Cyber & AI Risk Analyst
Job description
Cyber & AI Risk Analyst at Alpaca
About the role
Alpaca is seeking a Cyber & AI Risk Analyst to bolster our security and compliance efforts. This position will focus on identifying, assessing, and documenting risks related to both traditional cybersecurity and emerging AI technologies. You will contribute to building and maintaining our risk management framework, ensuring Alpaca remains secure and compliant.
Key facts
What you'll do
Support the ongoing cybersecurity risk management program.
Conduct risk assessments for cloud infrastructure, APIs, trading systems, and internal platforms.
Help identify, document, and evaluate risks associated with AI models and AI-driven features, including data privacy, bias, and misuse.
Contribute to the development of AI governance controls that align with regulatory expectations.
Perform security and AI risk assessments for third-party vendors.
Assist in control testing against frameworks like SOC 2, ISO 27001, and NIST CSF.
Track risk remediation efforts and maintain risk registers.
Support internal and external audits by providing necessary documentation.
Monitor regulatory changes in cybersecurity, financial services, and AI governance.
Help mature policies and procedures for cyber and AI risk domains.
Support the creation of a process for evaluating AI tools and models.
Assist in maintaining standards for AI system logging and monitoring.
Requirements
1+ years of experience in cybersecurity, risk management, IT audit, or GRC. Internships, coursework, or equivalent experience is acceptable.
A foundational understanding of cybersecurity principles, including cloud security, network security, and application security.
Familiarity with common frameworks such as NIST CSF, ISO 27001, or SOC 2.
An understanding of AI/ML concepts and associated risks like data governance, model bias, and prompt injection.
Strong written communication and documentation abilities.
The capacity to assess technical risks and explain them clearly to non-technical audiences.
Experience collaborating with engineering and product teams.
Highly organized with a keen eye for detail.
Comfortable working in a fast-paced environment.
A genuine curiosity for AI and a commitment to continuous learning in the field.
Comfort using AI tools daily and a willingness to learn new AI-powered tooling.
Nice to have
Experience in fintech, financial services, or trading platforms.
Exposure to AI governance, model risk management, or responsible AI programs.
Familiarity with AI regulatory frameworks such as the NIST AI RMF or EU AI Act.
Experience with GCP or other major cloud platforms.
Experience supporting audits for SOC 2 or ISO 27001.
Relevant security certifications like Security+ or SSCP.
Hands-on experience with AI/agentic tools.
Personal projects or self-study demonstrating initiative in AI/ML.
Skills & tools
Cybersecurity frameworks (NIST CSF, ISO 27001, SOC 2)
AI/ML concepts and risks
Cloud security (GCP preferred)
Risk assessment methodologies
Communication and documentation tools
AI tools and assistants
Practical notes
Alpaca offers competitive salary and stock options.
Health benefits are provided.
New hires receive a one-time USD $500 for home-office setup.
A monthly stipend of USD $150 is provided via a Brex Card.
Alpaca is an equal opportunity employer.
Please review the Recruitment Privacy Policy.