Skip to content
← Back to job listings

Senior Staff Technology Controls Architecture & Assurance Lead

Archer · San Jose, United States

External listingfull-timeabout 1 month ago

About The Role

Join Archer, a pioneering company in urban air mobility. As the Senior Staff Technology Controls Architecture & Assurance Lead, you will play a crucial role in shaping our information security policies, managing risk, and ensuring compliance with regulatory obligations. You will work closely with various teams, including engineering, IT, finance, and legal, and serve as the primary liaison for internal and external audits. This is a high-visibility role that requires exceptional communication skills, a deep understanding of information security frameworks, and a passion for innovation in the aerospace industry.

  • Lead the development, maintenance, and lifecycle governance of Archer's Information Security policy library, standards, and control frameworks.
  • Own the enterprise IS Issue Management process from identification through closure — establishing severity thresholds, SLA frameworks, escalation paths, and executive reporting cadences.
  • Design and execute Archer's internal Control Self-Assessment program — developing testing procedures, coordinating with control owners across engineering, IT, finance, and legal.
  • You will bring both qualitative judgment and quantitative discipline to the risk function — building data-driven KRIs, leveraging AI and analytics to surface themes and outliers, and translating signal into action across the organization
  • This is not a checkbox compliance role
  • We expect you to operate with the intellectual rigor of a risk analyst, the communication precision of an executive advisor, and the technical depth to understand what our controls actually do
  • CUI REGISTRY / DCSA EMASS
  • JIRA / CONFLUENCE
  • SPLUNK / SIEM
  • OSCAL
  • RTCA DO-326A / DO-356A
  • WORKIVA
  • AUDITBOARD
  • NIST SP 800-53 REV. 5
  • SERVICENOW GRC / IRM
  • AI/LLM TOOLING FOR ANALYSIS
  • Hands-on experience with the following platforms is expected or highly valued:
  • PYTHON / SQL (DATA ANALYTICS)
  • VANTA / DRATA / SECUREFRAME
  • POWER BI / TABLEAU
  • Exceptional written and verbal communication skills — the ability to produce board-ready risk briefings, distill complex regulatory findings into plain language, and command credibility with both technical engineers and C-suite executives
  • U.S. citizenship and eligibility to obtain a DoD Secret security clearance
  • Demonstrated experience managing SOX ITGC programs — including scoping, control design, auditor engagement, and year-round readiness in a public or pre-IPO company environment
  • Ability to build and maintain quantitative risk models and KRIs — translating risk data into business-impact terms and leveraging data analytics or AI tooling to identify risk themes, trends, and outliers at scale
  • Experience serving as the primary IS point of contact during formal external audits or government compliance assessments — managing evidence, auditor relationships, and findings remediation under deadline pressure
  • Proven track record designing and executing Control Self-Assessment (CSA) programs and managing the full issue lifecycle from identification through risk-accepted closure
  • 8+ years in information security, with at least 4 years in a GRC, compliance, or IS audit-focused role — ideally spanning both commercial and defense or government-adjacent environments
  • Deep, hands-on working knowledge of NIST SP 800-171 / CMMC Level 2, NIST SP 800-161 (C-SCRM), DFARS 252.204-7012, and ITAR — including practical application in an active compliance program, not just familiarity with the frameworks
  • Active DoD Secret or Top Secret/SCI clearance
  • Certifications: CISSP, CISM, CRISC, CISA, or CMMC Registered Practitioner (RP) / Certified Professional (CCP)
  • Familiarity with FAA Aircraft Systems Information Security/Protection (ASISP) requirements and the RTCA DO-326A / DO-356A / DO-355A airworthiness security standard suite — including how these apply to type certification Special Conditions, continued airworthiness obligations, and IS risk assessment for connected and eVTOL aircraft systems
  • Aerospace, aviation, or defense industry experience — including familiarity with FAA certification environments, ITAR/EAR data sharing constraints, and CUI program requirements
  • Hands-on experience with quantitative risk analysis methodologies such as FAIR (Factor Analysis of Information Risk) — ability to communicate risk in dollar-denominated, probabilistic terms
  • Practical experience applying AI, machine learning, or statistical analysis techniques to GRC datasets — anomaly detection, control testing coverage analysis, risk concentration mapping
  • Exposure to FOCI (Foreign Ownership, Control, or Influence) assessments and DCSA facility clearance requirements relevant to a defense contractor environment
  • Prior startup or high-growth company experience — comfort operating in ambiguous, low-bureaucracy environments where program infrastructure must be built, not inherited

This is an external listing. JobSpring does not represent or verify the employer. Report this listing