Sr. Insider & Data Risk Analyst

Alpaca · Remote - EMEA · Data

Posted 2026-08-07

Apply for this role →

Your Role

As Senior Insider & Data Risk Analyst, you will own insider risk investigations and help mature Alpaca's Insider Risk Management Program and Data Loss Prevention capabilities. You will triage and investigate signals across people, devices, identity, and data movement, apply risk tiering and escalation standards, and partner with People/HR, Legal, Compliance, Engineering, and IT on sensitive cases involving departures, policy violations, and data misuse.

This role sits at the intersection of insider risk, data protection, privacy, and financial services. Reporting to the Cyber GRC Lead, you will serve as Security's escalation point for insider and data loss cases affecting trading systems, customer data, and proprietary information. This is a practical senior individual contributor role for someone experienced, discreet, and highly organized who can own investigation workflows, translate risk into clear language for leadership, and build durable programs and processes. Prior experience in a regulated or financial services environment is a strong plus.

Things You Get To Do

Own insider risk investigations from triage through closure, including case timelines, containment, escalation, and documented determinations and lessons learned

Mature Alpaca's Insider Risk Management Program, including case management processes, risk tiering, and repeatable workflows

Operate and tune Data Loss Prevention tooling across multiple environments and endpoints, refining rulesets to improve signal and reduce false positives

Mature data classification and align DLP controls to sensitivity levels

Investigate potential data exfiltration, misuse, and policy violations; build and tune detections and monitoring

Investigate misuse and exfiltration risk across source code, Google, AWS, Azure, third party apps, Slack, and trading and platform system access

Partner with People/HR, Legal, Compliance, and IT on sensitive cases (departures, policy violations, data mishandling) with discretion and care

Assess risk from unauthorized AI/agentic tooling and sensitive data exposure through approved and unsanctioned AI tooling

Leverage Agentic AI to continue maturation of Insider risk program

Lead insider and data risk assessments and maintain risk registers

Support internal and external audits and regulatory requirements

Contribute insider risk and data handling content to the security awareness and training program

Serve as the insider risk escalation point for the Security team and mentor others on investigations and casework

Monitor developments in insider risk, data protection, privacy, and financial services regulation.

Who You Are (Must Haves)

Highly organized with strong attention to detail; comfortable in a fast paced, high demand, distributed environment

4+ years in insider risk, DLP operations, digital forensics, or security investigations, including hands on case management on sensitive personnel matters

Hands on experience leading investigations and case management with discretion, integrity, and sound judgment on sensitive personnel matters

Hands-on experience operating DLP in SaaS and endpoint environments and tuning rules to improve signal quality

Experience with workflow automation, AI, or SOAR platforms for alert triage and case orchestration

Solid understanding of data classification and data governance

Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk) to support investigations

Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI)

Strong written communication, able to draft clear investigation reports, case documentation, and executive summaries

High integrity and discretion when handling confidential and sensitive information

Ability to work across People/HR, Legal, Compliance, Engineering, and IT

Who You Might Be (Nice to Haves)

Academic background, personal interest, or real world experience in fintech, financial services, or trading platforms

Digital forensics or eDiscovery experience

Experience with UEBA or insider risk detection platforms

Scripting or automation for detections and data analysis (e.g., Python, SQL)

Experience with major cloud platforms

Experience supporting or observing SOC 2, ISO 27001, or regulatory audits

Certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or similar

Interest in AI related data risk (e.g., data exposure through AI tools) and using AI tooling to work more efficiently

Familiarity with financial services regulatory expectations (e.g., SEC/FINRA, broker dealer controls) and multi jurisdiction privacy requirements

Experience in security operations or incident response

Apply for this role →

← Back to all jobs