{"schemaVersion":"jobsearcher.job.v1","id":"e4199ec8bfab0ef3e8d30f38","url":"https://jobsearcher.com/jobs/e4199ec8bfab0ef3e8d30f38","canonicalUrl":"https://jobsearcher.com/jobs/e4199ec8bfab0ef3e8d30f38","title":"Security GRC Analyst","description":"Who We Are\r\nAlpaca is a US California headquartered brokerage infrastructure technology company and self-clearing broker-dealer, delivering execution and custody solutions for Stocks, ETFs, Options, Cryptocurrencies, and more. We have raised over $170 million in funding. With subsidiaries licensed in multiple countries, we serve hundreds of financial institutions worldwide such as broker-dealers, investment advisors, hedge funds, and crypto exchanges. Our globally distributed team includes engineers, traders, and brokerage professionals who share the mission of opening financial services to everyone on the planet. We are also deeply committed to open-source contributions and fostering a vibrant community. We will continue to enhance our award-winning developer-friendly API and the infrastructure behind it.\r\nYour Role\r\nWe are seeking an experienced Security Governance, Risk, and Compliance (GRC) Analyst to expand our security efforts and safeguard Alpaca's systems, data, and client assets. The role includes assessing risks, monitoring compliance, and collaborating with internal and external stakeholders to uphold security policies, regulations, and best practices. The analyst will report directly to the CISO.\r\nKey Responsibilities\r\nAssist the CISO with developing and maintaining a comprehensive security program, including policies and procedures to comply with relevant regulations and standards.\r\nEnsure compliance with SOC 2 Type 2, ISO 27001, CSA-Star, GDPR, and external regulatory requirements.\r\nConduct regular risk assessments, gap analyses, and develop risk-treatment plans.\r\nApply statistical models to risk frameworks, translating risk into quantifiable metrics (e.g., FAIR).\r\nCollaborate with the CISO to provide strategic guidance on security matters and respond to emerging risks.\r\nManage and maintain an up-to-date security control framework.\r\nFacilitate periodic user-access reviews.\r\nManage and coordinate internal and external audits, including preparation of audit responses and corrective-action plans.\r\nCollaborate with other departments to mitigate security risks and collect evidence as needed.\r\nManage supply-chain security risks by performing regular assessments of third parties.\r\nProvide training and awareness to employees on cybersecurity policies and compliance requirements.\r\nAssist the security team with triaging security events.\r\nMust-Haves\r\nAt least 3 years of experience in risk management and compliance functions.\r\nStrong knowledge of SOC 2, ISO 27001, CSA, NIST, GDPR, CCPA, FINRA, and SEC cybersecurity guidelines.\r\nExperience with risk assessments, gap analyses, and risk-treatment planning.\r\nStrong familiarity with cloud service providers.\r\nExperience with audit preparation, response, and corrective-action plan development.\r\nExcellent communication and interpersonal skills, with the ability to engage stakeholders and advocate issues strategically.\r\nAvailability for on-call rotations and after-hour responses as needed.\r\nNice-to-Haves\r\nBachelor's degree in Information Technology or a related field.\r\nSecurity certifications such as CISSP, CRISC, or GIAC.\r\nUnderstanding of financial and privacy regulations.\r\nExperience in financial services.\r\nExperience working at startups.\r\nBusiness acumen to balance trade-offs between stakeholders, technology feasibility, and budget constraints.\r\nBenefits\r\nCompetitive salary and stock options.\r\nHealth benefits start on day 1: Medical, Dental, Vision (US); supplemental health care (Canada); local benefits (Japan); and an international stipend to offset medical costs.\r\nOne-time $500 USD home-office setup.\r\nMonthly $150 USD stipend via Brex Card.\r\nEqual Opportunity Statement\r\nAlpaca is proud to be an equal-opportunity workplace dedicated to pursuing and hiring a diverse workforce.\r\nJ-18808-Ljbffr","company":"Framework Ventures","rawCompany":"framework ventures","city":"Fountain","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-08T01:14:46.204Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"523940","title":"Portfolio Management and Investment Advice","slug":"portfolio-management-and-investment-advice"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security GRC Analyst","description":"Who We Are\r\nAlpaca is a US California headquartered brokerage infrastructure technology company and self-clearing broker-dealer, delivering execution and custody solutions for Stocks, ETFs, Options, Cryptocurrencies, and more. We have raised over $170 million in funding. With subsidiaries licensed in multiple countries, we serve hundreds of financial institutions worldwide such as broker-dealers, investment advisors, hedge funds, and crypto exchanges. Our globally distributed team includes engineers, traders, and brokerage professionals who share the mission of opening financial services to everyone on the planet. We are also deeply committed to open-source contributions and fostering a vibrant community. We will continue to enhance our award-winning developer-friendly API and the infrastructure behind it.\r\nYour Role\r\nWe are seeking an experienced Security Governance, Risk, and Compliance (GRC) Analyst to expand our security efforts and safeguard Alpaca's systems, data, and client assets. The role includes assessing risks, monitoring compliance, and collaborating with internal and external stakeholders to uphold security policies, regulations, and best practices. The analyst will report directly to the CISO.\r\nKey Responsibilities\r\nAssist the CISO with developing and maintaining a comprehensive security program, including policies and procedures to comply with relevant regulations and standards.\r\nEnsure compliance with SOC 2 Type 2, ISO 27001, CSA-Star, GDPR, and external regulatory requirements.\r\nConduct regular risk assessments, gap analyses, and develop risk-treatment plans.\r\nApply statistical models to risk frameworks, translating risk into quantifiable metrics (e.g., FAIR).\r\nCollaborate with the CISO to provide strategic guidance on security matters and respond to emerging risks.\r\nManage and maintain an up-to-date security control framework.\r\nFacilitate periodic user-access reviews.\r\nManage and coordinate internal and external audits, including preparation of audit responses and corrective-action plans.\r\nCollaborate with other departments to mitigate security risks and collect evidence as needed.\r\nManage supply-chain security risks by performing regular assessments of third parties.\r\nProvide training and awareness to employees on cybersecurity policies and compliance requirements.\r\nAssist the security team with triaging security events.\r\nMust-Haves\r\nAt least 3 years of experience in risk management and compliance functions.\r\nStrong knowledge of SOC 2, ISO 27001, CSA, NIST, GDPR, CCPA, FINRA, and SEC cybersecurity guidelines.\r\nExperience with risk assessments, gap analyses, and risk-treatment planning.\r\nStrong familiarity with cloud service providers.\r\nExperience with audit preparation, response, and corrective-action plan development.\r\nExcellent communication and interpersonal skills, with the ability to engage stakeholders and advocate issues strategically.\r\nAvailability for on-call rotations and after-hour responses as needed.\r\nNice-to-Haves\r\nBachelor's degree in Information Technology or a related field.\r\nSecurity certifications such as CISSP, CRISC, or GIAC.\r\nUnderstanding of financial and privacy regulations.\r\nExperience in financial services.\r\nExperience working at startups.\r\nBusiness acumen to balance trade-offs between stakeholders, technology feasibility, and budget constraints.\r\nBenefits\r\nCompetitive salary and stock options.\r\nHealth benefits start on day 1: Medical, Dental, Vision (US); supplemental health care (Canada); local benefits (Japan); and an international stipend to offset medical costs.\r\nOne-time $500 USD home-office setup.\r\nMonthly $150 USD stipend via Brex Card.\r\nEqual Opportunity Statement\r\nAlpaca is proud to be an equal-opportunity workplace dedicated to pursuing and hiring a diverse workforce.\r\nJ-18808-Ljbffr","datePosted":"2026-08-08T01:14:46.204Z","dateModified":"2026-08-08T01:14:46.204Z","hiringOrganization":{"@type":"Organization","name":"Framework Ventures","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Fountain","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"e4199ec8bfab0ef3e8d30f38"},"url":"https://jobsearcher.com/jobs/e4199ec8bfab0ef3e8d30f38"}}