Sr. Manager, Security Risk, Assurance and Trust in Santa Clara, California at SiTime Corporation
Explore Related Opportunities
Job Description
About SiTime
SiTime is the Precision Timing company.
Timing is the heartbeat of all electronics, ensuring performance, resilience and scalability. For decades, quartz devices, non-silicon technology, have kept systems in sync, but they struggle in harsher, more demanding environments. MEMS-based Precision Timing delivers greater accuracy, smaller size and resilience. Today, MEMS timing powers over 400 applications, including high-growth ones in AI datacenters, automated driving, industrial and humanoid robots, wearables and IoT.
Our semiconductor MEMS programmable solutions offer a rich feature set that enables customers to differentiate their products with higher performance, smaller size, lower power, and better reliability. With more than 4 billion devices shipped, SiTime is changing the timing industry. For more information, visit: www.sitime.com.
Job Summary
Reporting to the CISO, this role builds and leads SiTime’s Security Risk, Assurance and Trust function. It owns customer security audits and trust, third-party and vendor risk management, the enterprise risk register, security policy and governance, compliance certifications, and SOX compliance support the audits, risk, and assurance pillar of the security organization.
This is a build role. The successful candidate will design and establish the enterprise risk register, the third-party risk program, the certification program, and the security policy and standards framework.
It is also a people-leadership role. The candidate starts hands-on, personally delivering the first cycle of each program, then scales the function through a mix of full-time hires and specialist contractors engaged for assessment cycles, certification readiness, and audit surge capacity.
This is an accountable owner role, not an advisory one. The role is the strategic and enforcement arm of the CISO’s office: it sets risk and governance strategy, then partners with IT, Legal, Finance, Design, and Engineering — and cross-functionally with the CISO’s other security functions (Vulnerability Management & Security Operations, Security Engineering, Security Architecture, and Offensive Security), to drive that strategy into implemented, verified controls and coordinated initiatives that improve the company’s overall security posture.
It is not necessary to meet all job requirements to be a qualified candidate for the position.
Responsibilities:
External Assurance — Customer Trust, Certification & SOX
- Own customer security assurance end to end. Build the reusable trust package including security whitepaper, certification and audit-report library, standard response templates and the response process.
- Distinguish formal customer audit findings from ad hoc customer requests for additional security controls or contractual commitments, resourcing and tracking each independently to closure.
- Drive remediation of gaps identified through customer audits with IT, Engineering, and system owners, tracking every finding to closure and feeding recurring themes back into the security roadmap.
- Own SiTime’s ISO 27001 certification end to end including scoping, gap assessment, control implementation, readiness, external audit, and ongoing surveillance.
- Monitor the certification and regulatory landscape relevant to SiTime’s customers, markets, and geographies; recommend and pursue additional certifications or attestations as business need emerges.
- Serve as the primary point of contact for external auditors and certification bodies, ensuring evidence, timelines, and remediation commitments are consistently met.
- Support SOX IT General Controls compliance with Internal Audit, Finance, and IT, and serve as the primary security liaison for SOX testing cycles, the annual external audit of internal controls over financial reporting, deficiency tracking, and remediation.
Enterprise Risk — Register, Third-Party Risk & Assessments
- Build and own the enterprise risk register, aggregating signals from vulnerability management, third-party risk, audits, and incidents into a single prioritized view with named owners and remediation timelines, and use it to shape and prioritize the security roadmap company-wide.
- Design and operate the third-party and vendor risk management program covering onboarding, risk tiering, and ongoing monitoring, including supply-chain partners critical to SiTime’s fabless model.
- Direct technical security risk assessments of critical enterprise assets and third-party systems
- Partner with Legal and Procurement to embed security requirements into vendor contracts and the procurement process, and to evaluate security posture as part of vendor selection.
- Drive remediation of vendor-identified risks to closure within defined SLAs, working directly with vendors and internal system owners.
- Establish the assessment cadence against NIST CSF and NIST SP 800-53 — running the first cycle directly, then scaling through the team and contractors. Extend coverage to NIST SP 800-171 and NIST SP 800-161 as business need dictates.
- Facilitate third-party independent assessments and readiness reviews, managing scoping, coordination, and remediation of findings.
- As the program matures, stand up and chair a cross-functional Risk Committee with Security, IT, Engineering, Legal, and Finance, with a defined recurring cadence to review the register, adjudicate risk-acceptance decisions, and surface material risks for executive visibility.
- Produce the recurring risk reporting that enables the CISO’s executive and Audit Committee/Board updates on a consistent cadence.
Governance & Enforcement — Policy, Standards & Control Effectiveness
- Own the security policy and standards framework end to end, creating policy with Engineering and IT and translating it into enforceable technical standards and control baselines.
- Establish a recurring policy review and refresh cycle aligned to evolving frameworks (NIST, ISO) and business change, including ongoing M&A integration activity.
- Stand up formal policy exception management with risk-based approval workflows, required compensating controls, and expiration and renewal tracking so exceptions stay visible, and time-boxed
- Establish oversight and monitoring of security control implementation and effectiveness company-wide, including security health dashboards that give the CISO and business leaders real-time visibility into program maturity.
- Define and track KPIs and KRIs for control effectiveness, using results to drive continuous improvement.
Qualifications & Requirements:
- 8+ years in information security, risk, or assurance, including 3+ years building or substantially rebuilding a program
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field — or equivalent practical experience.
- At least one of the following certifications: CISSP, CISA, CRISC, or CCSK.
- People leadership experience
- Technical fluency across cloud platforms (Azure, AWS), infrastructure security (network, endpoint, IAM), and third-party risk frameworks
- Working mastery of NIST CSF, NIST SP 800-53, ISO 27001, and SOX ITGC, with hands-on experience managing external audits and certifications end to end.
- Hands-on experience designing and running a third-party and vendor risk management program, including vendor tiering, ongoing monitoring, and remediation workflows.
- Experience building and maintaining an enterprise risk register and producing risk reporting for executive and Audit Committee/Board consumption.
- English proficiency is required, including the ability to effectively communicate, collaborate, and perform job responsibilities in a professional business environment.
Preferred:
- Experience in a semiconductor, hardware, or other fabless/manufacturing environment, or another regulated hardware/OT-adjacent industry.
- Familiarity with data privacy regimes (GDPR and equivalents) where they intersect customer due diligence and vendor contracting.
Desired Characteristics & Attributes:
- Strong executive presence and stakeholder management: able to translate complex technical security concepts into business-friendly, risk-oriented language and influence decision-making across functions without direct authority.
- Program management rigor with ablity to run multiple concurrent cross-functional initiatives to completion, not just track them.
Compensation Range:
At SiTime, we believe great work deserves great rewards. We offer a comprehensive and highly competitive compensation package designed to attract top talent.
The annual base salary range for this role is $154,710 – $221,230. The final offer is determined by factors such as location, experience, education, and training.
In addition to base salary, this role is eligible for a quarterly bonus tied to the achievement of innovation goals—reflecting our commitment to recognizing meaningful impact. We also offer equity grants, providing a meaningful opportunity to share in the company’s future growth and success.
Benefits offered: 401k plan, health and wellness that includes medical, dental, vision, life, parental leave, legal services, and time off plans.
SiTime is an Equal Opportunity Employer. We treat each person fairly and we do not tolerate discrimination or harassment against anyone on the basis of any protected characteristics, including race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, pregnancy, political affiliation, protected veteran status, protected genetic information, or marital status or other characteristics protected by law. SiTime participates in the E-Verify program.
Learn More about SiTime: Review the Get to Know SiTime section of our career page to explore our culture, values, and what makes us unique.
- Innovation on Top – Philosophies of Innovation with Rajesh Vashist
- Fabrication Knowledge – An Interview with Rajesh Vashist
- SiTime Corporation – YouTube