About the job
Archer is an innovative aerospace company headquartered in San Jose, California, dedicated to revolutionizing urban air mobility through the development of an all-electric vertical takeoff and landing aircraft. Our vision is to provide sustainable air transport solutions while minimizing environmental impact and noise.
At Archer, we embrace challenges and strive for excellence, believing that a diverse workforce fosters creativity and effective problem-solving. Our commitment to equity and inclusion shapes an environment where every team member is valued and celebrated.
Senior Incident Response Engineer (Onsite Role in San Jose, CA)
Job Overview
We are on the lookout for a Senior Incident Response Engineer to spearhead our detection and remediation initiatives across both enterprise and aviation technology landscapes. In this prominent role, you will act as the primary technical liaison between Archer’s internal security team and our Managed Security Service Provider (MSSP). Your expertise will be crucial in translating security alerts into actionable intelligence and orchestrating coordinated responses, ensuring compliance with NIST SP 800-171, CMMC Level 2, and SOX ITGC standards.
This role demands a highly technical and hands-on approach. You will manage investigations from detection to recovery, compile forensic reports for legal and regulatory stakeholders, and design automated response protocols. Given our regulated aerospace context, you will need to balance swift responses with careful evidence preservation.
Why This Role Matters at Archer
As we pave the way for the future of urban air mobility, our intellectual property and critical safety systems are prime targets for cyber threats. An incident could jeopardize aircraft certification or delay FAA approvals. You will be our first line of defense, ensuring our security posture remains robust and ready for audits by investors, government entities, and the Department of Defense.
Key Responsibilities
- MSSP Liaison & Alert Management: Act as the internal SIEM engineer and owner of the MSSP relationship. Independently validate alerts by querying SIEM data using YARA-L, SPL, or KQL.
- Incident Investigation: Lead investigations from initial detection through recovery, documenting findings and preserving evidence.
- Forensic Reporting: Prepare detailed forensic reports for both legal and regulatory compliance.
- Automated Response Design: Develop and implement automated incident response playbooks to enhance efficiency.
