Sr. Staff Technology Controls Architecture & Assurance Lead
Listed on 2026-08-18
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Sr. Staff Technology Controls Architecture & Assurance Lead
San Jose, California, United States
Archer is an aerospace company based in San Jose, California building an all‑electric vertical takeoff and landing aircraft with a mission to advance the benefits of sustainable air mobility. We are designing, manufacturing, and operating an all‑electric aircraft that can carry four passengers while producing minimal noise.
We believe that diversity in the workplace fuels smarter solutions, better insights, and collective success. We are dedicated to cultivating an equitable and inclusive environment that embraces differences and celebrates all team members.
As we scale our defense programs, certify aircraft with the FAA, and expand our enterprise footprint, the stakes of a control failure or compliance gap are measured in mission impact, not just audit findings. Information security is woven into the aircraft certification process itself, making this role uniquely consequential beyond a traditional enterprise GRC function.
We are seeking a Senior Staff Technology Controls & Assurance Lead to serve as a cornerstone of our GRC function, reporting to the Sr. Director of Governance, Risk & Compliance.
This high‑visibility role will own IS policy development, internal controls governance, risk quantification, and engagement with internal and external audit bodies. You will make our risk posture legible to board, auditors, DoD assessors, and engineering teams.
This is not a checkbox compliance role. We expect you to operate with the intellectual rigor of a risk analyst, the communication precision of an executive advisor, and the technical depth to understand what our controls actually do. You will bring both qualitative judgment and quantitative discipline—building data‑driven KRIs, leveraging AI and analytics to surface themes, and translating signal into action.
WhatYou Will Own
IS POLICY & CONTROLS DEVELOPMENT
Lead the development, maintenance, and lifecycle governance of Archer's Information Security policy library, standards, and control frameworks. Ensure policies are grounded in regulatory obligations—NIST SP 800‑171, CMMC Level 2, NIST SP 800‑161 C‑SCRM, DFARS, ITAR—and translated into implementable control requirements that engineering and operations teams can execute against.
ISSUE MANAGEMENT & RISK MITIGATION GOVERNANCE
Own the enterprise IS Issue Management process from identification through closure—establishing severity thresholds, SLA frameworks, escalation paths, and executive reporting cadences. Govern risk acceptance, exception management, and Plan of Action & Milestones (POA&M) processes. Ensure open risk items receive timely, accountable remediation and that residual risk is clearly communicated to leadership.
CONTROL SELF‑ASSESSMENTS (CSAS)
Design and execute Archer's internal Control Self‑Assessment program—develop testing procedures, coordinate with control owners across engineering, IT, finance, and legal, and produce structured findings that drive control improvement. Maintain ongoing awareness of control effectiveness between formal audit cycles to prevent surprise gaps.
INTERNAL & EXTERNAL AUDIT MANAGEMENT
Serve as the primary IS liaison for internal audit, external financial auditors, and government compliance assessors—including CMMC C3
PAO assessments and DCSA reviews. Manage evidence collection, artifact packaging, auditor communications, and findings remediation tracking.
SOX ITGC COMPLIANCE
Own Archer's SOX IT General Controls program—coordinate with external auditors, manage ITGC scoping, and ensure that change management, access controls, and IT operations controls meet the requirements for a public‑company financial reporting environment.
Build and maintain a meaningful set of Key Risk Indicators (KRIs) that go beyond checkbox coverage metrics to reflect actual risk exposure trends. Apply quantitative risk analysis techniques—including probabilistic modeling and loss magnitude estimation—to prioritize remediation investment and communicate risk in financial terms to executive and board audiences. Leverage AI‑assisted analytics and data science techniques to identify themes,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).