Enter a job title or keyword

Sr. Manager, Vulnerability Management and Security Operations

SiTime Corporation


Job Location:

Santa Clara County, CA - USA

Yearly Salary: USD 154710 - 221230
Posted: 2 October 2026 (Yesterday)
Application Deadline: 30 December 2026
Vacancies: 1 Vacancy

Job Summary

About SiTime


SiTime is the Precision Timing company.


Timing is the heartbeat of all electronics ensuring performance resilience and scalability. For decades quartz devices non-silicon technology have kept systems in sync but they struggle in harsher more demanding environments. MEMS-based Precision Timing delivers greater accuracy smaller size and resilience. Today MEMS timing powers over 400 applications including high-growth ones in AI datacenters automated driving industrial and humanoid robots wearables and IoT.


Our semiconductor MEMS programmable solutions offer a rich feature set that enables customers to differentiate their products with higher performance smaller size lower power and better reliability. With more than 4 billion devices shipped SiTime is changing the timing industry. For more information visit:.


Job Summary


Reporting to the CISO this role leads SiTimes Vulnerability Management and Security Operations function. It owns detection and monitoring the 24x7 managed detection and response relationship risk-based vulnerability operations incident response and ransomware readiness the detect and respond pillar of the security organization.


This is a build role. The candidate will mature and scale the SIEM and log coverage standard select and operate the MDR partner establish vulnerability remediation service levels that are enforced rather than reported and take the incident response and ransomware playbooks from draft to is also a people-leadership role. The candidate starts hands-on then scales the function through a mix of full-time hires managed service capacity and specialist contractors engaged for surge and testing cycles.


This is an accountable owner role not an advisory one. The role is the operational arm of the CISOs office: it detects triages and contains and it drives remediation to closure with IT Engineering and system owners partnering cross-functionally with the CISOs other functions (Security Risk Assurance and Trust; Security Engineering; Security Architecture; and Offensive Security) to improve the companys overall security posture.


We value diverse experiences perspectives and career paths and welcome candidates who are excited to contribute to our mission.


Responsibilities:


Detection and Monitoring SIEM MDR and Telemetry Coverage

  • Own SEIM end to end: design deployment priority log onboarding detection content tuning and ongoing cost management.
  • Own and enforce a log coverage standard spanning cloud SaaS endpoint network application and laboratory environments and close the gaps where coverage does not exist today.
  • Manage the 24x7 MDR provider. Own the service levels the escalation path into SiTime the quality review cycle and the operating rhythm.
  • Build detection use cases aligned to the threats that matter to a fabless semiconductor company including unauthorized access to and bulk movement of design data and source code.
  • Establish alert triage case management and hand-off workflow between the MDR provider and SiTime Security; measure and drive down time to acknowledge and time to contain.
  • Set log retention standards sufficient to support forensic investigation legal hold and customer or regulatory inquiry.
  • Partner with Security Engineering on the coverage configuration health and alert quality of CrowdStrike Darktrace Microsoft Defender and future sensors.


Vulnerability Management Risk-Based Operations

  • Design and operate a risk-based vulnerability management program across endpoints servers cloud workloads SaaS network devices and laboratory systems.
  • Define remediation service levels by severity and asset criticality and drive closure with IT Engineering and system owners rather than reporting on open counts.
  • Own attack surface and external exposure monitoring of internet-facing assets and reduce the exposed footprint over time.
  • Operate exception handling with risk-based approval compensating controls and time-boxed expiry in partnership with the Security Risk Assurance and Trust function.
  • Produce vulnerability coverage and aging metrics that demonstrate risk reduction rather than scan activity.
  • Feed vulnerability and exposure signal into the enterprise risk register so it shapes company-wide prioritization.


Incident Response and Ransomware Readiness

  • Own the incident response and ransomware playbooks and keep them approved socialized and exercised.
  • Deploy and operate paging the on-call rotation and escalation and make sure a real person is reachable at any hour.
  • Manage the external incident response and digital forensics retainer and keep the partner current on the SiTime environment.
  • Plan and run ransomware and crisis tabletop exercises for both executive and technical audiences and track every resulting action to closure with evidence.
  • Act as incident commander for security incidents: run the bridge set the status cadence and produce the executive reporting.
  • Partner with Legal Communications Finance and Insurance on notification obligations crisis communications and claims.
  • Run post-incident reviews and feed the findings back into detection content controls and the security roadmap.


Qualifications & Requirements:

  • 8 years in security operations detection and response or vulnerability management including 3 years building or substantially rebuilding a function.
  • Bachelors degree in Computer Science Information Security Engineering or a related technical field or equivalent practical experience.
  • At least one of the following certifications: CISSP GCIA GCIH GCFA or equivalent.
  • People leadership experience.
  • Hands-on experience deploying and operating a modern SIEM Microsoft Sentinel strongly preferred including log onboarding detection engineering and cost control.
  • Experience managing an MDR or MSSP relationship including service level definition escalation design and quality review.
  • Demonstrated ownership of a risk-based vulnerability management program with enforced remediation service levels.
  • Experience leading security incidents end to end including ransomware scenarios and designing and running tabletop exercises.
  • Technical fluency across cloud platforms (Azure AWS) endpoint network and identity telemetry.
  • English proficiency is required including the ability to effectively communicate collaborate and perform job responsibilities in a professional business environment.


Preferred:

  • Experience in a semiconductor hardware or other fabless/manufacturing environment or another regulated hardware/OT-adjacent industry.
  • Hands-on experience with industry leading security tools and scanner
  • Experience monitoring engineering design and laboratory environments including intellectual property exfiltration scenarios.


Desired Characteristics & Attributes:

  • Strong executive presence and stakeholder management: able to translate complex technical security concepts into business-friendly risk-oriented language and influence decision-making across functions without direct authority.
  • Program management rigor with ablity to run multiple concurrent cross-functional initiatives to completion not just track them.


Compensation Range:


At SiTime we believe great work deserves great rewards. We offer a comprehensive and highly competitive compensation package designed to attract top talent.


The annual base salary range for this role is $154710 $221230. The final offer is determined by factors such as location experience education and training.


In addition to base salary this role is eligible for a quarterly bonus tied to the achievement of innovation goalsreflecting our commitment to recognizing meaningful impact. We also offer equity grants providing a meaningful opportunity to share in the companys future growth and success.


Benefits offered: 401k plan health and wellness that includes medical dental vision life parental leave legal services and time off plans.


SiTime is anEqual Opportunity Employer. We treat each person fairly and we do not tolerate discrimination or harassment against anyone on the basis of any protected characteristics including race color religion national or ethnic origin sex sexual orientation gender identity or expression age disability pregnancy political affiliation protected veteran status protected genetic information or marital status or other characteristics protected by law. SiTime participates in theE-Verifyprogram.

Learn More about SiTime:Review theGet to Know SiTimesection of our career page to explore our culture values and what makes us unique.



Required Experience:

Manager


About Company

SiTime is a leader in MEMS timing solutions, having shipped billions of units. Learn about our silicon MEMS oscillators, TCXOs, OCXOs, MEMS resonators, clock generators, jitter cleaners, clock timing, timing clock, sitm stock, and much more.

View Profile View Profile