Tekgence Inc is seeking an Archer Engineer to work on control frameworks and risk management solutions. The role involves automating control selection, creating unique control lists, and developing dashboards for project status and control efficacy.
Responsibilities:
- In Archer LaunchSecure – The automated selection of controls from the control framework based a combination of technology solutions (inherited controls) and response to a questionnaire
- In Archer LaunchSecure – The creation of a unique control list in archer associated with each Archer LaunchSecure record. (see #3)
- In Archer LaunchSecure – The ability to store control testing and/or implementation details associated to the controls each Archer LaunchSecure record
- In Archer LaunchSecure – The ability to import control evidence where applicable from existing other control testing and validation tools
- Example: Leverage WIZ control results to utilize the associated WIZ output as input for control testing and/or implementation details
- Controls in WIZ are associated with the Cloud Security Alliance Cloud Controls Framework. Association to the Control Framework will require control cross association using NIST controls to establish control relationships
- In Archer LaunchSecure (or a new tool/dashboard) – The ability for a BISO, control owners, and control testing validation team to acknowledge and approve/deny testing results with input to the control input team on test results
- Creation of a BISO dashboard for sharing executive summaries of project status, control adoption/completion, control efficacy of test results, trending over time, and control state overview (Visualization of the total risk posture of a project, product, and business area by associated BISO and business leader)
Requirements:
- Experience with Archer LaunchSecure and its functionalities
- Ability to automate the selection of controls from the control framework
- Experience in creating unique control lists in Archer
- Ability to store control testing and/or implementation details
- Experience in importing control evidence from other control testing and validation tools
- Knowledge of the Cloud Security Alliance Cloud Controls Framework
- Ability to cross associate controls using NIST controls
- Experience in creating dashboards for project status and control efficacy
- Ability to visualize risk posture of projects and business areas