Cyber & AI Risk Analyst at Alpaca
Worldwide
<div class="content-intro"><p><strong>Who We Are:</strong></p> <p>Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our <a href="https://alpaca.markets/blog/alpaca-raises-150-million-at-a-1-15b-valuation-to-build-the-global-standard-for-brokerage-infrastructure/">recent Series D funding round</a> brought our total investment to over $320 million, fueling our ambitious vision.</p> <p>Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 9 million brokerage accounts.</p> <p>Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of <strong>opening financial services to everyone on the planet</strong>. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.</p> <p>Alpaca is proudly backed by top-tier global investors, including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Unbound, SBI Group, Derayah Financial, Elefund, and Y Combinator.</p> <p> </p> <p><strong>Our Team Members:</strong></p> <p>We're a dynamic team of 230+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!<br><br>We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.</p></div><p><span style="font-size: 12pt;"><strong>Your Role:</strong></span></p> <p><span style="font-size: 12pt;">As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca’s security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations.</span></p> <p><span style="font-size: 12pt;">You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features.</span></p> <p><span style="font-size: 12pt;">This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management. You’ll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk.</span></p> <p><span style="font-size: 12pt;">We’re looking for someone curious, organized, and eager to grow. If you enjoy learning how technical systems work, translating risk into clear language, and building structured programs from the ground up - then this role is for you. Prior GRC experience is a plus, but not required; we’re happy to invest in the right candidate.</span></p> <p> </p> <h3><span style="font-size: 12pt;"><strong>Things You Get To Do:</strong></span></h3> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Support the execution of Alpaca’s cybersecurity risk management program</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Conduct cyber risk assessments across cloud infrastructure, APIs, trading systems, and internal platforms</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Assist in identifying, documenting, and evaluating AI-related risks (model risk, data privacy, bias, explainability, adversarial threats, model misuse)</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Help develop and maintain AI governance controls aligned with evolving regulatory expectations, such as the EU AI Act</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Perform third-party/vendor security and AI risk assessments</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Contribute to control testing across frameworks such as SOC 2, ISO 27001, CSA Star, NIST CSF, and emerging AI governance standards</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Track remediation efforts and maintain risk registers and reporting dashboards</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Support internal and external audits by preparing documentation and evidence</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Monitor regulatory developments related to cybersecurity, financial services, and AI governance</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Help mature policies, standards, and procedures for both cyber and AI domains</span></li> </ul> <p> </p> <h3><span style="font-size: 12pt;"><strong>Who You Are (Must-Haves):</strong></span></h3> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">1+ years of experience in cybersecurity, risk management, IT audit, GRC, or a related field - internships, coursework, or equivalent experience is welcome</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Foundational understanding of cybersecurity principles (network security, cloud security, IAM, application security, vulnerability management)</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Familiarity with common frameworks such as NIST CSF, ISO 27001, SOC 2, or similar</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Understanding of AI/ML concepts and associated risks (data governance, model bias, hallucinations, prompt injection, model misuse, etc.) - you don’t need to be an expert, just curious</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Strong written communication and documentation skills</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Ability to assess technical risks and clearly communicate them to non-technical stakeholders</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience working cross-functionally with engineering and product teams</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Highly organized with strong attention to detail</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Comfort working in a fast-paced environment</span></li> </ul> <p> </p> <h3><span style="font-size: 12pt;"><strong>Who You Might Be (Nice-to-Haves):</strong></span></h3> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Academic background, personal interest, or real-world experience in fintech, financial services, or trading platforms</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Exposure to AI governance, model risk management, or responsible AI programs</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Familiarity with emerging AI regulatory frameworks (e.g., NIST AI RMF, EU AI Act concepts, model governance practices)</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience with GCP or other major cloud platforms</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience supporting or observing SOC 2, ISO 27001, or regulatory audits</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Security certifications (e.g., Security+, SSCP) or early-stage GRC certifications</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Interest in pursuing advanced certifications (CISA, CRISC, CISSP, or AI governance certifications)</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience working remotely or in distributed teams</span></li> </ul><div class="content-conclusion"><h3><strong>How We Take Care of You:</strong></h3> <ul> <li style="font-weight: 400; text-align: justify;"><span style="font-weight: 400;">Competitive Salary & Stock Options</span></li> <li style="text-align: justify;">Health Benefits</li> <li style="font-weight: 400; text-align: justify;"><span style="font-weight: 400;">New Hire Home-Office Setup: One-time USD $500</span></li> <li style="font-weight: 400; text-align: justify;"><span style="font-weight: 400;">Monthly Stipend: USD $150 per month via a Brex Card</span></li> </ul> <p><em><span style="font-weight: 400;">Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.<br></span></em></p> <p><span style="font-size: 8pt;"><a href="https://files.alpaca.markets/disclosures/AlpacaRecruitmentPrivacyPolicy.pdf"><em><span style="font-weight: 400;">Recruitment Privacy Policy</span></em></a></span></p></div>
Apply Now