cloud, SaaS, application, network and laboratory environments, covering both grey box and black box engagements.
  • Scope, plan and execute internal testing, and manage external testing firms where specialist capability or independence is required.
  • Prioritize testing around the paths that reach design data, source code repositories, laboratory and test networks, and partner and OSAT connectivity.
  • Own the finding lifecycle end to end: severity, named owner, remediation service level, retest and closure with evidence.
  • Move the program from point-in-time assessment toward continuous validation of the controls that matter most.
  • Design and run threat-informed red team exercises against realistic objectives, with clear rules of engagement and authorization.
  • Run purple team exercises jointly with Security Operations to validate and improve detection coverage, mapping results to MITRE ATT&CK.
  • Validate that deployed controls detect and prevent, and route the gaps to Security Engineering and Security Operations with reproducible evidence.
  • Simulate insider and data exfiltration scenarios to test data loss prevention, access controls and monitoring on the design environment.
  • Contribute technical injections and scenarios to ransomware and crisis tabletop exercises.
  • Track adversary tradecraft relevant to semiconductors, hardware and intellectual property theft, including state-linked activity, and translate it into test scenarios.
  • Stand up and run vulnerability disclosure and bug bounty programs, including scope definition, triage, reward policy and researcher relations.
  • Define the rules, authorization and safety controls that keep offensive activity inside agreed boundaries and out of production impact.
  • Build the internal testing capability over time, and manage the specialist firms that supplement it.
  • Support customer-facing security assurance by providing independent evidence of testing coverage and remediation.
  • Feed recurring themes back into the security roadmap, architecture standards and awareness content.

Benefits

  • Quarterly bonus tied to the achievement of innovation goals
  • Equity grants
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service