Governance, Risk Management and Compliance, Senior Director
Astera Labs · San Jose, CA · 1 mo ago
Finance$225k–$250k/yrFull-time
Key Responsibilities
- Build, lead, and continuously mature Astera Labs' enterprise GRC program, aligned to company strategy and growth stage
- Define governance structures, policies, and standards; drive executive and Board-level reporting on risk and compliance posture
- Partner with Legal, Finance, IT, and Security leadership to align GRC priorities with business objectives
- Risk Management: Design and operate the enterprise risk management (ERM) framework, including risk identification, assessment, treatment, and monitoring
- Lead third-party and vendor risk management, ensuring appropriate due diligence and ongoing oversight
- Establish clear risk appetite, metrics, and escalation paths across business functions
- Compliance & Controls: Own the internal controls program (including SOX readiness and ongoing 404 compliance) in partnership with Finance and Internal Audit
- Drive compliance with applicable regulatory, industry, and customer requirements (e.g., SOC 2, ISO 27001, NIST, data privacy regulations)
- Serve as primary liaison for internal and external auditors, coordinating audits, findings, and remediation
- Team & Culture: Recruit, develop, and lead a high-performing GRC team as the function scales
- Champion a culture of accountability, integrity, and continuous improvement across the organization
- Deliver training, awareness, and enablement programs that make risk and compliance part of how Astera Labs operates day-to-day
Basic Qualifications
- Bachelor's degree in business, Finance, Accounting, Information Systems, or a related field
- 10+ years of progressive experience in governance, risk management, compliance, internal audit, or a related discipline, with 5+ years in a leadership role
- Demonstrated experience building or scaling a GRC program at a public or pre-/post-IPO technology company
- Strong working knowledge of SOX, ERM frameworks (e.g., COSO), and industry standards such as SOC 2, ISO 27001, or NIST
- Proven ability to influence and partner with executive stakeholders across Finance, Legal, IT, Security, and business functions
- Excellent written and verbal communication skills, with experience presenting to executives, auditors, and/or the Board
Preferred Qualifications
- Advanced degree (MBA, MS) and/or professional certifications such as CPA, CIA, CISA, CRISC, or CISSP
- Experience in the semiconductor, hardware, or hyper-growth technology sector
- Familiarity with data privacy regulations (GDPR, CCPA) and export/trade compliance considerations
- Experience implementing GRC tooling and automating controls, assessments, and reporting
- Strategic thinker who thrives in fast-paced, ambiguous environments and can balance pragmatism with rigor