Cyber & AI Risk Analyst
Alpaca · New York, NY · 1 mo ago
RemoteRemoteFinance$400/hrFull-time
About the role
The Cyber & AI Risk Analyst plays a critical role in strengthening Alpaca's security, compliance, and AI risk posture across the organization. This role involves supporting the identification, assessment, and documentation of cybersecurity and AI-related risks, contributing to the design and execution of risk management frameworks, and collaborating with various teams to ensure resilience, compliance, and forward-looking risk management.
Responsibilities
- Support the execution of Alpaca's cybersecurity risk management program
- Conduct cyber risk assessments across cloud infrastructure, APIs, trading systems, and internal platforms
- Aid in identifying, documenting, and evaluating AI-related risks (model risk, data privacy, bias, explainability, adversarial threats, model misuse)
- Help develop and maintain AI governance controls aligned with evolving regulatory expectations such as the EU AI Act
- Perform third-party/vendor security and AI risk assessments
- Contribute to control testing across frameworks like SOC 2, ISO 27001, CSA Star, NIST CSF, and emerging AI governance standards
- Track remediation efforts and maintain risk registers and reporting dashboards
- Support internal and external audits by preparing documentation and evidence
- Monitor regulatory developments related to cybersecurity, financial services, and AI governance
- Mature policies, standards, and procedures for both cyber and AI domains
- Develop a repeatable AI tool/model evaluation process (intake → review → decision) for new and in-use AI tools
- Support Alpaca's AI usage guidance and standards, including safe use of AI-enabled developer tools and assistants
- Maintain AI logging/monitoring standards (audit logging, evidence) for AI systems
- Use AI tools in day-to-day work and help test how well AI-related controls are working
Requirements
- 1+ years of experience in cybersecurity, risk management, IT audit, GRC, or a related field
- Foundational understanding of cybersecurity principles (network security, cloud security, IAM, application security, vulnerability management)
- Familiarity with common frameworks such as NIST CSF, ISO 27001, SOC 2, or similar
- Understanding of AI/ML concepts and associated risks (data governance, model bias, hallucinations, prompt injection, model misuse, etc.)
- Strong written communication and documentation skills
- Ability to assess technical risks and clearly communicate them to non-technical stakeholders
- Experience working cross-functionally with engineering and product teams
- Highly organized with strong attention to detail
- Comfort working in a fast-paced environment
- Genuine curiosity about AI and a strong desire to learn, actively experimenting with AI tools, and wanting to grow AI fluency as the field evolves
- Willingness to use AI tools daily and learn newer agentic / assistant-based tooling
Qualifications
- Academic background, personal interest, or real-world experience in fintech, financial services, or trading platforms
- Exposure to AI governance, model risk management, or responsible AI programs
- Familiarity with emerging AI regulatory frameworks (e.g., NIST AI RMF, EU AI Act concepts, model governance practices)
- Experience with GCP or other major cloud platforms
- Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
- Security certifications (e.g., Security+, SSCP) or early-stage GRC certifications
- Interest in pursuing advanced certifications (CISA, CRISC, CISSP, or AI governance certifications)
- Experience working remotely or in distributed teams
- Hands-on experience with AI/agentic tooling (e.g., AI coding assistants, LLM apps, or similar)
- Personal projects or self-study in AI/ML that show initiative and interest
Benefits
- Competitive Salary & Stock Options
- Health Benefits
- New Hire Home-Office Setup: One-time USD $500
- Monthly Stipend: USD $150 per month via a Brex Card