Lead, Data Governance
Job description
.
About the role
You will architect and operationalize data governance and data security practices for Alpaca's expanding data estate. This role defines how data is classified, accessed, and protected across our lakehouse, analytics platforms, and internal data products. You will establish standards that balance security with analytical agility, enabling trusted data use across the organization. You will partner closely with Data Engineering and Data Science to embed governance into day-to-day workflows. Your work will directly support compliance readiness and the responsible use of data and AI across markets. This is an individual contributor role with no direct reports, reporting to the Chief Information & Security Officer. You will influence cross-functional teams to adopt durable data governance practices as we evaluate new analytics and AI tooling.
Key facts
What you'll do
Define and maintain data governance policies, data classification standards, data ownership models, and exception handling processes aligned with security and privacy requirements.
Own data access governance for the lakehouse and analytics stack, including entitlement standards, periodic access reviews, and enforcement of least-privilege access across Trino, Ranger, Cube, Metabase, and related analytics tools.
Collaborate with Data Engineering on the implementation of technical controls such as Ranger policies, schema restrictions, and service account management to enforce governance at scale.
Establish data quality standards and work with data teams to track, measure, and continuously improve data quality across pipelines and analytics outputs.
Maintain current data inventory, metadata repositories, and lineage documentation to support compliance, audit, and regulatory reporting needs.
Review data-related vendors and new use cases, including analytics platforms, reverse ETL pipelines, AI query tools, notebooks, and similar technologies, in coordination with Security, Privacy, and Legal.
Support sensitive and cross-border data requests, including proper handling of PII and oversight of regional data flows for Engineering, Operations, and New Markets teams.
Prepare evidence and artifacts for SOC 2, ISO 27001, CSA STAR, partner security reviews, and regulatory examinations related to data governance and access controls.
Track data risks and control gaps within the Enterprise Risk Management (ERM) program, ensuring appropriate mitigation plans and ownership.
Act as the primary governance partner for Data and Security teams, providing guidance on access, classification, and tooling decisions.
Define guardrails and operational practices as Alpaca expands the use of AI and agentic workflows involving corporate data in analytics and decision-making processes.
Partner with Security, Privacy, Legal, and Data teams to align data governance practices with evolving regulatory expectations and business needs.
Champion transparency and accountability in data usage by driving clear documentation and communication of policies and exceptions.
Promote continuous improvement by monitoring emerging tools and frameworks, and advocating for governance practices that scale with product and market demands.
Requirements
Demonstrated experience building and implementing data governance, data security, and data privacy programs in complex, multi-region environments.
Strong knowledge of data classification frameworks, access control models, and data protection regulations relevant to financial services and global data flows.
Experience managing data access at scale in cloud data platforms, including work with tools such as Trino, Ranger, Cube, and Metabase.
Solid understanding of security and compliance frameworks relevant to financial services, such as SOC 2, ISO 27001, and CSA STAR.
Proven ability to collaborate with technical teams including Data Engineering and Data Science to translate governance requirements into technical controls.
Excellent judgment and discretion when handling sensitive, confidential, and regulated data across jurisdictions.
Strong written and verbal communication skills to articulate policies, trade-offs, and risks to both technical and non-technical stakeholders.
Self-driven orientation with the ability to manage priorities in a fast-paced, distributed, and rapidly evolving startup environment.
Nice to have
Experience in regulated financial services environments where data governance and audit readiness are critical.
Familiarity with AI and analytics tooling ecosystems, and experience defining guardrails for secure and compliant use of these tools.
Background in cross-border data transfer mechanisms and regional data residency requirements.
Practical notes
The team is fully remote. This is an individual contributor role with no direct reports. You will report to our Chief Information & Security Officer and work closely with Data Engineering and Data Science through a dotted-line relationship.