Sr. Staff Technology Controls Architecture & Assurance Lead

Archer
San Jose
Workplace: OnsiteFull timeFunction: Architecture & Urban PlanningExperience: 8+ yearsSkills: ["Communication","Leadership","Stakeholder management","Problem-solving","Executive communication"]

Lead Archer’s information security policy, controls, and GRC program. Own risk governance, internal controls, and audit readiness across SOX ITGC, CSA, and external/government assessments; translate regulatory obligations into actionable controls for engineering and operations; communicate risk to executives and board while leveraging analytics and AI to surface themes and drive remediation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Archer
Archer
3 months ago

Sr. Staff Technology Controls Architecture & Assurance Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Lead Archer’s information security policy, controls, and GRC program. Own risk governance, internal controls, and audit readiness across SOX ITGC, CSA, and external/government assessments; translate regulatory obligations into actionable controls for engineering and operations; communicate risk to executives and board while leveraging analytics and AI to surface themes and drive remediation.
Location: San Jose
Workplace: Onsite
Employment Type: Full time
Job Function: Architecture & Urban Planning
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead the development, maintenance, and lifecycle governance of Archer's Information Security policy library, standards, and control frameworks grounded in regulatory obligations (NIST SP 800-171, CMMC Level 2, NIST SP 800-161 C-SCRM, DFARS, ITAR) and translate into implementable control requirements for engineering and operations teams
  • •Own the enterprise IS Issue Management process from identification through closure—establish severity thresholds, SLAs, escalation paths, and executive reporting cadences; govern risk acceptance, exception management, and POA&M processes
  • •Design and execute Archer's Control Self-Assessment program—develop testing procedures, coordinate with control owners across engineering/IT/finance/legal, and produce findings that drive control improvement
  • •Serve as the primary IS liaison for internal and external audits and government compliance assessments (CMMC C3PAO, DCSA reviews); manage evidence collection, auditor communications, and remediation tracking
  • •Own Archer's SOX ITGC compliance program—scoping, control design, auditor engagement, and year-round readiness in a public/pre-IPO company environment

Key Requirements

  • •8+ years in information security, with at least 4 years in a GRC, compliance, or IS audit-focused role — ideally spanning both commercial and defense or government-adjacent environments
  • •Deep, hands-on working knowledge of NIST SP 800-171 / CMMC Level 2, NIST SP 800-161 (C-SCRM), DFARS 252.204-7012, and ITAR — including practical application in an active compliance program, not just familiarity with the frameworks
  • •Demonstrated experience managing SOX ITGC programs — including scoping, control design, auditor engagement, and year-round readiness in a public or pre-IPO company environment
  • •Proven track record designing and executing Control Self-Assessment (CSA) programs and managing the full issue lifecycle from identification through risk-accepted closure
  • •Experience serving as the primary IS point of contact during formal external audits or government compliance assessments — managing evidence, auditor relationships, and findings remediation under deadline pressure
  • •Ability to build and maintain quantitative risk models and KRIs — translating risk data into business-impact terms and leveraging data analytics or AI tooling to identify risk themes, trends, and outliers at scale
  • •Exceptional written and verbal communication skills — the ability to produce board-ready risk briefs, distill complex regulatory findings into plain language, and command credibility with both technical engineers and C-suite executives
  • •U.S. citizenship and eligibility to obtain a DoD Secret security clearance
Experience:8+ yearsAerospaceDefenseAviation
Skills:CommunicationLeadershipStakeholder managementProblem-solvingExecutive communication
Languages:English
Tech Stack:ServiceNow GRC/IRMAuditBoardJIRAConfluencePower BITableauVantaDrataSecureframeWorkivaSplunkSIEMPythonSQLAI/LLM toolingNIST SP 800-53 Rev.5OSCALDO-326ADO-356ADO-355A

Eligibility

Nationality:US National
Security Clearance:Secret

Company Brief

Archer
Develops electric vertical takeoff and landing (eVTOL) aircraft and urban air mobility systems to enable sustainable, intra-city air transportation for passengers and cargo.
Industry: Aerospace Manufacturing
Company Size: Large (251 to 1,000 employees)
Revenue: Pre-Revenue (USD 0)
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Palo Alto, United States
Founded: 2018
WebsiteLinkedIn