alpaca

Cyber & AI Risk Analyst

Apply Now

At a Glance

Location
Americas
Work Regime
remote
Experience
1+ years
Posted
2026-07-27T09:04:29-04:00

Key Requirements

Required Skills

GCP

Certifications

  • CISA
  • CISSP
  • ISO

Domain Knowledge

  • Cybersecurity
  • Engineering
  • Finance
  • Regulatory

Requirements

Foundational understanding of cybersecurity principles (network security, cloud security, IAM, application security, vulnerability management)

Familiarity with common frameworks such as NIST CSF, ISO 27001, SOC 2, or similar

Understanding of AI/ML concepts and associated risks (data governance, model bias, hallucinations, prompt injection, model misuse, etc.) - you don’t need to be an expert, just curious

Experience working cross-functionally with engineering and product teams

Genuine curiosity about AI and a strong desire to learn, actively experiments with AI tools, and wants to grow AI fluency as the field evolves

Comfort using AI tools daily and willingness to learn newer agentic / assistant-based tooling

Compensation & Benefits

New Hire Home-Office Setup: One-time USD $500

Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Responsibilities

Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of  cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations.

You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features.

This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management.

You’ll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk.

Support the execution of Alpaca’s cybersecurity risk management program

Conduct cyber risk assessments across cloud infrastructure , APIs, trading systems, and internal platforms

About the Company

Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure

for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.

Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.

Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.

Our Team Members: