Sr. Staff Technology Controls Architecture & Assurance Lead
(SJ2026DV) · San Jose, California, United States
- Location
- San Jose, California, United States
- Salary
- $207,400 - $259,200
- Funding
- N/A
- Posted
- Jun 19, 2026
(SJ2026DV) is hiring a Sr. Staff Technology Controls Architecture & Assurance Lead based in San Jose, California, United States. Every apply link on Engg.space goes straight to the company's own careers page - no recruiter middleman, no generic job-board form.
Apply directly at (SJ2026DV)Role details
Archer is an aerospace and defense company headquartered in San Jose, California, building the aircraft and technology that will define the next era of flight. The company works across air taxis, UAS, AI and powertrain development — building real-world systems that combine software intelligence with physical hardware. That includes Midnight, Archer's all-electric air taxi; Halo, an autonomous vertical takeoff and landing aircraft built for both commercial and defense use; and ZEE, Archer's AI foundation model built specifically for aviation. We’re seeking exceptional engineers, operators and builders to join us on our mission to build the future of aerospace and defense. Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members. Archer is building the future of urban air mobility — and the integrity of that mission depends on a security posture that is not just defensible, but demonstrable. As we scale our defense programs, certify aircraft with the FAA, and expand our enterprise footprint, the stakes of a control failure or compliance gap are measured in mission impact, not just audit findings. At Archer, information security is woven into the aircraft certification process itself — making this role uniquely consequential in ways that go well beyond a traditional enterprise GRC function. Archer is seeking a Senior Staff Technology Controls & Assurance Lead to serve as a cornerstone of our GRC function, reporting to the Sr. Director of Governance, Risk & Compliance. In this high-visibility role, you will own IS policy development, internal controls governance, risk quantification, and engagement with internal and external audit bodies. You are the person who makes our risk posture legible — to our board, to our auditors, to DoD assessors, and to our own engineering teams. This is not a checkbox compliance role. We expect you to operate with the intellectual rigor of a risk analyst, the communication precision of an executive advisor, and the technical depth to understand what our controls actually do. You will bring both qualitative judgment and quantitative discipline to the risk function — building data-driven KRIs, leveraging AI and analytics to surface themes and outliers, and translating signal into action across the organization. What You Will Own IS POLICY & CONTROLS DEVELOPMENT Lead the development, maintenance, and lifecycle governance of Archer's Information Security policy library, standards, and control frameworks. Ensure policies are grounded in applicable regulatory obligations — NIST SP 800-171, CMMC Level 2, NIST SP 800-161 C-SCRM, DFARS, ITAR — and translated into implementable control requirements that engineering and operations teams can execute against. ISSUE MANAGEMENT & RISK MITIGATION GOVERNANCE Own the enterprise IS Issue Management process from identification through closure — establishing severity thresholds, SLA frameworks, escalation paths, and executive reporting cadences. Govern risk acceptance, exception management, and Plan of Action & Milestones (POA&M) processes. Ensure that open risk items receive time-bound, accountable remediation ownership, and that residual risk is clearly communicated to leadership. CONTROL SELF-ASSESSMENTS (CSAS) Design and execute Archer's internal Control Self-Assessment program — developing testing procedures, coordinating with control owners across engineering, IT, finance, and legal, and producing structured findings that drive control improvement. Maintain ongoing awareness of control effectiveness between formal audit cycles to prevent surprise gaps. INTERNAL & EXTERNAL AUDIT MANAGEMENT Serve as the primary IS liaison for internal audit, external financial auditors, and government compliance assessors — including CMMC C3PAO assessments and DCSA reviews. Manage evidence collection, artifact packaging, auditor communications, and findings remediation tracking. Translate auditor requests into efficient, well-organized responses that demonstrate the maturity and rigor of Archer's control environment. SOX ITGC COMPLIANCE Own Archer's SOX IT General Controls program — coordinating with external auditors, managing ITGC scoping, and ensuring that change management, access controls, and IT operations controls meet the standards required to support a public-company financial reporting environment. Partner with Finance and Internal Audit to maintain SOX readiness year-round. QUANTITATIVE RISK ANALYSIS & KRI DEVELOPMENT Build and maintain a meaningful set of Key Risk Indicators (KRIs) that go beyond checkbox coverage metrics to reflect actual risk exposure trends. Apply quantitative risk analysis techniques — including probabilistic modeling and loss magnitude estimation — to prioritize remediation investment and communicate risk in financial terms to executive and board audiences. Leverage AI-assisted analytics and data science techniques to identify themes, concentrations, and anomalies across risk data that qualitative review alone would miss. REGULATORY COMPLIANCE & DEFENSE PROGRAM OBLIGATIONS Maintain deep working knowledge of DFARS 252.204-7012, ITAR Part 120-130, CMMC Level 2 practices, and evolving DoD cybersecurity requirements. Advise program teams on data handling, access control, and CUI safeguarding obligations. Ensure Archer's compliance posture is continuously calibrated against new regulatory guidance and remains audit-ready for government assessments supporting active defense contracts. FAA INFORMATION SECURITY & AIRCRAFT CERTIFICATION SUPPORT Partner with Archer's engineering, avionics, and certification teams to ensure that IS controls and governance processes align with FAA Aircraft Systems Information Security/Protection (ASISP) req
More roles at (SJ2026DV)
- Staff Software Engineer, Android4 days agoSouth East Hampshire, UK
- Senior Staff Systems Engineer09-09-2026San Jose, California, United States$180,000 - $225,000
- Powertrain Architect — Hybrid-Electric Propulsion01-09-2026San Jose, California, United States$172,800 - $237,600
- Structures Architect — Conceptual Design01-09-2026San Jose, California, United States$152,800 - $227,600
- Vehicle Architect — Conceptual Sizing01-09-2026San Jose, California, United States$172,800 - $237,600
- Aircraft Architecture & Integration Engineer26-08-2026San Jose, California, United States$172,800 - $237,600
- Senior Embedded Software Engineer (CCU) - (SJ2026JB)25-08-2026San Jose, California, United States$189,072 to $198,525.60
- Staff Embedded Software Engineer, CCU - (SJ2026PS)25-08-2026San Jose, California, United States$255,653 to $268,435.65
- Software Engineer - (SJ2026BS)25-08-2026San Jose, California, United States$169,208.00 to $177,668.40
- Senior Engineer, State Estimation and Modeling - (SJ2026DV)25-08-2026San Jose, California, United States$205,379 to $215,647.95
- Senior Software Engineer - Integrated Test17-08-2026San Jose, California, United States$140,000 - $180,000
- Staff Data Engineer14-08-2026San Jose, California, United States$175,00.00 - $215,000.00