Senior Incident Response Engineer

Posted 2 Days Ago
Be an Early Applicant
San Jose, CA, USA
In-Office
144K-180K Annually
Senior level
Aerospace
The Role
Leads incident detection, response, containment, eradication, recovery, threat hunting, digital forensics, SIEM/SOAR engineering, and MSSP coordination. Develops detection rules, response playbooks, automation workflows, compliance audit processes, and incident documentation. Manages endpoint detection policies, threat intelligence, tabletop exercises, and IR program strategy while communicating risk and incident findings to technical teams, executives, legal, HR, and regulatory stakeholders.
Summary Generated by Built In

Headquartered in Silicon Valley, California, Archer is a leader in the next-gen aerospace sector building an end-to-end advanced air mobility platform that delivers air taxis, unmanned aircraft systems (“UAS”), aviation-related physical artificial intelligence (“AI”) solutions, and other technologies to customers worldwide across the commercial aerospace and defense sectors.

Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members.

Job Overview

We are seeking a Senior Incident Response (IR) Engineer to lead Archer's detection and remediation efforts. You will serve as the primary technical liaison to our Managed Security Service Provider (MSSP), translating alerts into actionable responses while ensuring compliance with NIST SP 800-171. This role requires deep expertise in digital forensics, threat hunting, and enterprise security operations across SIEM, SOAR, and security platforms to collaborate with infrastructure and security teams to rapidly contain threats and improve our security posture.

Key Responsibilities
  • Serve as Archer's primary internal SIEM engineer, working closely with internal resources and our MSSP for the triage & validation of alerts, defining escalation thresholds, and ensuring accurate tuning of security tools and detection rules.
  • Lead the technical response to validated security incidents including identification, containment, eradication, and recovery, coordinating cross-functional response teams during breaches, malware outbreaks, and insider threats.
  • Conduct deep-dive forensic investigations including memory analysis, disk imaging, timeline reconstruction, and evidence preservation, producing detailed incident reports for HR, legal, and regulatory stakeholders.
  • Execute proactive threat hunts using SIEM data to identify lateral movement, persistence mechanisms, and indicators of compromise (IOCs).
  • Develop, refine, and validate custom detection rules mapped to the MITRE ATT&CK framework, considering Archer-specific threats and compliance-driven use cases.
  • Design and maintain incident response playbooks and SOAR workflows to automate evidence collection, containment actions, and notification procedures.
  • Design log collection requirements and facilitate external compliance audits to ensure adherence to NIST SP 800-171 Audit and Accountability (AU) requirements, CMMC Level 2 practices, and SOX ITGC expectations.
  • Manage endpoint and system detection policies, deploy sensors, and perform live response actions to contain active threats and collect forensic artifacts during incidents.
  • Identify and consume Archer-relevant cyber threat intelligence (CTI) feeds and operationalize IOCs and threat actor TTPs into detection logic.
  • Own the IR documentation architecture: author, organize, and continuously maintain incident response procedures, playbooks, and runbooks to ensure consistency, clarity, and audit-readiness.
  • Own and evolve Archer's IR program strategy, metrics, and roadmap, reporting progress and risk posture to the CISO and executive leadership.
  • Provide technical guidance and tabletop exercise facilitation to IT, application, and leadership teams on incident reporting procedures, response protocols, and lessons learned from post-incident reviews.
Required Qualifications
  • 5+ years in Incident Response or Security Operations (SOC), with proven experience managing MSSP relationships, alert triage, and SLA performance.
  • Hands-on experience investigating security incidents from initial detection through containment and eradication, including malware analysis, phishing attacks, ransomware, and insider threats.
  • Deep understanding of OS internals (Windows/Mac/Linux), network protocols, and proficiency in scripting (Python, PowerShell, Bash) for automation.
  • Working knowledge of SIEM platforms (Google SecOps/Chronicle, Splunk, Microsoft Sentinel) and query languages (YARA-L/GoogleSQL, SPL, KQL) to hunt for threats and validate MSSP detections.
  • Hands-on experience with SOAR platforms (Google SecOps/Chronicle, Palo Alto Cortex XSOAR, Splunk Phantom SOAR) to design and execute automated response workflows.
  • Knowledge of Cyber Threat Intelligence standards and User Behavior Analytics (UEBA).
  • Strong technical writing skills, with demonstrated experience authoring, structuring, and maintaining security documentation, including playbooks, runbooks, and incident response procedures.
  • Demonstrated experience designing, leading, and facilitating tabletop exercises, purple team engagements, or incident simulations for technical and executive audiences.
  • Demonstrated experience conducting proactive threat hunts using SIEM and EDR telemetry to identify lateral movement, persistence mechanisms, and indicators of compromise (IOCs).
  • Broad security utility across the stack, with working familiarity with firewalls and network security, cloud security (AWS/Azure/GCP), and application security (AppSec) practices, enabling cross-domain support beyond core IR/SOC responsibilities.
  • Excellent technical and executive writing and communication skills, with the ability to translate complex threat data and incident timelines for both technical teams and executive leadership during high-pressure situations.
Preferred Qualifications
  • Advanced malware analysis skills (static/dynamic) using IDA Pro, Ghidra, or Cuckoo Sandbox.
  • Familiarity administering email security platforms (Material Security, ProofPoint, Check Point Harmony) and conducting phishing campaigns.
  • Strong understanding of NIST SP 800-171 and CMMC Level 2 requirements, specifically as they relate to Incident Response (IR) and Audit/Accountability (AU).
  • Familiarity with aerospace and startup environments.

Please note that this job description is intended to provide a general overview of the position and does not include an exhaustive list of responsibilities and qualifications.

At Archer we aim to attract, retain, and motivate talent that possess the skills and leadership necessary to grow our business. We drive a pay-for-performance culture and reward performance that supports the Company’s business strategy. For this position we are targeting a base pay between $144,000 - $180,000. Actual compensation offered will be determined by factors such as job-related knowledge, skills, and experience.

Archer is committed to working with and providing reasonable accommodations to job applicants with physical or mental disabilities, and those with sincerely held religious beliefs. Applicants who may require reasonable accommodation for any part of the application or hiring process should provide their name and contact information to Archer’s People Team at [email protected]. Reasonable accommodations will be determined on a case-by-case basis.
Information collected and processed as part of any job applications you choose to submit is subject to Archer's Candidate Privacy Policy.Certain positions may be eligible for visa sponsorship.Archer is proud to be an Equal Opportunity employer committed to diversity and inclusivity in the workplace. All aspects of employment are decided on the basis of merit, qualifications, and business needs. We do not discriminate based upon race, color, religion, sex, sexual orientation, age, national origin, disability status, protected veteran status, gender identity or any other characteristic protected by federal, state or local laws.Archer Aviation does not engage with external recruiting agencies/individual recruiters with whom it does not have a prior written agreement. Archer reserves the right to make use of any unsolicited resumes that it receives and bears no responsibility for payment of any fees asserted from the use of unsolicited resumes. If you are a recruiting agency or individual recruiter wishing to do business with Archer, please reach out to [email protected]. All employment processes are managed by the Archer People Team.

Skills Required

  • 5+ years of experience in Incident Response or Security Operations, including MSSP relationship management, alert triage, and SLA performance
  • Experience investigating incidents from detection through containment and eradication, including malware, phishing, ransomware, and insider threats
  • Understanding of Windows, macOS, and Linux operating system internals and network protocols
  • Proficiency in Python, PowerShell, and Bash scripting for automation
  • Experience with SIEM platforms including Google SecOps/Chronicle, Splunk, or Microsoft Sentinel
  • Experience with YARA-L/GoogleSQL, SPL, or KQL query languages
  • Experience with SOAR platforms and automated incident response workflows
  • Knowledge of cyber threat intelligence standards and User Behavior Analytics
  • Strong technical writing skills and experience maintaining playbooks, runbooks, and incident response procedures
  • Experience leading tabletop exercises, purple team engagements, or incident simulations
  • Experience conducting proactive threat hunts using SIEM and EDR telemetry
  • Familiarity with firewalls, network security, cloud security, and application security practices
  • Excellent technical and executive communication skills
  • Advanced static or dynamic malware analysis using IDA Pro, Ghidra, or Cuckoo Sandbox
  • Experience administering email security platforms such as Material Security, Proofpoint, or Check Point Harmony
  • Understanding of NIST SP 800-171 and CMMC Level 2 requirements related to Incident Response and Audit/Accountability
  • Familiarity with aerospace and startup environments

Archer Aviation Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Archer Aviation and has not been reviewed or approved by Archer Aviation.

  • Healthcare Strength — Health coverage includes medical, dental, and vision, alongside HSA/FSA options and an Employee Assistance Program, forming a comprehensive base. Wellness activities and company-sponsored outings are additionally referenced.
  • Leave & Time Off Breadth — Time off includes generous PTO, paid sick days, and paid holidays, with unlimited PTO noted for exempt employees. This breadth provides above-average flexibility for a hardware-focused environment.
  • Equity Value & Accessibility — Ownership opportunities include company equity, performance bonuses, and an Employee Stock Purchase Plan with a purchase discount. Equity is used to keep packages competitive in high-demand roles, creating meaningful upside potential.

Archer Aviation Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
283 Employees
Year Founded: 2018

What We Do

Archer is an aerospace company building an all-electric vertical takeoff and landing aircraft focused on improving mobility in cities. The company's mission is to advance the benefits of sustainable air mobility. Archer is designing, manufacturing, and operating a fully electric aircraft that can carry four passengers for 60 miles at speeds of up to 150mph while producing minimal noise. Archer's team is based in the San Francisco Bay Area.

Similar Jobs

Grow Therapy Logo Grow Therapy

Security Engineer

Healthtech • Social Impact • Software
Remote or Hybrid
3 Locations
650 Employees
220K-280K Annually

UL Solutions Logo UL Solutions

Test Engineer

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Fremont, CA, USA
15000 Employees
131K-165K Annually

PNC Bank Logo PNC Bank

Product Owner

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
91K-203K Annually

Boeing Logo Boeing

Flight Software Engineers (Associate/Experienced/Senior)

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
El Segundo, CA, USA
170000 Employees
106K-232K Annually

Similar Companies Hiring

Rangeview Thumbnail
Manufacturing • Defense • Aerospace
Berkeley, CA
25 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account