IS POLICY & CONTROLS DEVELOPMENT
Lead the development, maintenance, and lifecycle governance of Archer’s Information Security policy library, standards, and control frameworks. Ensure policies are grounded in applicable regulatory obligations — NIST SP 800-171, CMMC Level 2, NIST SP 800-161 C-SCRM, DFARS, ITAR — and translated into implementable control requirements that engineering and operations teams can execute against.
ISSUE MANAGEMENT & RISK MITIGATION GOVERNANCE
Own the enterprise IS Issue Management process from identification through closure — establishing severity thresholds, SLA frameworks, escalation paths, and executive reporting cadences. Govern risk acceptance, exception management, and Plan of Action & Milestones (POA&M) processes. Ensure that open risk items receive time-bound, accountable remediation ownership, and that residual risk is clearly communicated to leadership.
CONTROL SELF-ASSESSMENTS (CSAS)
Design and execute Archer’s internal Control Self-Assessment program — developing testing procedures, coordinating with control owners across engineering, IT, finance, and legal, and producing structured findings that drive control improvement. Maintain ongoing awareness of control effectiveness between formal audit cycles to prevent surprise gaps.
INTERNAL & EXTERNAL AUDIT MANAGEMENT
Serve as the primary IS liaison for internal audit, external financial auditors, and government compliance assessors — including CMMC C3PAO assessments and DCSA reviews. Manage evidence collection, artifact packaging, auditor communications, and findings remediation tracking. Translate auditor requests into efficient, well-organized responses that demonstrate the maturity and rigor of Archer’s control environment.
Own Archer’s SOX IT General Controls program — coordinating with external auditors, managing ITGC scoping, and ensuring that change management, access controls, and IT operations controls meet the standards required to support a public-company financial reporting environment. Partner with Finance and Internal Audit to maintain SOX readiness year-round.
QUANTITATIVE RISK ANALYSIS & KRI DEVELOPMENT
Build and maintain a meaningful set of Key Risk Indicators (KRIs) that go beyond checkbox coverage metrics to reflect actual risk exposure trends. Apply quantitative risk analysis techniques — including probabilistic modeling and loss magnitude estimation — to prioritize remediation investment and communicate risk in financial terms to executive and board audiences. Leverage AI-assisted analytics and data science techniques to identify themes, concentrations, and anomalies across risk data that qualitative review alone would miss.
REGULATORY COMPLIANCE & DEFENSE PROGRAM OBLIGATIONS
Maintain deep working knowledge of DFARS 252.204-7012, ITAR Part 120-130, CMMC Level 2 practices, and evolving DoD cybersecurity requirements. Advise program teams on data handling, access control, and CUI safeguarding obligations. Ensure Archer’s compliance posture is continuously calibrated against new regulatory guidance and remains audit-ready for government assessments supporting active defense contracts.
FAA INFORMATION SECURITY & AIRCRAFT CERTIFICATION SUPPORT
Partner with Archer’s engineering, avionics, and certification teams to ensure that IS controls and governance processes align with FAA Aircraft Systems Information Security/Protection (ASISP) requirements throughout the type certification lifecycle. Support the application of airworthiness security standards — including RTCA DO-326A, DO-356A, and DO-355A — as the FAA applies Special Conditions and Means of Compliance to Archer’s aircraft systems. Assess how intentional unauthorized electronic interactions (IUEI) and enterprise IS risk could propagate into aircraft safety domains, and maintain awareness of evolving FAA rulemaking that will shape Archer’s certification obligations as we approach type certificate milestones.
EXECUTIVE COMMUNICATION & STAKEHOLDER ENGAGEMENT
Produce crisp, executive-quality risk briefings, board-level dashboards, and audit-ready evidence packages. Communicate complex regulatory and technical risk findings with clarity and precision to non-technical audiences — including the CISO, General Counsel, CFO, and Board Audit Committee. Serve as a trusted advisor to business stakeholders who need to understand their compliance obligations without drowning in framework language.