Alpaca logo
AlpacaΒ·

Sr. Insider & Data Risk Analyst - Alpaca

About Alpaca

Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totaling over 10 million brokerage accounts.

Our global team is a diverse group of 400+ experienced engineers, traders, and brokerage professionals spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond. Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, and Y Combinator.

Your Role

As Senior Insider & Data Risk Analyst, you will own insider risk investigations and help mature Alpaca's Insider Risk Management Program and Data Loss Prevention (DLP) capabilities. You will triage and investigate signals across people, devices, identity, and data movement, apply risk tiering and escalation standards, and partner with People/HR, Legal, Compliance, Engineering, and IT on sensitive cases involving departures, policy violations, and data misuse.

Reporting to the Cyber GRC Lead, you will serve as Security's escalation point for insider and data loss cases affecting trading systems, customer data, and proprietary information. This is a practical senior individual contributor role for someone experienced, discreet, and highly organized who can own investigation workflows, translate risk into clear language for leadership, and build durable programs and processes.

Key Responsibilities

  • Own insider risk investigations from triage through closure, including case timelines, containment, escalation, documented determinations, and lessons learned.
  • Mature Alpaca's Insider Risk Management Program, including case management processes, risk tiering, and repeatable workflows.
  • Operate and tune Data Loss Prevention tooling across multiple environments and endpoints, refining rulesets to improve signal and reduce false positives.
  • Mature data classification and align DLP controls to sensitivity levels.
  • Investigate potential data exfiltration, misuse, and policy violations across source code, Google, AWS, Azure, third-party apps, Slack, and trading platform system access.
  • Partner with People/HR, Legal, Compliance, and IT on sensitive personnel cases with discretion and care.
  • Assess risk from unauthorized AI/agentic tooling and sensitive data exposure through approved and unsanctioned AI tools.
  • Leverage Agentic AI to continue maturation of the Insider risk program.
  • Lead insider and data risk assessments and maintain risk registers.
  • Support internal and external audits and regulatory requirements.
  • Contribute insider risk and data handling content to the security awareness and training program.
  • Serve as the insider risk escalation point for the Security team and mentor others on investigations and casework.
  • Monitor developments in insider risk, data protection, privacy, and financial services regulation.

Qualifications

Must Haves

  • Experience: 4+ years in insider risk, DLP operations, digital forensics, or security investigations, including hands-on case management on sensitive personnel matters.
  • Investigation Skills: Hands-on experience leading investigations and case management with discretion, integrity, and sound judgment on sensitive personnel matters.
  • Tooling & Technical Capabilities: Hands-on experience operating DLP in SaaS and endpoint environments and tuning rules to improve signal quality.
  • Automation: Experience with workflow automation, AI, or SOAR platforms for alert triage and case orchestration.
  • Governance & Logs: Solid understanding of data classification and governance, alongside working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk) to support investigations.
  • Framework Knowledge: Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI).
  • Communication: Strong written communication skills to draft clear investigation reports, case documentation, and executive summaries.
  • Cross-functional Collaboration: Ability to work effectively across People/HR, Legal, Compliance, Engineering, and IT.

Nice to Haves

  • Fintech, financial services, or trading platform background or experience.
  • Digital forensics or eDiscovery experience.
  • Experience with UEBA or insider risk detection platforms.
  • Scripting or automation skills for detections and data analysis (e.g., Python, SQL).
  • Experience with major cloud platforms (AWS, Azure, GCP).
  • Experience supporting or observing SOC 2, ISO 27001, or regulatory audits.
  • Relevant industry certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or similar.
  • Interest in AI-related data risk and utilizing AI tooling to increase efficiency.
  • Familiarity with financial services regulatory expectations (e.g., SEC/FINRA, broker-dealer controls) and multi-jurisdiction privacy requirements.
  • Experience in security operations or incident response.

Compensation & Benefits

  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time $500 USD
  • Monthly Stipend: $150 USD per month via a Brex Card

Open to

Worldwide

Sign in to track applications and earn points.

More roles at Alpaca

Similar remote roles