Governance, Risk Management and Compliance, Senior Director
Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs’ Intelligent Connectivity Platform integrates CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor-based technologies with the company’s COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company’s custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at www.asteralabs.com.
Senior Director, Governance, Risk Management and Compliance
Location: San Jose, CA
Role Overview
Astera Labs is redefining connectivity for the AI era, and as we scale, we need a strategic leader to safeguard how we operate. The Senior Director, Governance, Risk Management and Compliance (GRC) will build and lead the enterprise GRC function — establishing the frameworks, controls, and culture that protect Astera Labs' people, products, data, and reputation as we grow.
This is a highly visible, cross-functional role that partners with Finance, Legal, IT, Security, Engineering, and Operations to embed risk-aware decision-making across the company. You'll shape how Astera Labs manages enterprise risk, regulatory compliance, internal controls, and third-party risk during one of the most exciting growth chapters in semiconductors — enabling rack-scale AI infrastructure for the world's leading hyperscalers.
Key Responsibilities
- Governance & Program Leadership
- Build, lead, and continuously mature Astera Labs' enterprise GRC program, aligned to company strategy and growth stage
- Define governance structures, policies, and standards; drive executive and Board-level reporting on risk and compliance posture
- Partner with Legal, Finance, IT, and Security leadership to align GRC priorities with business objectives
- Risk Management
- Design and operate the enterprise risk management (ERM) framework, including risk identification, assessment, treatment, and monitoring
- Lead third-party and vendor risk management, ensuring appropriate due diligence and ongoing oversight
- Establish clear risk appetite, metrics, and escalation paths across business functions
- Compliance & Controls
- Own the internal controls program (including SOX readiness and ongoing 404 compliance) in partnership with Finance and Internal Audit
- Drive compliance with applicable regulatory, industry, and customer requirements (e.g., SOC 2, ISO 27001, NIST, data privacy regulations)
- Serve as primary liaison for internal and external auditors, coordinating audits, findings, and remediation
- Team & Culture
- Recruit, develop, and lead a high-performing GRC team as the function scales
- Champion a culture of accountability, integrity, and continuous improvement across the organization
- Deliver training, awareness, and enablement programs that make risk and compliance part of how Astera Labs operates day-to-day
Basic Qualifications
- Bachelor's degree in business, Finance, Accounting, Information Systems, or a related field
- 10+ years of progressive experience in governance, risk management, compliance, internal audit, or a related discipline, with 5+ years in a leadership role
- Demonstrated experience building or scaling a GRC program at a public or pre-/post-IPO technology company
- Strong working knowledge of SOX, ERM frameworks (e.g., COSO), and industry standards such as SOC 2, ISO 27001, or NIST
- Proven ability to influence and partner with executive stakeholders across Finance, Legal, IT, Security, and business functions
- Excellent written and verbal communication skills, with experience presenting to executives, auditors, and/or the Board
Preferred Qualifications
- Advanced degree (MBA, MS) and/or professional certifications such as CPA, CIA, CISA, CRISC, or CISSP
- Experience in the semiconductor, hardware, or hyper-growth technology sector
- Familiarity with data privacy regulations (GDPR, CCPA) and export/trade compliance considerations
- Experience implementing GRC tooling and automating controls, assessments, and reporting
- Strategic thinker who thrives in fast-paced, ambiguous environments and can balance pragmatism with rigor
Salary range is $225,000 to $250,000 depending on experience, level, and business need. This role may be eligible for discretionary bonus, incentives and benefits.
We know that creativity and innovation happen more often when teams include diverse ideas, backgrounds, and experiences, and we actively encourage everyone with relevant experience to apply, including people of color, LGBTQ+ and non-binary people, veterans, parents, and individuals with disabilities.
Apply for this job
*
indicates a required field