Cyber & AI Risk Analyst at Alpaca — Social Leverage

Socialleverage · Remote · First seen 3 weeks ago
Remote Mid level Cybersecurity
Apply on the employer's site

About this role

Jobs Companies Location All locations Remote On-site Job function Seniority All levels Internship Entry Level Associate Mid-Senior Senior Director Executive Salary Any salary $50k+ $75k+ $100k+ $150k+ $200k+ Industry Company stage All stages Seed Series A Series B Series C+ Other Company size All sizes 1-10 11-50 51-200 201-500 501-1000 1000+ 0 jobs Industry Company stage All stages Seed Series A Series B Series C+ Other Company size All sizes 1-10 11-50 51-200 201-500 501-1000 1000+ 0 companies Load more jobs Load more companies Careers / Alpaca API Careers / Alpaca / Cyber & AI Risk Analyst Cyber & AI Risk Analyst Posted 3 weeks ago Who We Are: Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts. Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it. Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator. Our Team Members: We're a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond! We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply. Your Role: As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca’s security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations. You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features. This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management. You’ll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk. We’re looking for someone curious, organized, and eager to grow. If you enjoy learning how technical systems work, translating risk into clear language, and building structured programs from the group up - then this role is for you. Prior GRC experience is a plus, but not required, we’re happy to invest in the right candidate. Things You Get To Do: Support the execution of Alpaca’s cybersecurity risk management program Conduct cyber risk assessments across cloud infrastructure , APIs, trading systems, and internal platforms Assist in identifying, documenting, and evaluating AI-related risks (model risk, data privacy, bias, explainability, adversarial threats, model misuse) Help develop and maintain AI governance controls aligned with evolving regulatory expectations such as the EU AI Act Perform third-party/vendor security and AI risk assessments Contribute to control testing across frameworks such as SOC 2, ISO 27001, CSA Star, NIST CSF, and emerging AI governance standards Track remediation efforts and maintain risk registers and reporting dashboards Support internal and external audits by preparing documentation and evidence Monitor regulatory developments related to cybersecurity, financial services, and AI governance Help mature policies, standards, and procedures for both cyber and AI domains Support the development of a repeatable AI tool/model evaluation process (intake → review → decision) for new and in-use AI tools Support Alpaca's AI usage guidance and standards, including safe use of AI-enabled developer tools and assistants Help maintain AI logging/monitoring standards (audit logging, evidence) for AI systems Use AI tools in day-to-day work and help test how well AI-related controls are working Who You Are (Must-Haves): 1+ years of experience in cybersecurity, risk management, IT audit, GRC, or a related field - internships, coursework, or equivalent experience is welcome Foundational understanding of cybersecurity principles (network security, cloud security, IAM, application security, vulnerability management) Familiarity with common frameworks such as NIST CSF, ISO 27001, SOC 2, or similar Understanding of AI/ML concepts and associated risks (data governance, model bias, hallucinations, prompt injection, model misuse, etc.) - you don’t need to be an expert, just curious Strong written communication and documentation skills Ability to assess technical risks and clearly communicate them to non-technical stakeholders Experience working cross-functionally with engineering and product teams Highly organized with strong attention to detail Comfort working in a fast-paced environment Genuine curiosity about AI and a strong desire to learn, actively experiments with AI tools, and wants to grow AI fluency as the field evolves Comfort using AI tools daily and willingness to learn newer agentic / assistant-based tooling Who You Might Be (Nice-to-Haves): Academic background, personal interest, or real world experience in fintech, financial services, or trading platforms Exposure to AI governance, model risk management, or responsible AI programs Familiarity with emerging AI regulatory frameworks (e.g., NIST AI RMF, EU AI Act concepts, model governance practices) Experience with GCP or other major cloud platforms Experience supporting or observing SOC 2, ISO 27001, or regulatory audits Security certifications (e.g., Security+, SSCP) or early-stage GRC certifications Interest in pursuing advanced certifications (CISA, CRISC, CISSP, or AI governance certifications) Experience working remotely or in distributed teams Hands-on experience with AI/agentic tooling (e.g., AI coding assistants, LLM apps, or similar) Personal projects or self-study in AI/ML that show initiative and interest How We Take Care of You: Competitive Salary & Stock Options Health Benefits New Hire Home-Office Setup: One-time USD $500 Monthly Stipend: USD $150 per month via a Brex Card Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

What this role is, and what else it is called

Employers in the UK advertise this kind of work as Security Engineer, Fire & Security Engineer, Cybersecurity Engineer and Cyber Security Consultant too, so it is worth searching more than one wording. It is a mid-level Cybersecurity role in the UK, advertised as fully remote, so it is open to candidates working from home.

About hiring at Socialleverage

Socialleverage has 7 other live technology roles on its careers page, across Software Engineering, DevOps, Platform & SRE and Cybersecurity. Of those, 100% are advertised as fully remote and 0% as hybrid. Elsewhere in its adverts Socialleverage asks for Kubernetes, Python, C++, Rust and Java. We have been observing Socialleverage hiring technology staff since May 2026. See all Socialleverage roles, salaries and stack.

How this role compares to the market

542 live UK roles list Google Cloud right now, from 224 employers. The median advertised salary is £90,000; 30% are advertised as remote. Browse Google Cloud roles.

233 live UK roles list Spark right now, from 68 employers. The median advertised salary is £40,000; 26% are advertised as remote. Browse Spark roles.

Market figures are today's snapshot of live UK roles on employer careers pages; see hiring trends.

Technologies mentioned

Detected on Socialleverage's careers page. ProdReady Recruitment lists this vacancy as an aggregator and is not the employer; applications go to the employer's own site.

Get these jobs by email

New matching UK IT roles, straight to your inbox. No spam -- unsubscribe any time.

We'll email you a confirmation link first -- nothing is sent until you click it.