高级内部与数据风险分析师
Sr. Insider & Data Risk Analyst
我们是谁:
Alpaca 是一家总部位于美国的全球领先代理优先经纪基础设施公司,提供股票、ETF、期权、加密货币、固定收益、24/5 小时交易等服务。
在我们的子公司中,Alpaca 是一家持牌金融服务公司,通过我们机构级 API 为全球 40 个国家的数百家金融机构提供服务。这包括经纪自营商、投资顾问、财富管理公司、对冲基金和加密货币交易所,总计超过 1000 万笔经纪账户。
我们的全球团队是由经验丰富的工程师、交易员和经纪专业人士组成的多元化团队,致力于实现我们让全球每个人都能获得金融服务的使命。我们高度重视开源贡献,积极培育活跃的社区,持续提升我们获奖的、开发者友好的 API 及其背后的强大基础设施。
Alpaca 获得了来自顶级全球投资者的 4 亿美元融资,包括 Portage Ventures、Spark Capital、Tribe Capital、Social Leverage、Horizons Ventures、Opera Tech Ventures、SBI Group、Derayah Financial、Unbound、Peak XV、Elefund 和 Y Combinator。
我们的团队成员:
我们是一个由 400 多名分布在世界各地的成员组成的充满活力的团队,大家在世界各个最喜欢的地方工作,团队成员遍布美国、加拿大、日本、匈牙利、尼日利亚、巴西、英国等地!
我们正在寻找渴望为 Alpaca 快速发展做出贡献的热情人士。如果你认同我们的核心价值观——保持好奇、富有同理心、承担责任,并准备好产生重大影响,我们鼓励你申请。
你的角色
作为高级内部风险与数据风险分析师,你将负责内部风险调查,并帮助完善 Alpaca 的内部风险管理系统和数据防泄漏能力。你将对人员、设备、身份和数据流动中的信号进行分类和调查,应用风险分级和升级标准,并与人力资源、法律、合规、工程和 IT 部门合作处理涉及离职、政策违规和数据滥用的敏感案件。
该职位处于内部风险、数据保护、隐私和金融服务的交汇点。向网络安全 GRC 主管汇报,你将成为安全团队在涉及交易系统、客户数据和专有信息的内部和数据泄露案件中的主要联系人。这是一个需要经验丰富、谨慎且高度组织化的高级个人贡献者角色。
查看英文原文
Who We Are:
Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.
Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.
Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.
Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.
Our Team Members:
We're a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!
We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.
Your Role
As Senior Insider & Data Risk Analyst, you will own insider risk investigations and help mature Alpaca's Insider Risk Management Program and Data Loss Prevention capabilities. You will triage and investigate signals across people, devices, identity, and data movement, apply risk tiering and escalation standards, and partner with People/HR, Legal, Compliance, Engineering, and IT on sensitive cases involving departures, policy violations, and data misuse.
This role sits at the intersection of insider risk, data protection, privacy, and financial services. Reporting to the Cyber GRC Lead, you will serve as Security's escalation point for insider and data loss cases affecting trading systems, customer data, and proprietary information. This is a practical senior individual contributor role for someone experienced, discreet, and highly organized who can own investigation workflows, translate risk into clear language for leadership, and build durable programs and processes. Prior experience in a regulated or financial services environment is a strong plus.
Things You Get To Do
- Own insider risk investigations from triage through closure, including case timelines, containment, escalation, and documented determinations and lessons learned
- Mature Alpaca's Insider Risk Management Program, including case management processes, risk tiering, and repeatable workflows
- Operate and tune Data Loss Prevention tooling across multiple environments and endpoints, refining rulesets to improve signal and reduce false positives
- Mature data classification and align DLP controls to sensitivity levels
- Investigate potential data exfiltration, misuse, and policy violations; build and tune detections and monitoring
- Investigate misuse and exfiltration risk across source code, Google, AWS, Azure, third party apps, Slack, and trading and platform system access
- Partner with People/HR, Legal, Compliance, and IT on sensitive cases (departures, policy violations, data mishandling) with discretion and care
- Assess risk from unauthorized AI/agentic tooling and sensitive data exposure through approved and unsanctioned AI tooling
- Leverage Agentic AI to continue maturation of Insider risk program
- Lead insider and data risk assessments and maintain risk registers
- Support internal and external audits and regulatory requirements
- Contribute insider risk and data handling content to the security awareness and training program
- Serve as the insider risk escalation point for the Security team and mentor others on investigations and casework
- Monitor developments in insider risk, data protection, privacy, and financial services regulation.
Who You Are (Must Haves)
- Highly organized with strong attention to detail; comfortable in a fast paced, high demand, distributed environment
- 4+ years in insider risk, DLP operations, digital forensics, or security investigations, including hands on case management on sensitive personnel matters
- Hands on experience leading investigations and case management with discretion, integrity, and sound judgment on sensitive personnel matters
- Hands-on experience operating DLP in SaaS and endpoint environments and tuning rules to improve signal quality
- Experience with workflow automation, AI, or SOAR platforms for alert triage and case orchestration
- Solid understanding of data classification and data governance
- Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk) to support investigations
- Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI)
- Strong written communication, able to draft clear investigation reports, case documentation, and executive summaries
- High integrity and discretion when handling confidential and sensitive information
- Ability to work across People/HR, Legal, Compliance, Engineering, and IT
Who You Might Be (Nice to Haves)
- Academic background, personal interest, or real world experience in fintech, financial services, or trading platforms
- Digital forensics or eDiscovery experience
- Experience with UEBA or insider risk detection platforms
- Scripting or automation for detections and data analysis (e.g., Python, SQL)
- Experience with major cloud platforms
- Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
- Certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or similar
- Interest in AI related data risk (e.g., data exposure through AI tools) and using AI tooling to work more efficiently
- Familiarity with financial services regulatory expectations (e.g., SEC/FINRA, broker dealer controls) and multi jurisdiction privacy requirements
- Experience in security operations or incident response
How We Take Care of You:
- Competitive Salary & Stock Options
- Health Benefits
- New Hire Home-Office Setup: One-time USD $500
- Monthly Stipend: USD $150 per month via a Brex Card
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
Recruitment Privacy Policy