Security GRC Analyst
Listed on 2026-07-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Who We Are
Alpaca is a US California headquartered brokerage infrastructure technology company and self‑clearing broker‑dealer, delivering execution and custody solutions for Stocks, ETFs, Options, Cryptocurrencies, and more. We have raised over $170 million in funding. With subsidiaries licensed in multiple countries, we serve hundreds of financial institutions worldwide such as broker‑dealers, investment advisors, hedge funds, and crypto exchanges. Our globally distributed team includes engineers, traders, and brokerage professionals who share the mission of opening financial services to everyone on the planet.
We are also deeply committed to open‑source contributions and fostering a vibrant community. We will continue to enhance our award‑winning developer‑friendly API and the infrastructure behind it.
We are seeking an experienced Security Governance, Risk, and Compliance (GRC) Analyst to expand our security efforts and safeguard Alpaca’s systems, data, and client assets. The role includes assessing risks, monitoring compliance, and collaborating with internal and external stakeholders to uphold security policies, regulations, and best practices. The analyst will report directly to the CISO.
Key Responsibilities- Assist the CISO with developing and maintaining a comprehensive security program, including policies and procedures to comply with relevant regulations and standards.
- Ensure compliance with SOC 2 Type 2, ISO 27001, CSA‑Star, GDPR, and external regulatory requirements.
- Conduct regular risk assessments, gap analyses, and develop risk‑treatment plans.
- Apply statistical models to risk frameworks, translating risk into quantifiable metrics (e.g., FAIR).
- Collaborate with the CISO to provide strategic guidance on security matters and respond to emerging risks.
- Manage and maintain an up‑to‑date security control framework.
- Facilitate periodic user‑access reviews.
- Manage and coordinate internal and external audits, including preparation of audit responses and corrective‑action plans.
- Collaborate with other departments to mitigate security risks and collect evidence as needed.
- Manage supply‑chain security risks by performing regular assessments of third parties.
- Provide training and awareness to employees on cybersecurity policies and compliance requirements.
- Assist the security team with triaging security events.
- At least 3 years of experience in risk management and compliance functions.
- Strong knowledge of SOC 2, ISO 27001, CSA, NIST, GDPR, CCPA, FINRA, and SEC cybersecurity guidelines.
- Experience with risk assessments, gap analyses, and risk‑treatment planning.
- Strong familiarity with cloud service providers.
- Experience with audit preparation, response, and corrective‑action plan development.
- Excellent communication and interpersonal skills, with the ability to engage stakeholders and advocate issues strategically.
- Availability for on‑call rotations and after‑hour responses as needed.
- Bachelor’s degree in Information Technology or a related field.
- Security certifications such as CISSP, CRISC, or GIAC.
- Understanding of financial and privacy regulations.
- Experience in financial services.
- Experience working at startups.
- Business acumen to balance trade‑offs between stakeholders, technology feasibility, and budget constraints.
- Competitive salary and stock options.
- Health benefits start on day 1:
Medical, Dental, Vision (US); supplemental health care (Canada); local benefits (Japan); and an international stipend to offset medical costs. - One‑time $500 USD home‑office setup.
- Monthly $150 USD stipend via Brex Card.
Alpaca is proud to be an equal‑opportunity workplace dedicated to pursuing and hiring a diverse workforce.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).