Назад
Company hidden
обновлено 13 дней назад

Senior Staff Technology Controls Architecture & Assurance Lead (Cybersecurity)

207 400 - 259 200$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Staff Technology Controls Architecture & Assurance Lead (Cybersecurity): Building and governing information security controls, assurance programs, and quantitative risk reporting for aerospace aircraft certification and defense compliance with an accent on NIST, CMMC, DFARS, ITAR, SOX ITGC, and FAA security requirements. Focus on designing control self-assessments, managing audits and remediation, modeling risk exposure, and translating complex regulatory and technical findings into board-level decisions.

Location: San Jose, California, United States. U.S. citizenship and eligibility to obtain a DoD Secret security clearance are required. Visa sponsorship is not available.

Base pay: $207,400–$259,200 per year.

Company

hirify.global is an aerospace company developing, manufacturing, and operating all-electric vertical takeoff and landing aircraft for sustainable urban air mobility.

What you will do

  • Lead the development and lifecycle governance of information security policies, standards, and control frameworks.
  • Own issue management, risk acceptance, exception management, POA&M processes, escalation paths, and executive reporting.
  • Design and execute Control Self-Assessments across engineering, IT, finance, and legal.
  • Manage internal audits, external financial audits, CMMC C3PAO assessments, DCSA reviews, evidence collection, and remediation tracking.
  • Own the SOX IT General Controls program and maintain year-round audit readiness.
  • Develop KRIs and quantitative risk models, using analytics and AI-assisted techniques to identify trends, concentrations, and anomalies.

Requirements

  • 8+ years of information security experience, including at least 4 years in GRC, compliance, or information security audit roles.
  • Hands-on experience with NIST SP 800-171, CMMC Level 2, NIST SP 800-161, DFARS 252.204-7012, and ITAR.
  • Experience managing SOX ITGC programs, including scoping, control design, auditor engagement, and continuous readiness.
  • Experience designing CSA programs and managing issues through risk-accepted closure.
  • Experience leading formal external audits or government compliance assessments and managing evidence and remediation under deadlines.
  • Ability to build quantitative risk models and KRIs and communicate risk clearly to engineers, executives, and board-level stakeholders.

Nice to have

  • Active DoD Secret or Top Secret/SCI clearance.
  • CISSP, CISM, CRISC, CISA, CMMC RP, or CCP certification.
  • FAA ASISP and RTCA DO-326A, DO-356A, and DO-355A experience.
  • Aerospace, aviation, defense, FAIR, AI/ML analytics, FOCI, or DCSA facility clearance experience.
  • Startup or high-growth company experience.

Culture & Benefits

  • Work in a high-impact aerospace environment connecting information security with aircraft certification and defense programs.
  • Collaborate with engineering, avionics, certification, finance, legal, internal audit, and executive stakeholders.
  • Contribute to an equitable and inclusive workplace.
  • Performance-based compensation aligned with business strategy.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →