Sr. Staff Technology Controls Architecture & Assurance Lead
Job Description
<div class="content-intro"><p>Headquartered in Silicon Valley, California, Archer is a leader in the next-gen aerospace sector building an end-to-end advanced air mobility platform that delivers air taxis, unmanned aircraft systems (“UAS”), aviation-related physical artificial intelligence (“AI”) solutions, and other technologies to customers worldwide across the commercial aerospace and defense sectors.</p> <p><span style="font-weight: 400;">Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members.</span></p></div><p>Archer is building the future of urban air mobility — and the integrity of that mission depends on a security posture that is not just defensible, but demonstrable. As we scale our defense programs, certify aircraft with the FAA, and expand our enterprise footprint, the stakes of a control failure or compliance gap are measured in mission impact, not just audit findings. At Archer, information security is woven into the aircraft certification process itself — making this role uniquely consequential in ways that go well beyond a traditional enterprise GRC function.</p> <p>Archer is seeking a Senior Staff Technology Controls & Assurance Lead to serve as a cornerstone of our GRC function, reporting to the Sr. Director of Governance, Risk & Compliance. In this high-visibility role, you will own IS policy development, internal controls governance, risk quantification, and engagement with internal and external audit bodies. You are the person who makes our risk posture legible — to our board, to our auditors, to DoD assessors, and to our own engineering teams.</p> <p>This is not a checkbox compliance role. We expect you to operate with the intellectual rigor of a risk analyst, the communication precision of an executive advisor, and the technical depth to understand what our controls actually do. You will bring both qualitative judgment and quantitative discipline to the risk function — building data-driven KRIs, leveraging AI and analytics to surface themes and outliers, and translating signal into action across the organization.</p> <p> </p> <h2>What You Will Own</h2> <p><strong>IS POLICY & CONTROLS DEVELOPMENT</strong></p> <p>Lead the development, maintenance, and lifecycle governance of Archer's Information Security policy library, standards, and control frameworks. Ensure policies are grounded in applicable regulatory obligations — NIST SP 800-171, CMMC Level 2, NIST SP 800-161 C-SCRM, DFARS, ITAR — and translated into implementable control requirements that engineering and operations teams can execute against.</p> <p><strong>ISSUE MANAGEMENT & RISK MITIGATION GOVERNANCE</strong></p> <p>Own the enterprise IS Issue Management process from identification through closure — establishing severity thresholds, SLA frameworks, escalation paths, and executive reporting cadences. Govern risk acceptance, exception management, and Plan of Action & Milestones (POA&M) processes. Ensure that open risk items receive time-bound, accountable remediation ownership, and that residual risk is clearly communicated to leadership.</p> <p><strong>CONTROL SELF-ASSESSMENTS (CSAS)</strong></p> <p>Design and execute Archer's internal Control Self-Assessment program — developing testing procedures, coordinating with control owners across engineering, IT, finance, and legal, and producing structured findings that drive control improvement. Maintain ongoing awareness of control effectiveness between formal audit cycles to preve