Data Risk Engineer

Diagram

Richmond (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Stock options
Health benefits
Home-office setup
Monthly stipend

Job summary

Alpaca is seeking a Data Risk Engineer to implement and tune DLP across SaaS, email, endpoints, and collaboration tools. You will triage alerts, refine rules, and partner with People/HR, Legal, Compliance, Engineering, and IT on data mishandling.

Reporting to the Cyber GRC Lead, you will own DLP engineering and alert operations affecting customer data and trading systems, and you will grow into leading Insider Risk investigations end-to-end.

Qualifications

  • 3+ years in DLP, data protection, or adjacent security work with real alert volume.
  • Hands-on experience implementing and tuning DLP in SaaS and/or endpoint environments.
  • Solid understanding of data classification, PII handling, and common ways data leaves the company by accident.
  • Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk).
  • Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI).
  • Strong written communication; able to document alerts, coaching outreach, and case notes clearly.

Responsibilities

  • Implement, operate, and tune DLP across SaaS, email, endpoints, and collaboration tools.
  • Triage and work DLP alerts — determine what fired, why, whether it is real, and what to do next.
  • Handle false positives and tune rules so the same noise does not keep coming back.
  • Respond to user accidents and data mishandling: educate, correct course, and document what happened.
  • Engage employees who share PII or sensitive data in the wrong systems, and help them use approved paths.
  • Mature data classification and align DLP controls to sensitivity levels.
  • Build and improve detections and monitoring for data movement risk across Google, Slack, cloud, source code, and related systems.
  • Work with People/HR, Legal, Compliance, Engineering, and IT on data mishandling and related follow-up.
  • Partner with the Cyber GRC Lead on higher-severity Insider Risk and data loss cases, and grow into leading investigations from intake through closure.
  • Assess risk from unauthorized AI tooling and sensitive data exposure through approved and unsanctioned AI tools.
  • Support audits and regulatory asks tied to DLP and data handling.
  • Contribute data handling content to security awareness and training.
  • Stay current on DLP, data protection, privacy, and financial services expectations.

Skills

DLP
Data protection
SIEM
ELK
Splunk
Data classification
PII handling
Cross-functional collaboration
Regulatory compliance
Incident response

Tools

Cloud platforms
Python
SQL

Job description

Who We Are:

Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.
Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.
Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.
Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.
Our Team Members:

We're a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!
We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.

Your Role

As a Data Risk Engineer, you will implement and tune Alpaca's Data Loss Prevention (DLP) capabilities and handle day-to-day DLP alert response. You will triage signals across data movement, refine rulesets to improve signal quality, and partner with People/HR, Legal, Compliance, Engineering, and IT on data mishandling, including coaching users and correcting accidental misuse.

This role sits at the intersection of data protection, privacy, and financial services. Reporting to the Cyber GRC Lead, you will own DLP engineering and alert operations affecting customer data, proprietary information, and trading systems, while working alongside Security on higher-severity Insider Risk and data loss cases. This is a practical individual contributor role for someone experienced with DLP implementation, discreet when engaging employees, and eager to grow into leading Insider Risk investigations end-to-end. Prior experience in a regulated or financial services environment is a strong plus.

Things You Get To Do
  • Implement, operate, and tune DLP across SaaS, email, endpoints, and collaboration tools
  • Triage and work DLP alerts — determine what fired, why, whether it is real, and what to do next
  • Handle false positives and tune rules so the same noise does not keep coming back
  • Respond to user accidents and data mishandling: educate, correct course, and document what happened
  • Engage employees who share PII or sensitive data in the wrong systems, and help them use approved paths
  • Mature data classification and align DLP controls to sensitivity levels
  • Build and improve detections and monitoring for data movement risk across Google, Slack, cloud, source code, and related systems
  • Work with People/HR, Legal, Compliance, Engineering, and IT on data mishandling and related follow-up
  • Partner with the Cyber GRC Lead on higher-severity Insider Risk and data loss cases, and grow into leading investigations from intake through closure
  • Assess risk from unauthorized AI tooling and sensitive data exposure through approved and unsanctioned AI tools
  • Support audits and regulatory asks tied to DLP and data handling
  • Contribute data handling content to security awareness and training
  • Stay current on DLP, data protection, privacy, and financial services expectations
Who You Are (Must Haves)
  • Highly organized with strong attention to detail; comfortable in a fast-paced, high-demand, distributed environment
  • 3+ years in DLP, data protection, or adjacent security work with real alert volume
  • Hands-on experience implementing and tuning DLP in SaaS and/or endpoint environments
  • Comfortable triaging alerts, deciding severity, and knowing when to escape
  • Solid understanding of data classification, PII handling, and common ways data leaves the company by accident
  • Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk)
  • Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI)
  • Strong written communication; able to document alerts, coaching outreach, and case notes clearly
  • High integrity and discretion when handling confidential and sensitive information
  • Ability to work across People/HR, Legal, Compliance, Engineering, and IT
  • Interest in growing into Insider Risk investigation work
Who You Might Be (Nice to Haves)
  • Academic background, personal interest, or real-world experience in fintech, financial services, or trading platforms
  • Scripting or automation for detections and data analysis (e.g., Python, SQL)
  • Experience with major cloud platforms
  • Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
  • Certifications such as CISSP, CISM, CIPP, or similar
  • Interest in AI-related data risk and using automation to improve triage quality
  • Familiarity with financial services regulatory expectations (e.g., SEC/FINRA, broker-dealer controls) and multi-jurisdiction privacy requirements
  • Prior exposure to Insider Risk, investigations, or incident response
How We Take Care of You:
  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time USD $500
  • Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Recruitment Privacy Policy

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Insider & Data Risk Analyst
Sr. Insider & Data Risk Analyst

Social Leverage • Northern (KY)

On-site
USD 120,000 - 180,000
Stock options
New Hire Home-Office Setup
Monthly Stipend
Lead, Data Governance
Lead, Data Governance

Portage Ventures GP Inc. • United States

On-site
USD 140,000 - 180,000
Health benefits
Stock options
New hire home-office setup: USD 500
+1
Director of Data Platform
Director of Data Platform

Alpaca • New York (NY)

On-site
USD 150,000 - 200,000
Competitive Salary & Stock Options
Health Benefits
New Hire Home-Office Setup: One-time USD $500
+1
Director of Data Platform
Director of Data Platform

Drive Capital • United States

On-site
USD 230,000 - 320,000
Competitive Salary
Data Risk Engineer – DLP & Insider Risk
Data Risk Engineer – DLP & Insider Risk

Diagram • Richmond (VA)

On-site
USD 120,000 - 160,000
Stock options
Health benefits
Home-office setup
+1
Due Diligence Analyst
Due Diligence Analyst

Diagram • San Mateo (CA)

On-site
USD 110,000 - 140,000
Stock options
Health benefits
Home-office setup (one-time USD 500)
+1
Senior Data Scientist
Senior Data Scientist

Alpaca • New York (NY)

On-site
USD 80,000 - 110,000
Health Benefits
New Hire Home-Office Setup: One-time USD $500
Monthly Stipend: USD $150 per month
Financial Risk Manager
Financial Risk Manager

Alpaca • Northern (KY)

Hybrid
USD 140,000 - 180,000
Stock options
Home-office setup stipend
Staff Software Engineer - Margin & Risk
Staff Software Engineer - Margin & Risk

Alpaca • United States

On-site
USD 180,000 - 240,000
Stock options
Health benefits
One-time home-office setup
+1
Staff Analytics Engineer
Staff Analytics Engineer

SimplyHired • United States

Remote
USD 120,000 - 180,000
Health Benefits
New Hire Home-Office Setup: USD $500
Monthly Stipend: USD $150