Archer GRC开发工程师
Archer GRC Developer
我们是谁:
ShorePoint 是一家快速发展的、在行业内受到认可并获得奖项的网络安全服务公司,专注于高知名度、高威胁的公共和私营部门客户,这些客户要求有经验和经过验证的安全模型来保护他们的数据。我们秉持“努力工作,尽情享受”的理念,庆祝个人和公司的成功。我们对我们的使命充满热情,致力于超越期望为客户服务,同时营造一个支持创造力、责任感、任务成功、批判性思维以及回馈社区的环境。
福利待遇:
作为网络安全精英的一员,我们携手合作,保卫国家的关键基础设施,同时在一个注重个人技术和职业成长的文化中,打造有意义且令人兴奋的职业发展机会。我们坚信,当团队成员感到快乐并得到良好的照顾时,他们才能发挥最佳水平。为了践行这一理念,我们提供全面的福利包,包括主要的医疗保险公司。突出的福利包括 144 小时带薪休假、11 天节假日、85% 的保险费用报销、401(k) 计划、继续教育、证书维护和报销等。
我们寻找的人:
我们正在寻找一位具备配置、开发和维护 RSA Archer 解决方案经验的 Archer GRC 开发人员,以支持治理、风险与合规(GRC)计划。理想的候选人应具备 Archer 开发、数据集成、风险自动化以及符合联邦安全框架的合规性方面的强大技术能力。Archer GRC 开发人员职位需要有配置 Archer 应用程序、设计流程、优化风险和合规流程的实际经验,同时确保系统的稳定性和性能。这是在网络安全市场中一家令人兴奋且快速发展的公司中塑造其增长、发展和文化的一个独特机会。
你将负责:
- 开发和增强 Archer 应用程序,以支持 SOC 事件跟踪、POA&M 管理和 A&A 生命周期监控。
- 配置和优化 Archer 问卷。
- 确保 Archer 解决方案符合 NIST 800-53、800-37、800-30 和 FISMA 要求,提升风险分析和合规工作。
- 领导核心和按需应用程序的设计、开发和配置,为安全和风险团队提供定制的工作流程。
- De
查看英文原文
Who we are:
ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers. Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.
Who we’re looking for:
We are seeking an Archer GRC Developer with expertise in configuring, developing, and maintaining RSA Archer solutions to support Governance, Risk, and Compliance (GRC) initiatives. The ideal candidate will have strong technical capabilities in Archer development, data integration, risk automation, and compliance alignment with federal security frameworks. The Archer GRC Developer role requires hands-on experience in configuring Archer applications, designing workflows, and optimizing risk and compliance processes while ensuring system stability and performance. This is a unique opportunity to shape the growth, development, and culture of an exciting and fast-growing company in the cybersecurity market.
What you’ll be doing:
- Develop and enhance Archer applications to support SOC incident tracking, POA&M management, and A&A lifecycle monitoring.
- Configure and optimize Archer questionnaires.
- Ensure Archer solutions align with NIST 800-53, 800-37, 800-30, and FISMA requirements, enhancing risk analysis and compliance efforts.
- Lead the design, development, and configuration of core and on-demand applications, enabling custom workflows for security and risk teams.
- Develop and integrate data feeds from internal and external sources, ensuring real-time risk assessments and compliance tracking.
- Collaborate with cross-functional teams, including infrastructure, security, and project management, to ensure smooth Archer implementation and compliance alignment.
- Work closely with infrastructure teams to facilitate necessary configurations (e.g., x.509 certificates) while ensuring Archer platform security and performance compliance.
- Design interactive dashboards and reports, providing CISO, CIO, and stakeholders with critical risk insights.
- Initiate and manage change requests for Archer server updates, SQL Server configurations, and OS maintenance, ensuring seamless platform operations.
- Perform hands-on Archer server configuration in development environments, documenting changes for consistency across test and production.
- Oversee platform upgrades, patching, and post-installation validations, maintaining system stability and compliance with security policies.
- Troubleshoot and resolve Archer application issues, working closely with end-users, DBAs, and infrastructure teams.
- Work with business and security teams to gather requirements and ensure Archer implementations meet evolving risk management needs.
- Provide regular status updates to project managers and refine Archer solutions based on iterative customer feedback and evolving risk management needs.
- Provide training and documentation for end-users, ensuring proper adoption and best practices across Archer applications.
- Support risk committee reporting, issues management oversight, and vendor risk assessments for efficient GRC operations.
- Identify and implement process improvements, leveraging Archer automation capabilities to enhance risk and compliance workflows.
- Maintain ongoing communication with Archer vendor support, ensuring timely issue resolution and platform enhancements.
- Assist in the integration of Archer audit logs with Splunk, generating executive-level security reports for improved monitoring.
What you need to know:
- Strong experience in Archer GRC platform development, configuration, and administration.
- Proficiency in designing, developing, and integrating Archer applications with existing security and compliance programs.
- Strong experience with Archer’s advanced workflow and questionnaire capabilities.
- Knowledge of NIST 800-series frameworks (800-53, 800-37, 800-30) and their application to risk management and compliance initiatives.
- Hands-on experience with Windows Server and SQL Server administration related to Archer configuration and performance tuning.
- Experience in automating risk acceptance processes, POA&M tracking, and A&A workflows within Archer.
- Ability to create custom dashboards, reports, and workflows for improved GRC visibility and efficiency.
- Understanding of data integration methods to connect Archer with third-party risk management tools and data sources.
- Strong troubleshooting skills to analyze and resolve technical issues in Archer, databases, and web server integrations.
- Familiarity with Splunk integration for Archer audit log monitoring.
- Strong ability to document configurations, workflows, and system updates for repeatability and compliance best practices.
- Excellent communication and stakeholder engagement skills to align Archer solutions with business and security requirements.
Must have’s:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field.
- 8+ years of relevant experience in of software development experience.
- Strong experience with Archer's Advanced Workflow and Custom Objects (JavaScript-based code blocks used to customize UI/UX on Archer records), in addition to core questionnaire capabilities.
- Proven ability to gather and translate business and client requirements into actionable Archer application designs, configurations, and workflows.
- Hands-on experience in developing Archer applications, integrating risk data feeds, and automating GRC processes.
- Experience working in federal security and compliance environments, aligning Archer solutions with FISMA and NIST frameworks.
- Proficiency in designing and configuring core and on-demand Archer applications, including workflow automation and data integrations.
- Strong troubleshooting skills to diagnose and resolve Archer application issues, database connectivity problems, and web server integrations.
- Experience in integrating Archer with external systems via data feeds, imports, and APIs.
- Knowledge of Archer access control, role-based security, and compliance-driven configurations.
- Familiarity with Windows Server and SQL Server administration as it relates to Archer configuration and performance tuning.
- Ability to develop and maintain Archer dashboards and reports to provide executives with actionable security and risk insights.
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Applicants must currently be a U.S. citizen in compliance with federal contract requirements.
Beneficial to have the following:
- Recent hands-on development experience on a current Archer platform version (6.15).
- Familiarity with OSCAL (Open Security Controls Assessment Language) and its emerging role in Archer-based compliance automation.
- Relevant certifications such as: CISSP, CISA and CISM.
- Experience with Excel VBA macros for data normalization in POA&M reporting.
Where it’s done:
· Remote (Herndon, VA).
Originally posted on Himalayas