Sr. Manager, Vulnerability Management and Security Operations

Posted 2 Days Ago
Be an Early Applicant
Santa Clara, CA, USA
In-Office
155K-221K Annually
Senior level
Hardware • Semiconductor • Manufacturing
The Role
Leads vulnerability management and security operations, including SIEM and telemetry coverage, MDR oversight, risk-based remediation, incident response, ransomware readiness, and security incident command. Builds and scales the function through employees, managed services, and contractors; establishes service levels, detection workflows, playbooks, exercises, and executive reporting. Partners with technical and business stakeholders to reduce security risk and drive remediation to closure.
Summary Generated by Built In

About SiTime


SiTime is the Precision Timing company. 


Timing is the heartbeat of all electronics, ensuring performance, resilience and scalability. For decades, quartz devices, non-silicon technology, have kept systems in sync, but they struggle in harsher, more demanding environments. MEMS-based Precision Timing delivers greater accuracy, smaller size and resilience. Today, MEMS timing powers over 400 applications, including high-growth ones in AI datacenters, automated driving, industrial and humanoid robots, wearables and IoT.


Our semiconductor MEMS programmable solutions offer a rich feature set that enables customers to differentiate their products with higher performance, smaller size, lower power, and better reliability. With more than 4 billion devices shipped, SiTime is changing the timing industry. For more information, visit: www.sitime.com.


Job Summary


Reporting to the CISO, this role leads SiTime's Vulnerability Management and Security Operations function. It owns detection and monitoring, the 24x7 managed detection and response relationship, risk-based vulnerability operations, incident response and ransomware readiness — the detect and respond pillar of the security organization.


This is a build role. The candidate will mature and scale the SIEM and log coverage standard, select and operate the MDR partner, establish vulnerability remediation service levels that are enforced rather than reported, and take the incident response and ransomware playbooks from draft to rehearsed.It is also a people-leadership role. The candidate starts hands-on, then scales the function through a mix of full-time hires, managed service capacity and specialist contractors engaged for surge and testing cycles.


This is an accountable owner role, not an advisory one. The role is the operational arm of the CISO's office: it detects, triages and contains, and it drives remediation to closure with IT, Engineering and system owners — partnering cross-functionally with the CISO's other functions (Security Risk, Assurance and Trust; Security Engineering; Security Architecture; and Offensive Security) to improve the company's overall security posture.


We value diverse experiences, perspectives, and career paths, and welcome candidates who are excited to contribute to our mission.


Responsibilities:


Detection and Monitoring — SIEM, MDR and Telemetry Coverage

  • Own SEIM end to end: design, deployment, priority log onboarding, detection content, tuning, and ongoing cost management.
  • Own and enforce a log coverage standard spanning cloud, SaaS, endpoint, network, application and laboratory environments, and close the gaps where coverage does not exist today.
  • Manage the 24x7 MDR provider. Own the service levels, the escalation path into SiTime, the quality review cycle and the operating rhythm.
  • Build detection use cases aligned to the threats that matter to a fabless semiconductor company, including unauthorized access to and bulk movement of design data and source code.
  • Establish alert triage, case management and hand-off workflow between the MDR provider and SiTime Security; measure and drive down time to acknowledge and time to contain.
  • Set log retention standards sufficient to support forensic investigation, legal hold and customer or regulatory inquiry.
  • Partner with Security Engineering on the coverage, configuration health and alert quality of CrowdStrike, Darktrace, Microsoft Defender and future sensors.


Vulnerability Management — Risk-Based Operations

  • Design and operate a risk-based vulnerability management program across endpoints, servers, cloud workloads, SaaS, network devices and laboratory systems.
  • Define remediation service levels by severity and asset criticality, and drive closure with IT, Engineering and system owners rather than reporting on open counts.
  • Own attack surface and external exposure monitoring of internet-facing assets, and reduce the exposed footprint over time.
  • Operate exception handling with risk-based approval, compensating controls and time-boxed expiry, in partnership with the Security Risk, Assurance and Trust function.
  • Produce vulnerability, coverage and aging metrics that demonstrate risk reduction rather than scan activity.
  • Feed vulnerability and exposure signal into the enterprise risk register so it shapes company-wide prioritization.


Incident Response and Ransomware Readiness

  • Own the incident response and ransomware playbooks, and keep them approved, socialized and exercised.
  • Deploy and operate paging, the on-call rotation and escalation, and make sure a real person is reachable at any hour.
  • Manage the external incident response and digital forensics retainer, and keep the partner current on the SiTime environment.
  • Plan and run ransomware and crisis tabletop exercises for both executive and technical audiences, and track every resulting action to closure with evidence.
  • Act as incident commander for security incidents: run the bridge, set the status cadence, and produce the executive reporting.
  • Partner with Legal, Communications, Finance and Insurance on notification obligations, crisis communications and claims.
  • Run post-incident reviews and feed the findings back into detection content, controls and the security roadmap.


Qualifications & Requirements: 

  • 8+ years in security operations, detection and response, or vulnerability management, including 3+ years building or substantially rebuilding a function.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field — or equivalent practical experience.
  • At least one of the following certifications: CISSP, GCIA, GCIH, GCFA, or equivalent.
  • People leadership experience.
  • Hands-on experience deploying and operating a modern SIEM, Microsoft Sentinel strongly preferred, including log onboarding, detection engineering and cost control.
  • Experience managing an MDR or MSSP relationship, including service level definition, escalation design and quality review.
  • Demonstrated ownership of a risk-based vulnerability management program with enforced remediation service levels.
  • Experience leading security incidents end to end, including ransomware scenarios, and designing and running tabletop exercises.
  • Technical fluency across cloud platforms (Azure, AWS), endpoint, network and identity telemetry.
  • English proficiency is required, including the ability to effectively communicate, collaborate, and perform job responsibilities in a professional business environment.


Preferred:

  • Experience in a semiconductor, hardware, or other fabless/manufacturing environment, or another regulated hardware/OT-adjacent industry.
  • Hands-on experience with industry leading security tools and scanner
  • Experience monitoring engineering, design and laboratory environments, including intellectual property exfiltration scenarios.


Desired Characteristics & Attributes:

  • Strong executive presence and stakeholder management: able to translate complex technical security concepts into business-friendly, risk-oriented language and influence decision-making across functions without direct authority.
  • Program management rigor with ablity to run multiple concurrent cross-functional initiatives to completion, not just track them.


Compensation Range:


At SiTime, we believe great work deserves great rewards. We offer a comprehensive and highly competitive compensation package designed to attract top talent. 


The annual base salary range for this role is $123,750 – $176,970. The final offer is determined by factors such as location, experience, education, and training.


 In addition to base salary, this role is eligible for a quarterly bonus tied to the achievement of innovation goals—reflecting our commitment to recognizing meaningful impact. We also offer equity grants, providing a meaningful opportunity to share in the company’s future growth and success.


Benefits offered: 401k plan, health and wellness that includes medical, dental, vision, life, parental leave, legal services, and time off plans.


SiTime is an Equal Opportunity Employer. We treat each person fairly and we do not tolerate discrimination or harassment against anyone on the basis of any protected characteristics, including race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, pregnancy, political affiliation, protected veteran status, protected genetic information, or marital status or other characteristics protected by law. SiTime participates in the E-Verify program.

Learn More about SiTime: Review the Get to Know SiTime section of our career page to explore our culture, values, and what makes us unique. 

  • Innovation on Top – Philosophies of Innovation with Rajesh Vashist
  • Fabrication Knowledge – An Interview with Rajesh Vashist
  • SiTime Corporation – YouTube


Skills Required

  • 8+ years of experience in security operations, detection and response, or vulnerability management
  • 3+ years building or substantially rebuilding a security function
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience
  • At least one certification such as CISSP, GCIA, GCIH, GCFA, or equivalent
  • People leadership experience
  • Hands-on experience deploying and operating a modern SIEM; Microsoft Sentinel strongly preferred
  • Experience managing an MDR or MSSP relationship, including service levels, escalation design, and quality review
  • Experience owning a risk-based vulnerability management program with enforced remediation service levels
  • Experience leading security incidents end to end, including ransomware scenarios, and running tabletop exercises
  • Technical fluency across Azure, AWS, endpoint, network, and identity telemetry
  • Professional English proficiency
  • Experience in semiconductor, hardware, fabless, manufacturing, regulated hardware, or OT-adjacent environments
  • Hands-on experience with industry-leading security tools and scanners
  • Experience monitoring engineering, design, and laboratory environments, including intellectual property exfiltration scenarios

SiTime Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SiTime and has not been reviewed or approved by SiTime.

  • Equity Value & Accessibility — Feedback suggests equity is a meaningful part of total compensation, with some highlighting the combination of salary, bonus, and stock as a strong point. Company materials emphasize employee equity as a core element of rewards.
  • Wellbeing & Lifestyle Benefits — Feedback suggests on-site wellness amenities and daily conveniences (gym, snacks, beverages) support day-to-day wellbeing. The company highlights wellness programs alongside these lifestyle perks.
  • Leave & Time Off Breadth — Feedback suggests paid vacation, holidays, sick leave, and volunteer time off are available, reinforcing recharge time. The company emphasizes work-life balance and encourages time to recharge.

SiTime Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Santa Clara, CA
465 Employees
Year Founded: 2005

What We Do

SiTime Corporation (Nasdaq: SITM), the market leader in silicon MEMS timing, is an analog and semiconductor company that is revolutionizing the timing market. Our broad portfolio of programmable solutions is available with ultra-fast lead times and offer a rich feature set that enables customers to differentiate their products with higher performance, smaller size, lower power, and better reliability.

Similar Jobs

Shield AI Logo Shield AI

Senior Analyst, U.S. Market Intelligence/Price-to-Win — X-BAT Family of Systems (R6168)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
In-Office
3 Locations
130K-190K Annually
In-Office or Remote
2 Locations
175633 Employees
133K-284K Annually

Gusto Logo Gusto

Staff Software Engineer

Fintech • HR Tech
Easy Apply
Hybrid
3 Locations
4405 Employees
164K-247K Annually

PwC Logo PwC

Deals - Deal Valuation - Experienced Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
2 Locations
370000 Employees
63K-140K Annually

Similar Companies Hiring

Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account