Alpaca logo

Data Risk Engineer

Hiring from
Worldwide
Work type
Remote
Posted
Aug 7, 2026
Is this job info correct?

Who We Are:

Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.

Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.

Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.

Our Team Members:

We're a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!

We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.

Your Role

As a Data Risk Engineer, you will implement and tune Alpaca's Data Loss Prevention (DLP) capabilities and handle day-to-day DLP alert response. You will triage signals across data movement, refine rulesets to improve signal quality, and partner with People/HR, Legal, Compliance, Engineering, and IT on data mishandling, including coaching users and correcting accidental misuse.

This role sits at the intersection of data protection, privacy, and financial services. Reporting to the Cyber GRC Lead, you will own DLP engineering and alert operations affecting customer data, proprietary information, and trading systems, while working alongside Security on higher-severity Insider Risk and data loss cases. This is a practical individual contributor role for someone experienced with DLP implementation, discreet when engaging employees, and eager to grow into leading Insider Risk investigations end-to-end. Prior experience in a regulated or financial services environment is a strong plus.

Things You Get To Do

  • Implement, operate, and tune DLP across SaaS, email, endpoints, and collaboration tools
  • Triage and work DLP alerts — determine what fired, why, whether it is real, and what to do next
  • Handle false positives and tune rules so the same noise does not keep coming back
  • Respond to user accidents and data mishandling: educate, correct course, and document what happened
  • Engage employees who share PII or sensitive data in the wrong systems, and help them use approved paths
  • Mature data classification and align DLP controls to sensitivity levels
  • Build and improve detections and monitoring for data movement risk across Google, Slack, cloud, source code, and related systems
  • Work with People/HR, Legal, Compliance, Engineering, and IT on data mishandling and related follow-up
  • Partner with the Cyber GRC Lead on higher-severity Insider Risk and data loss cases, and grow into leading investigations from intake through closure
  • Assess risk from unauthorized AI tooling and sensitive data exposure through approved and unsanctioned AI tools
  • Support audits and regulatory asks tied to DLP and data handling
  • Contribute data handling content to security awareness and training
  • Stay current on DLP, data protection, privacy, and financial services expectations

Who You Are (Must Haves)

  • Highly organized with strong attention to detail; comfortable in a fast-paced, high-demand, distributed environment
  • 3+ years in DLP, data protection, or adjacent security work with real alert volume
  • Hands-on experience implementing and tuning DLP in SaaS and/or endpoint environments
  • Comfortable triaging alerts, deciding severity, and knowing when to escalate
  • Solid understanding of data classification, PII handling, and common ways data leaves the company by accident
  • Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk)
  • Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI)
  • Strong written communication; able to document alerts, coaching outreach, and case notes clearly
  • High integrity and discretion when handling confidential and sensitive information
  • Ability to work across People/HR, Legal, Compliance, Engineering, and IT
  • Interest in growing into Insider Risk investigation work

Who You Might Be (Nice to Haves)

  • Academic background, personal interest, or real-world experience in fintech, financial services, or trading platforms
  • Scripting or automation for detections and data analysis (e.g., Python, SQL)
  • Experience with major cloud platforms
  • Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
  • Certifications such as CISSP, CISM, CIPP, or similar
  • Interest in AI-related data risk and using automation to improve triage quality
  • Familiarity with financial services regulatory expectations (e.g., SEC/FINRA, broker-dealer controls) and multi-jurisdiction privacy requirements
  • Prior exposure to Insider Risk, investigations, or incident response

How We Take Care of You:

  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time USD $500
  • Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Recruitment Privacy Policy

Similar jobs

Apply for this job