Sr. Manager, Security Risk, Assurance and Trust
Santa Clara County, CA - USA
Job Summary
About SiTime
SiTime is the Precision Timing company.
Timing is the heartbeat of all electronics ensuring performance resilience and scalability. For decades quartz devices non-silicon technology have kept systems in sync but they struggle in harsher more demanding environments. MEMS-based Precision Timing delivers greater accuracy smaller size and resilience. Today MEMS timing powers over 400 applications including high-growth ones in AI datacenters automated driving industrial and humanoid robots wearables and IoT.
Our semiconductor MEMS programmable solutions offer a rich feature set that enables customers to differentiate their products with higher performance smaller size lower power and better reliability. With more than 4 billion devices shipped SiTime is changing the timing industry. For more information visit:.
Job Summary
Reporting to the CISO this role builds and leads SiTimes Security Risk Assurance and Trust function. It owns customer security audits and trust third-party and vendor risk management the enterprise risk register security policy and governance compliance certifications and SOX compliance support the audits risk and assurance pillar of the security organization.
This is a build role. The successful candidate will design and establish the enterprise risk register the third-party risk program the certification program and the security policy and standards framework.
It is also a people-leadership role. The candidate starts hands-on personally delivering the first cycle of each program then scales the function through a mix of full-time hires and specialist contractors engaged for assessment cycles certification readiness and audit surge capacity.
This is an accountable owner role not an advisory one. The role is the strategic and enforcement arm of the CISOs office: it sets risk and governance strategy then partners with IT Legal Finance Design and Engineering and cross-functionally with the CISOs other security functions (Vulnerability Management & Security Operations Security Engineering Security Architecture and Offensive Security) to drive that strategy into implemented verified controls and coordinated initiatives that improve the companys overall security posture.
It is not necessary to meet all job requirements to be a qualified candidate for the position.
Responsibilities:
External Assurance Customer Trust Certification & SOX
- Own customer security assurance end to end. Build the reusable trust package including security whitepaper certification and audit-report library standard response templates and the response process.
- Distinguish formal customer audit findings from ad hoc customer requests for additional security controls or contractual commitments resourcing and tracking each independently to closure.
- Drive remediation of gaps identified through customer audits with IT Engineering and system owners tracking every finding to closure and feeding recurring themes back into the security roadmap.
- Own SiTimes ISO 27001 certification end to end including scoping gap assessment control implementation readiness external audit and ongoing surveillance.
- Monitor the certification and regulatory landscape relevant to SiTimes customers markets and geographies; recommend and pursue additional certifications or attestations as business need emerges.
- Serve as the primary point of contact for external auditors and certification bodies ensuring evidence timelines and remediation commitments are consistently met.
- Support SOX IT General Controls compliance with Internal Audit Finance and IT and serve as the primary security liaison for SOX testing cycles the annual external audit of internal controls over financial reporting deficiency tracking and remediation.
Enterprise Risk Register Third-Party Risk & Assessments
- Build and own the enterprise risk register aggregating signals from vulnerability management third-party risk audits and incidents into a single prioritized view with named owners and remediation timelines and use it to shape and prioritize the security roadmap company-wide.
- Design and operate the third-party and vendor risk management program covering onboarding risk tiering and ongoing monitoring including supply-chain partners critical to SiTimes fabless model.
- Direct technical security risk assessments of critical enterprise assets and third-party systems
- Partner with Legal and Procurement to embed security requirements into vendor contracts and the procurement process and to evaluate security posture as part of vendor selection.
- Drive remediation of vendor-identified risks to closure within defined SLAs working directly with vendors and internal system owners.
- Establish the assessment cadence against NIST CSF and NIST SP 800-53 running the first cycle directly then scaling through the team and contractors. Extend coverage to NIST SP 800-171 and NIST SP 800-161 as business need dictates.
- Facilitate third-party independent assessments and readiness reviews managing scoping coordination and remediation of findings.
- As the program matures stand up and chair a cross-functional Risk Committee with Security IT Engineering Legal and Finance with a defined recurring cadence to review the register adjudicate risk-acceptance decisions and surface material risks for executive visibility.
- Produce the recurring risk reporting that enables the CISOs executive and Audit Committee/Board updates on a consistent cadence.
Governance & Enforcement Policy Standards & Control Effectiveness
- Own the security policy and standards framework end to end creating policy with Engineering and IT and translating it into enforceable technical standards and control baselines.
- Establish a recurring policy review and refresh cycle aligned to evolving frameworks (NIST ISO) and business change including ongoing M&A integration activity.
- Stand up formal policy exception management with risk-based approval workflows required compensating controls and expiration and renewal tracking so exceptions stay visible and time-boxed
- Establish oversight and monitoring of security control implementation and effectiveness company-wide including security health dashboards that give the CISO and business leaders real-time visibility into program maturity.
- Define and track KPIs and KRIs for control effectiveness using results to drive continuous improvement.
Qualifications & Requirements:
- 8 years in information security risk or assurance including 3 years building or substantially rebuilding a program
- Bachelors degree in Computer Science Information Security Engineering or a related technical field or equivalent practical experience.
- At least one of the following certifications: CISSP CISA CRISC or CCSK.
- People leadership experience
- Technical fluency across cloud platforms (Azure AWS) infrastructure security (network endpoint IAM) and third-party risk frameworks
- Working mastery of NIST CSF NIST SP 800-53 ISO 27001 and SOX ITGC with hands-on experience managing external audits and certifications end to end.
- Hands-on experience designing and running a third-party and vendor risk management program including vendor tiering ongoing monitoring and remediation workflows.
- Experience building and maintaining an enterprise risk register and producing risk reporting for executive and Audit Committee/Board consumption.
- English proficiency is required including the ability to effectively communicate collaborate and perform job responsibilities in a professional business environment.
Preferred:
- Experience in a semiconductor hardware or other fabless/manufacturing environment or another regulated hardware/OT-adjacent industry.
- Familiarity with data privacy regimes (GDPR and equivalents) where they intersect customer due diligence and vendor contracting.
Desired Characteristics & Attributes:
- Strong executive presence and stakeholder management: able to translate complex technical security concepts into business-friendly risk-oriented language and influence decision-making across functions without direct authority.
- Program management rigor with ablity to run multiple concurrent cross-functional initiatives to completion not just track them.
Compensation Range:
At SiTime we believe great work deserves great rewards. We offer a comprehensive and highly competitive compensation package designed to attract top talent.
The annual base salary range for this role is $154710 $221230. The final offer is determined by factors such as location experience education and training.
In addition to base salary this role is eligible for a quarterly bonus tied to the achievement of innovation goalsreflecting our commitment to recognizing meaningful impact. We also offer equity grants providing a meaningful opportunity to share in the companys future growth and success.
Benefits offered: 401k plan health and wellness that includes medical dental vision life parental leave legal services and time off plans.
SiTime is anEqual Opportunity Employer. We treat each person fairly and we do not tolerate discrimination or harassment against anyone on the basis of any protected characteristics including race color religion national or ethnic origin sex sexual orientation gender identity or expression age disability pregnancy political affiliation protected veteran status protected genetic information or marital status or other characteristics protected by law. SiTime participates in theE-Verifyprogram.
Learn More about SiTime:Review theGet to Know SiTimesection of our career page to explore our culture values and what makes us unique.
- Innovation on Top Philosophies of Innovation with Rajesh Vashist
- Fabrication Knowledge An Interview with Rajesh Vashist
- SiTime Corporation YouTube
Required Experience:
Manager
About Company
SiTime is a leader in MEMS timing solutions, having shipped billions of units. Learn about our silicon MEMS oscillators, TCXOs, OCXOs, MEMS resonators, clock generators, jitter cleaners, clock timing, timing clock, sitm stock, and much more.