ERM Program Manager

Alpaca · Remote - Americas · Product

Posted 2026-10-08

Apply for this role →

Your Role

This is a hands-on operator role. You will update risk registers yourself, run functional risk lead check-ins, and produce board materials. No direct reports.

Alpaca has the ERM framework, taxonomy, and scoring model. As ERM Program Manager, you will own execution: intake from functional risk leads, risk register hygiene, residual scoring with risk owners, and board-ready reporting on schedule. You report to the CISO / ERM Lead and work closely with the ERM Working Group, functional risk leads, and local entity leaders.

Things You Get To Do

Run the ERM intake cycle end to end: Ticket ingestion, functional interviews, surveys, and ad hoc signals from incidents or operational channels.

Maintain functional and enterprise risk registers in Vanta: owners, inherent and residual scores, mitigations, and status.

Coordinate functional risk lead check-ins, chase blockers, and normalize inputs into the enterprise view.

Map risks to Alpaca's 15 L1 categories and Appendix C L2 subcategories to enterprise scenarios for reporting.

Apply the ERM Risk Scoring Model and push residual validation with risk owners.

Track mitigation plans, action owners, target dates, and escalations.

Define KRIs with data owners; use proxy metrics where instrumentation is still maturing.

Produce leadership and board ERM materials.

Support ERM Working Group agendas, minutes, and action tracking.

Operate the intake triage workflow: score, dedupe, register action.

Build playbooks and templates for functional leads.

Support local entity quarterly risk updates and escalation hygiene.

Surface emerging risks (crypto, AI, multi-jurisdiction) for review.

Who You Are (Must-Haves)

Mid-career (roughly 5 to 10 years) in operational risk, ERM, GRC, or compliance program management at a regulated financial institution (broker-dealer, fintech, or capital markets).

Built or run a risk register from intake through reporting. Not framework design only.

Can coordinate Legal, Compliance, Finance, Product, Security, and Operations stakeholders without direct authority.

Hands-on GRC platform experience

Clear writing: risk statements, executive summaries, board-ready tables.

SEC/FINRA familiarity or equivalent regulated-environment experience.

Who You Might Be (Nice-To-Haves)

Broker-dealer, clearing, or custody operations context.

High-growth fintech where you stood up ERM while the business scaled.

Crypto / digital assets risk register exposure.

Multi-entity, multi-jurisdiction risk consolidation.

Jira service desk or structured intake workflow design.

COSO ERM / ISO 31000 implementation as an operator.

Prior work drafting board or risk committee reporting.

Apply for this role →

← Back to all jobs