Cyber & AI Risk Analyst
About the role
Your Role:
As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca’s security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations.
You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features.
This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management. You’ll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk.
We’re looking for someone curious, organized, and eager to grow. If you enjoy learning how technical systems work, translating risk into clear language, and building structured programs from the group up - then this role is for you. Prior GRC experience is a plus, but not required, we’re happy to invest in the right candidate.
Things You Get To Do:
- Support the execution of Alpaca’s cybersecurity risk management program
- Conduct cyber risk assessments across cloud infrastructure , APIs, trading systems, and internal platforms
- Assist in identifying, documenting, and evaluating AI-related risks (model risk, data privacy, bias, explainability, adversarial threats, model misuse)
- Help develop and maintain AI governance controls aligned with evolving regulatory expectations such as the EU AI Act
- Perform third-party/vendor security and AI risk assessments
- Contribute to control testing across frameworks such as SOC 2, ISO 27001, CSA Star, NIST CSF, and emerg