Sr. Insider Risk Analyst

Alpaca

United States

Remote

USD 140,000 - 190,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Alpaca, a leading fintech company, is seeking a Senior Insider & Data Risk Analyst to own investigations and mature Insider Risk Management and Data Loss Prevention capabilities across people, devices, identity, and data movement.

Reporting to the Cyber GRC Lead, you will triage signals, define risk tiers, collaborate with Legal, Compliance, Engineering and IT, and develop durable workflows, detection rules, and program governance.

Qualifications

  • 4+ years in insider risk, DLP operations, digital forensics, or security investigations.
  • Hands-on investigation experience with sensitive personnel matters.
  • Experience with workflow automation, AI, or SOAR platforms for alert triage and case orchestration.

Responsibilities

  • Own insider risk investigations from triage through closure with timelines and determinations.
  • Mature Insider Risk Management Program and case management processes.
  • Operate and tune DLP tooling across environments to improve signal quality.

Skills

Insider risk
DLP operations
Digital forensics
Case management
SIEM
Workflow automation
SOAR platforms
Data classification
Data governance
Executive communication
Cross-functional collaboration
AI tooling
Cloud platforms

Tools

ELK
Splunk

Job description

Your Role

As Senior Insider & Data Risk Analyst, you will own insider risk investigations and help mature Alpaca's Insider Risk Management Program and Data Loss Prevention capabilities. You will triage and investigate signals across people, devices, identity, and data movement, apply risk tiering and escalation standards, and partner with People/HR, Legal, Compliance, Engineering, and IT on sensitive cases involving departures, policy violations, and data misuse.

This role sits at the intersection of insider risk, data protection, privacy, and financial services. Reporting to the Cyber GRC Lead, you will serve as Security's escalation point for insider and data loss cases affecting trading systems, customer data, and proprietary information. This is a practical senior individual contributor role for someone experienced, discreet, and highly organized who can own investigation workflows, translate risk into clear language for leadership, and build durable programs and processes. Prior experience in a regulated or financial services environment is a strong plus.

Things You Get To Do
  • Own insider risk investigations from triage through closure, including case timelines, containment, escalation, and documented determinations and lessons learned
  • Mature Alpaca's Insider Risk Management Program, including case management processes, risk tiering, and repeatable workflows
  • Operate and tune Data Loss Prevention tooling across multiple environments and endpoints, refining rulesets to improve signal and reduce false positives
  • Mature data classification and align DLP controls to sensitivity levels
  • Investigate potential data exfiltration, misuse, and policy violations; build and tune detections and monitoring
  • Investigate misuse and exfiltration risk across source code, Google, AWS, Azure, third party apps, Slack, and trading and platform system access
  • Partner with People/HR, Legal, Compliance, and IT on sensitive cases (departures, policy violations, data mishandling) with discretion and care
  • Assess risk from unauthorized AI/agentic tooling and sensitive data exposure through approved and unsanctioned AI tooling
  • Leverage Agentic AI to continue maturation of Insider risk program
  • Lead insider and data risk assessments and maintain risk registers
  • Support internal and external audits and regulatory requirements
  • Contribute insider risk and data handling content to the security awareness and training program
  • Serve as the insider risk escalation point for the Security team and mentor others on investigations and casework
  • Monitor developments in insider risk, data protection, privacy, and financial services regulation.
Who You Are (Must Haves)
  • Highly organized with strong attention to detail; comfortable in a fast paced, high demand, distributed environment
  • 4+ years in insider risk, DLP operations, digital forensics, or security investigations, including hands on case management on sensitive personnel matters
  • Hands on experience leading investigations and case management with discretion, integrity, and sound judgment on sensitive personnel matters
  • Hands-on experience operating DLP in SaaS and endpoint environments and tuning rules to improve signal quality
  • Experience with workflow automation, AI, or SOAR platforms for alert triage and case orchestration
  • Solid understanding of data classification and data governance
  • Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk) to support investigations
  • Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 2, and privacy regulations (GDPR, APPI)
  • Strong written communication, able to draft clear investigation reports, case documentation, and executive summaries
  • High integrity and discretion when handling confidential and sensitive information
  • Ability to work across People/HR, Legal, Compliance, Engineering, and IT
Who You Might Be (Nice to Haves)
  • Academic background, personal interest, or real world experience in fintech, financial services, or trading platforms
  • Digital forensics or eDiscovery experience
  • Experience with UEBA or insider risk detection platforms
  • Scripting or automation for detections and data analysis (e.g., Python, SQL)
  • Experience with major cloud platforms
  • Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
  • Certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or similar
  • Interest in AI related data risk (e.g., data exposure through AI tools) and using AI tooling to work more efficiently
  • Familiarity with financial services regulatory expectations (e.g., SEC/FINRA, broker dealer controls) and multi jurisdiction privacy requirements
  • Experience in security operations or incident response
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Insider & Data Risk Analyst
Sr. Insider & Data Risk Analyst

Social Leverage • Northern (KY)

On-site
USD 120,000 - 180,000
Stock options
New Hire Home-Office Setup
Monthly Stipend
Remote Senior Insider Risk & Data Protection Analyst
Remote Senior Insider Risk & Data Protection Analyst

Social Leverage • Northern (KY)

Hybrid
USD 120,000 - 180,000
Stock options
New Hire Home-Office Setup
Monthly Stipend
Data Risk Engineer
Data Risk Engineer

Diagram • Richmond (VA)

On-site
USD 120,000 - 160,000
Stock options
Health benefits
Home-office setup
+1
Senior Insider Risk & Data Protection Analyst
Senior Insider Risk & Data Protection Analyst

Alpaca • United States

Remote
USD 140,000 - 190,000
Senior Data Security Engineer
Senior Data Security Engineer

I.T. Solutions, Inc. • United States

On-site
USD 160,000 - 220,000
Sr. Manager, Insider Risk & Digital Forensics
Sr. Manager, Insider Risk & Digital Forensics

Huntington • Atlanta (TX)

On-site
USD 140,000 - 190,000
Data Scientist Insider Risk Analytics
Data Scientist Insider Risk Analytics

Zohorecruit • Jersey City (NJ)

Hybrid
USD 120,000 - 170,000
Risk & Cyber Analytics.
Risk & Cyber Analytics.

Recurring Decimal • New Jersey

On-site
USD 90,000 - 130,000
Insider Risk Sr Analyst
Insider Risk Sr Analyst

Texas Capital Bank • Richardson (TX)

On-site
USD 120,000 - 160,000
Health benefits
Insider Risk Analyst (Remote, GBR)
Insider Risk Analyst (Remote, GBR)

CrowdStrike • United States

On-site
GBP 60,000 - 90,000
Market-leading compensation
Wellness programs
Generous vacation
+2