Sr. Manager, Security Risk, Assurance and Trust
Listed on 2026-09-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Sr. Manager, Security Risk, Assurance and Trust
Full-time Regular Management Santa Clara, CA, US
About Si Time
SiTime is the Precision Timing company.
Timing is the heartbeat of all electronics, ensuring performance, resilience and scalability. For decades, quartz devices, non-silicon technology, have kept systems in sync, but they struggle in harsher, more demanding environments. MEMS-based Precision Timing delivers greater accuracy, smaller size and resilience. Today, MEMS timing powers over 400 applications, including high-growth ones in AI datacenters, automated driving, industrial and humanoid robots, wearables and IoT.
Our semiconductor MEMS programmable solutions offer a rich feature set that enables customers to differentiate their products with higher performance, smaller size, lower power, and better reliability. With more than 4 billion devices shipped, SiTime is changing the timing industry. For more information, visit: .
Job Summary
Reporting to the CISO, this role builds and leads SiTime’s Security Risk, Assurance and Trust function. It owns customer security audits and trust, third-party and vendor risk management, the enterprise risk register, security policy and governance, compliance certifications, and SOX compliance support the audits, risk, and assurance pillar of the security organization.
This is a build role. The successful candidate will design and establish the enterprise risk register, the third-party risk program, the certification program, and the security policy and standards framework.
It is also a people-leadership role. The candidate starts hands-on, personally delivering the first cycle of each program, then scales the function through a mix of full-time hires and specialist contractors engaged for assessment cycles, certification readiness, and audit surge capacity.
It is an accountable owner role, not an advisory one. The role is the strategic and enforcement arm of the CISO’s office: it sets risk and governance strategy, then partners with IT, Legal, Finance, Design, and Engineering — and cross-functionally with the CISO’s other security functions (Vulnerability Management & Security Operations, Security Engineering, Security Architecture, and Offensive Security), to drive that strategy into implemented, verified controls and coordinated initiatives that improve the company’s overall security posture.
It is not necessary to meet all job requirements to be a qualified candidate for the position.
Responsibilities:
External Assurance — Customer Trust, Certification & SOX
- Own customer security assurance end to end. Build the reusable trust package including security white paper, certification and audit-report library, standard response templates and the response process.
- Distinguish formal customer audit findings from ad hoc customer requests for additional security controls or contractual commitments, resourcing and tracking each independently to closure.
- Drive remediation of gaps identified through customer audits with IT, Engineering, and system owners, tracking every finding to closure and feeding recurring themes back into the security roadmap.
- Own SiTime’s ISO 27001 certification end to end including scoping, gap assessment, control implementation, readiness, external audit, and ongoing surveillance.
- Monitor the certification and regulatory landscape relevant to SiTime’s customers, markets, and geographies; recommend and pursue additional certifications or attestations as business need emerges.
- Serve as the primary point of contact for external auditors and certification bodies, ensuring evidence, timelines, and remediation commitments are consistently met.
- Support SOX IT General Controls compliance with Internal Audit, Finance, and IT, and serve as the primary…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).