Archer Aviation Inc.

Senior Incident Response Engineer

Archer Aviation Inc. • $144K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in Incident Response or Security Operations with MSSP management experience.
  • Hands-on experience with incident investigations including malware, phishing, and insider threats.
  • Proficient in OS internals (Windows/Mac/Linux) and scripting (Python, PowerShell, Bash).
  • Experience with SIEM platforms and query languages for threat hunting.
  • Hands-on experience with SOAR platforms for automated workflows.
  • Strong technical writing skills for documentation and incident procedures.
  • Experience facilitating tabletop exercises and incident simulations.

Responsibilities

  • Act as the internal SIEM engineer to validate alerts and ensure effective security tool tuning.
  • Lead technical responses to security incidents, coordinating across teams during breaches.
  • Conduct forensic investigations, preserving evidence and producing incident reports for stakeholders.
  • Execute proactive threat hunts to identify compromises and lateral movements.
  • Develop and validate detection rules based on the MITRE ATT&CK framework.
  • Design incident response playbooks and automate processes using SOAR tools.
  • Oversee compliance with NIST SP 800-171 and facilitate external audits.

Benefits

  • Collaborative environment with cross-functional response teams.
  • Opportunities for professional growth and skill advancement.
  • Engagement with cutting-edge cybersecurity tools and technologies.
  • Involvement in developing robust incident response strategies.
  • Participation in tabletop exercises for practical learning.
Full Job Description
Job Overview

We are seeking a Senior Incident Response (IR) Engineer to lead Archer's detection and remediation efforts. You will serve as the primary technical liaison to our Managed Security Service Provider (MSSP), translating alerts into actionable responses while ensuring compliance with NIST SP 800-171. This role requires deep expertise in digital forensics, threat hunting, and enterprise security operations across SIEM, SOAR, and security platforms to collaborate with infrastructure and security teams to rapidly contain threats and improve our security posture.
Key Responsibilities
  • Serve as Archer's primary internal SIEM engineer, working closely with internal resources and our MSSP for the triage & validation of alerts, defining escalation thresholds, and ensuring accurate tuning of security tools and detection rules.
  • Lead the technical response to validated security incidents including identification, containment, eradication, and recovery, coordinating cross-functional response teams during breaches, malware outbreaks, and insider threats.
  • Conduct deep-dive forensic investigations including memory analysis, disk imaging, timeline reconstruction, and evidence preservation, producing detailed incident reports for HR, legal, and regulatory stakeholders.
  • Execute proactive threat hunts using SIEM data to identify lateral movement, persistence mechanisms, and indicators of compromise (IOCs).
  • Develop, refine, and validate custom detection rules mapped to the MITRE ATT&CK framework, considering Archer-specific threats and compliance-driven use cases.
  • Design and maintain incident response playbooks and SOAR workflows to automate evidence collection, containment actions, and notification procedures.
  • Design log collection requirements and facilitate external compliance audits to ensure adherence to NIST SP 800-171 Audit and Accountability (AU) requirements, CMMC Level 2 practices, and SOX ITGC expectations.
  • Manage endpoint and system detection policies, deploy sensors, and perform live response actions to contain active threats and collect forensic artifacts during incidents.
  • Identify and consume Archer-relevant cyber threat intelligence (CTI) feeds and operationalize IOCs and threat actor TTPs into detection logic.
  • Own the IR documentation architecture: author, organize, and continuously maintain incident response procedures, playbooks, and runbooks to ensure consistency, clarity, and audit-readiness.
  • Own and evolve Archer's IR program strategy, metrics, and roadmap, reporting progress and risk posture to the CISO and executive leadership.
  • Provide technical guidance and tabletop exercise facilitation to IT, application, and leadership teams on incident reporting procedures, response protocols, and lessons learned from post-incident reviews.
Required Qualifications
  • 5+ years in Incident Response or Security Operations (SOC), with proven experience managing MSSP relationships, alert triage, and SLA performance.
  • Hands-on experience investigating security incidents from initial detection through containment and eradication, including malware analysis, phishing attacks, ransomware, and insider threats.
  • Deep understanding of OS internals (Windows/Mac/Linux), network protocols, and proficiency in scripting (Python, PowerShell, Bash) for automation.
  • Working knowledge of SIEM platforms (Google SecOps/Chronicle, Splunk, Microsoft Sentinel) and query languages (YARA-L/GoogleSQL, SPL, KQL) to hunt for threats and validate MSSP detections.
  • Hands-on experience with SOAR platforms (Google SecOps/Chronicle, Palo Alto Cortex XSOAR, Splunk Phantom SOAR) to design and execute automated response workflows.
  • Knowledge of Cyber Threat Intelligence standards and User Behavior Analytics (UEBA).
  • Strong technical writing skills, with demonstrated experience authoring, structuring, and maintaining security documentation, including playbooks, runbooks, and incident response procedures.
  • Demonstrated experience designing, leading, and facilitating tabletop exercises, purple team engagements, or incident simulations for technical and executive audiences.
  • Demonstrated experience conducting proactive threat hunts using SIEM and EDR telemetry to identify lateral movement, persistence mechanisms, and indicators of compromise (IOCs).
  • Broad security utility across the stack, with working familiarity with firewalls and network security, cloud security (AWS/Azure/GCP), and application security (AppSec) practices, enabling cross-domain support beyond core IR/SOC responsibilities.
  • Excellent technical and executive writing and communication skills, with the ability to translate complex threat data and incident timelines for both technical teams and executive leadership during high-pressure situations.
Preferred Qualifications
  • Advanced malware analysis skills (static/dynamic) using IDA Pro, Ghidra, or Cuckoo Sandbox.
  • Familiarity administering email security platforms (Material Security, ProofPoint, Check Point Harmony) and conducting phishing campaigns.
  • Strong understanding of NIST SP 800-171 and CMMC Level 2 requirements, specifically as they relate to Incident Response (IR) and Audit/Accountability (AU).
  • Familiarity with aerospace and startup environments.


Please note that this job description is intended to provide a general overview of the position and does not include an exhaustive list of responsibilities and qualifications.

At Archer we aim to attract, retain, and motivate talent that possess the skills and leadership necessary to grow our business. We drive a pay-for-performance culture and reward performance that supports the Company's business strategy. For this position we are targeting a base pay between $144,000 - $180,000. Actual compensation offered will be determined by factors such as job-related knowledge, skills, and experience.

About Archer Aviation Inc.

Archer Aviation is an American aerospace manufacturer that develops electric vertical takeoff and landing (eVTOL) aircraft for urban air mobility. The company was founded in 2018 by Brett Adcock and Adam Goldstein. Archer Aviation is developing an eVTOL aircraft that can travel up to 60 miles at speeds of up to 150 mph. The aircraft is designed to be quiet, safe, and efficient, with zero emissions. The company has partnerships with United Airlines and Stellantis, and plans to launch its first aircraft in 2024.
Learn more about Archer Aviation Inc.
Market Cap
$403.1 million
Industry
NASDAQ

Similar Jobs

More Jobs at Archer Aviation Inc.

More Information Technology Jobs

Find similar Senior Incident Response Engineer jobs: