# Senior Insider & Data Risk Analyst

**Company:** [Alpaca](https://hotfix.jobs/companies/alpaca)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Data Loss Prevention, Insider Risk Management, Digital Forensics, Security Investigations, SIEM, Splunk, Elastic, Python, SQL, Soar, Data Classification, Data Governance, AWS, Azure, Nist Csf
**Posted:** 2026-08-13

> Owns insider-risk investigations and advances data-loss prevention capabilities across people, devices, identities, and data movement. The role requires 4+ years of security investigations or DLP experience, strong case-management judgment, and familiarity with governance frameworks and SIEM tooling.

## Job Description

## Responsibilities
- Own insider risk investigations from triage through closure, including case timelines, containment, escalation, documented determinations, and lessons learned.
- Mature the Insider Risk Management Program through case management processes, risk tiering, and repeatable workflows.
- Operate and tune Data Loss Prevention tooling across SaaS environments and endpoints, refining rulesets to improve signal quality and reduce false positives.
- Mature data classification and align DLP controls to sensitivity levels.
- Investigate potential data exfiltration, misuse, and policy violations; build and tune detections and monitoring.
- Investigate misuse and exfiltration risk across source code, Google, AWS, Azure, third-party applications, Slack, and trading and platform system access.
- Partner with People/HR, Legal, Compliance, and IT on sensitive cases involving departures, policy violations, and data mishandling.
- Assess risk from unauthorized AI or agentic tooling and sensitive-data exposure through approved and unsanctioned AI tools.
- Use agentic AI to mature the insider risk program.
- Lead insider and data risk assessments and maintain risk registers.
- Support internal and external audits and regulatory requirements.
- Contribute insider risk and data-handling content to security awareness and training programs.
- Serve as the Security team's insider risk escalation point and mentor others on investigations and casework.
- Monitor developments in insider risk, data protection, privacy, and financial-services regulation.

## Requirements
- 4+ years of experience in insider risk, DLP operations, digital forensics, or security investigations, including hands-on case management involving sensitive personnel matters.
- Experience leading investigations and case management with discretion, integrity, and sound judgment.
- Hands-on experience operating DLP in SaaS and endpoint environments and tuning rules to improve signal quality.
- Experience with workflow automation, AI, or SOAR platforms for alert triage and case orchestration.
- Solid understanding of data classification and data governance.
- Working knowledge of SIEM and log analysis, such as ELK/Elastic or Splunk.
- Familiarity with NIST CSF, ISO 27001, SOC 2, GDPR, and APPI.
- Strong written communication skills, including investigation reports, case documentation, and executive summaries.
- High integrity and discretion when handling confidential and sensitive information.
- Ability to work across People/HR, Legal, Compliance, Engineering, and IT.

## Nice-to-Haves
- Academic, personal, or professional experience in fintech, financial services, or trading platforms.
- Digital forensics or eDiscovery experience.
- Experience with UEBA or insider risk detection platforms.
- Scripting or automation for detections and data analysis, such as Python or SQL.
- Experience with major cloud platforms.
- Experience supporting or observing SOC 2, ISO 27001, or regulatory audits.
- Certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or similar.
- Interest in AI-related data risk and using AI tools to work more efficiently.
- Familiarity with SEC/FINRA expectations, broker-dealer controls, and multi-jurisdiction privacy requirements.
- Experience in security operations or incident response.

## Compensation and Benefits
- Competitive salary and stock options.
- Health benefits.
- One-time **$500** new-hire home-office setup benefit.
- **$150 per month** stipend via a Brex Card.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/8113b68c-6854-4c18-836b-5075ae3f3af4
**Canonical:** https://hotfix.jobs/jobs/8113b68c-6854-4c18-836b-5075ae3f3af4