About the job
Archer Aviation, located in San Jose, California, is pioneering the future of sustainable air mobility by developing an innovative all-electric vertical takeoff and landing aircraft. Our mission is to enhance air mobility while significantly reducing noise pollution. We are committed to advancing technology that will redefine air transportation.
At Archer, we embrace challenges and strive for excellence through diversity and inclusion. We believe that a diverse workforce fosters innovation, insight, and ultimately leads to greater success. Our workplace is dedicated to creating an equitable environment that celebrates the unique contributions of all team members.
Senior Enterprise Application Security Engineer (Hybrid-San Jose)
Job Overview
We are seeking an exceptional Senior Enterprise Application Security Engineer to architect and secure the cloud infrastructure driving the next wave of sustainable air mobility. The ideal candidate is a proactive collaborator with outstanding communication skills and a comprehensive understanding of cloud security. In this role, you will safeguard our cloud-native environments (AWS/Azure) and protect our telemetry, flight operations, and enterprise systems from advanced persistent threats. You will bridge DevOps and Security by embedding secure design principles into our Infrastructure as Code (IaC) and CI/CD pipelines, ensuring compliance with aviation and federal standards (NIST CSF, 800-53, FedRAMP, DO-326A).
Key Responsibilities
- Cloud Architecture & Hardening: Design, implement, and maintain robust cloud architectures in AWS and Azure. Enforce zero-trust principles and least-privilege access utilizing advanced IAM policies and roles.
- Infrastructure as Code (IaC) Security: Lead the security review and automated scanning of IaC templates (Terraform, CloudFormation, Helm) to preemptively prevent misconfigurations.
- DevSecOps & Automation: Integrate security tools (CSPM, CWPP, Secret Scanning) into CI/CD pipelines (Jenkins, GitLab, GitHub Actions) to facilitate rapid and secure deployments.
- Kubernetes Security: Implement security controls for Kubernetes clusters, ensuring compliance with industry best practices.

