远程工作雷达

Sr. Insider Risk Analyst

开发工程全球可投
公司Alpaca
薪资未公开
工作地点Remote - Global Anywhere
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间2026-08-07
数据来源Greenhouse
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

Who We Are:

Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.

Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.

Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.

Our Team Members:

We're a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!

We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.

Your Role

As Senior Insider & Data Risk Analyst, you will own insider risk investigations and help mature Alpaca's Insider Risk Management Program and Data Loss Prevention capabilities. You will triage and investigate signals across people, devices, identity, and data movement, apply risk tiering and escalation standards, and partner with People/HR, Legal, Compliance, Engineering, and IT on sensitive cases involving departures, policy violations, and data misuse.

This role sits at the intersection of insider risk, data protection, privacy, and financial services. Reporting to the Cyber GRC Lead, you will serve as Security's escalation point for insider and data loss cases affecting trading systems, customer data, and proprietary information. This is a practical senior individual contributor role for someone experienced, discreet, and highly organized who can own investigation workflows, translate risk into clear language for leadership, and build durable programs and processes. Prior experience in a regulated or financial services environment is a strong plus.

Things You Get To Do

  • Own insider risk investigations from triage through closure, including case timelines, containment, escalation, and documented determinations and lessons learned
  • Mature Alpaca's Insider Risk Management Program, including case management processes, risk tiering, and repeatable workflows
  • Operate and tune Data Loss Prevention tooling across multiple environments and endpoints, refining rulesets to improve signal and reduce false positives
  • Mature data classification and align DLP controls to sensitivity levels
  • Investigate potential data exfiltration, misuse, and policy violations; build and tune detections and monitoring
  • Investigate misuse and exfiltration risk across source code, Google, AWS, Azure, third party apps, Slack, and trading and platform system access
  • Partner with People/HR, Legal, Compliance, and IT on sensitive cases (departures, policy violations, data mishandling) with discretion and care
  • Assess risk from unauthorized AI/agentic tooling and sensitive data exposure through approved and unsanctioned AI tooling
  • Leverage Agentic AI to continue maturation of Insider risk program
  • Lead insider and data risk assessments and maintain risk registers
  • Support internal and external audits and regulatory requirements
  • Contribute insider risk and data handling content to the security awareness and training program
  • Serve as the insider risk escalation point for the Security team and mentor others on investigations and casework
  • Monitor developments in insider risk, data protection, privacy, and financial services regulation.

Who You Are (Must Haves)

  • Highly organized with strong attention to detail; comfortable in a fast paced, high demand, distributed environment
  • 4+ years in insider risk, DLP operations, digital forensics, or security investigations, including hands on case management on sensitive personnel matters
  • Hands on experience leading investigations and case management with discretion, integrity, and sound judgment on sensitive personnel matters
  • Hands-on experience operating DLP in SaaS and endpoint environments and tuning rules to improve signal quality
  • Experience with workflow automation, AI, or SOAR platforms for alert triage and case orchestration
  • Solid understanding of data classification and data governance
  • Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk) to support investigations
  • Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI)
  • Strong written communication, able to draft clear investigation reports, case documentation, and executive summaries
  • High integrity and discretion when handling confidential and sensitive information
  • Ability to work across People/HR, Legal, Compliance, Engineering, and IT

Who You Might Be (Nice to Haves)

  • Academic background, personal interest, or real world experience in fintech, financial services, or trading platforms
  • Digital forensics or eDiscovery experience
  • Experience with UEBA or insider risk detection platforms
  • Scripting or automation for detections and data analysis (e.g., Python, SQL)
  • Experience with major cloud platforms
  • Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
  • Certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or similar
  • Interest in AI related data risk (e.g., data exposure through AI tools) and using AI tooling to work more efficiently
  • Familiarity with financial services regulatory expectations (e.g., SEC/FINRA, broker dealer controls) and multi jurisdiction privacy requirements
  • Experience in security operations or incident response

How We Take Care of You:

  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time USD $500
  • Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Recruitment Privacy Policy

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位