Lead, Data Governance

Alpaca · Remote - Americas · Data

Posted 2026-08-12

Apply for this role →

Your Role:

As Lead, Data Governance, you will help build and run Alpaca's data governance and data security program across our lakehouse, analytics tools, and internal data products. You'll set the standards for how we classify data, who can access it, and how we protect it, working closely with Data Engineering and Data Science to put those standards into practice.

Our data environment has grown quickly. We run several data solutions, and we handle more cross-region data every year across the US, Japan, EU, and other markets. We are also evaluating new analytics and AI tools on a regular basis. Access controls have not always kept pace, and we need someone who can help us catch up and stay ahead of partner and regulatory expectations.

The team is fully remote. This is an individual contributor role with no direct reports. You'll report to our Chief Information & Security Officer (CISO) and work closely with Data Engineering and Data Science through a dotted-line relationship.

Things You Get To Do

- Build and maintain our data governance policies, classification standards, ownership model, and exception process, in line with Security and Privacy requirements

- Own data access governance for the lakehouse and analytics stack, including entitlement standards, periodic access reviews, and least-privilege access across Trino, Ranger, Cube, Metabase, and related tools

- Work with Data Engineering on the technical side of controls such as Ranger policies, schema restrictions, and service account management

- Set data quality standards and help Data teams track and improve against them

- Keep our data inventory, metadata, and lineage documentation current for compliance and audit purposes

- Review data-related vendors and new use cases (analytics platforms, reverse ETL, AI query tools, notebooks, and similar) with Security, Privacy, and Legal

- Support sensitive and cross-border data requests, including PII handling and regional data flows for Engineering, Operations, and New Markets

- Prepare evidence for SOC 2, ISO 27001, CSA STAR, partner security reviews, and regulatory exams

- Track data risks and control gaps as part of our Enterprise Risk Management (ERM) program

- Be the go-to governance partner for Data and Security on access, classification, and tooling questions

- Help define guardrails as we expand AI and agentic use of corporate data in analytics workflows

Who You Are (Must-Haves)

- 5+ years in data governance, data security, GRC, privacy engineering, or a related field

- At least 2 years working with modern data platforms (lakehouse/warehouse, SQL engines, BI, semantic layers)

- Solid grasp of data governance frameworks (DAMA-DMBOK, NIST, or similar) and how to apply them in a company that moves quickly

- You've built or run data classification, access control, or entitlement review programs, not just written the policies

- Familiar with cloud data platforms (GCP a plus) and typical analytics tooling

- Working knowledge of privacy and regulatory requirements in financial services (GDPR, CCPA, cross-border transfers, and similar)

- Experience supporting SOC 2, ISO 27001, or similar audits

- You work well with engineering teams and know how to push for good controls without becoming a bottleneck

- Strong written and verbal communication skills

- Organized, detail-oriented, and comfortable in a fast-paced remote environment

- Comfortable as an IC with no direct reports

Who You Might Be (Nice-to-Haves)

- Fintech, brokerage, or regulated financial services background

- Hands-on experience with Trino, Apache Ranger, dbt, Cube, Metabase, Airflow, or Iceberg

- Experience reviewing AI/ML and analytics tools

- Privacy program or vendor/DPA review experience

- CIPT, CIPM, CISM, CISSP, CDMP, CRISC, or similar certifications

- You've been the first governance hire at a growing company before

- Experience with Japan or EU data residency and cross-border data issues

- Exposure to ERM or operational risk

- Remote or distributed team experience

Apply for this role →

← Back to all jobs