
Governance, Risk Management and Compliance, Senior Director at Astera Labs (San Jose California, United States)
Astera Labs· San Jose California, United States·
Job description
Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs’ Intelligent Connectivity Platform integrates CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor-based technologies with the company’s COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company’s custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at www.asteralabs.com.
Senior Director, Governance, Risk Management and Compliance
Location: San Jose, CA
Role Overview
Astera Labs is redefining connectivity for the AI era, and as we scale, we need a strategic leader to safeguard how we operate. The Senior Director, Governance, Risk Management and Compliance (GRC) will build and lead the enterprise GRC function — establishing the frameworks, controls, and culture that protect Astera Labs' people, products, data, and reputation as we grow.
This is a highly visible, cross-functional role that partners with Finance, Legal, IT, Security, Engineering, and Operations to embed risk-aware decision-making across the company. You'll shape how Astera Labs manages enterprise risk, regulatory compliance, internal controls, and third-party risk during one of the most exciting growth chapters in semiconductors — enabling rack-scale AI infrastructure for the world's leading hyperscalers.
Key Responsibilities
- Governance & Program Leadership
- Build, lead, and continuously mature Astera Labs' enterprise GRC program, aligned to company strategy and growth stage
- Define governance structures, policies, and standards; drive executive and Board-level reporting on risk and compliance posture
- Partner with Legal, Finance, IT, and Security leadership to align GRC priorities with business objectives
- Risk Management
- Design and operate the enterprise risk management (ERM) framework, including risk identification, assessment, treatment, and monitoring
- Lead third-party and vendor risk management, ensuring appropriate due diligence and ongoing oversight
- Establish clear risk appetite, metrics, and escalation paths across business functions
- Compliance & Controls
- Own the internal controls program (including SOX readiness and ongoing 404 compliance) in partnership with Finance and Internal Audit
- Drive compliance with applicable regulatory, industry, and customer requirements (e.g., SOC 2, ISO 27001, NIST, data privacy regulations)
- Serve as primary liaison for internal and external auditors, coordinating audits, findings, and remediation
- Team & Culture
- Recruit, develop, and lead a high-performing GRC team as the function scales
- Champion a culture of accountability, integrity, and continuous improvement across the organization
- Deliver training, awareness, and enablement programs that make risk and compliance part of how Astera Labs operates day-to-day
Basic Qualifications
- Bachelor's degree in business, Finance, Accounting, Information Systems, or a related field
- 10+ years of progressive experience in governance, risk management, compliance, internal audit, or a related discipline, with 5+ years in a leadership role
- Demonstrated experience building or scaling a GRC program at a public or pre-/post-IPO technology company
- Strong working knowledge of SOX, ERM frameworks (e.g., COSO), and industry standards such as SOC 2, ISO 27001, or NIST
- Proven ability to influence and partner with executive stakeholders across Finance, Legal, IT, Security, and business functions
- Excellent written and verbal communication skills, with experience presenting to executives, auditors, and/or the Board
Preferred Qualifications
- Advanced degree (MBA, MS) and/or professional certifications such as CPA, CIA, CISA, CRISC, or CISSP
- Experience in the semiconductor, hardware, or hyper-growth technology sector
- Familiarity with data privacy regulations (GDPR, CCPA) and export/trade compliance considerations
- Experience implementing GRC tooling and automating controls, assessments, and reporting
- Strategic thinker who thrives in fast-paced, ambiguous environments and can balance pragmatism with rigor
Salary range is $225,000 to $250,000 depending on experience, level, and business need. This role may be eligible for discretionary bonus, incentives and benefits. We know that creativity and innovation happen more often when teams include diverse ideas, backgrounds, and experiences, and we actively encourage everyone with relevant experience to apply, including people of color, LGBTQ+ and non-binary people, veterans, parents, and individuals with disabilities.
Why work at Astera Labs
- Culture: Described as collaborative, ownership-driven, and focused on solving complex problems together. The company emphasizes diversity and inclusion as drivers of creativity and innovation.
- Growth: Astera Labs supports non-linear career growth—employees can deepen expertise (“scale up”) or broaden into new areas (“scale out”). 92% YoY headcount growth signals rapid expansion and opportunity.
- Remote/Hybrid: Not explicitly stated, but global operations across 12 countries (including India, Canada, Israel, Taiwan, Vietnam) suggest a flexible, distributed work model.
- Benefits: Competitive medical, dental, and vision plans; flexible time off; family planning and parental leave; 401K and retirement plans.
- Engineering culture: Strong focus on cutting-edge semiconductor and AI infrastructure technology. High concentration of senior (24%) and specialist (19%) talent. Active internship and new graduate programs.
- Employee ratings: 4.5/5.0 on LinkedIn (124 reviews), with high marks for compensation (4.6), culture (4.4), and career development (4.4).