Lead, Data Governance
Central America · North America · South America · Remote
Who We Are:
Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.
Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.
Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.
Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.
Our Team Members:
We're a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!
We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.
Your Role:
As Lead, Data Governance, you will help build and run Alpaca's data governance and data security program across our lakehouse, analytics tools, and internal data products. You'll set the standards for how we classify data, who can access it, and how we protect it, working closely with Data Engineering and Data Science to put those standards into practice.
Our data environment has grown quickly. We run several data solutions, and we handle more cross-region data every year across the US, Japan, EU, and other markets. We are also evaluating new analytics and AI tools on a regular basis. Access controls have not always kept pace, and we need someone who can help us catch up and stay ahead of partner and regulatory expectations.
The team is fully remote. This is an individual contributor role with no direct reports. You'll report to our Chief Information & Security Officer (CISO) and work closely with Data Engineering and Data Science through a dotted-line relationship.
Things You Get To Do
- Build and maintain our data governance policies, classification standards, ownership model, and exception process, in line with Security and Privacy requirements
- Own data access governance for the lakehouse and analytics stack, including entitlement standards, periodic access reviews, and least-privilege access across Trino, Ranger, Cube, Metabase, and related tools
- Work with Data Engineering on the technical side of controls such as Ranger policies, schema restrictions, and service account management
- Set data quality standards and help Data teams track and improve against them
- Keep our data inventory, metadata, and lineage documentation current for compliance and audit purposes
- Review data-related vendors and new use cases (analytics platforms, reverse ETL, AI query tools, notebooks, and similar) with Security, Privacy, and Legal
- Support sensitive and cross-border data requests, including PII handling and regional data flows for Engineering, Operations, and New Markets
- Prepare evidence for SOC 2, ISO 27001, CSA STAR, partner security reviews, and regulatory exams
- Track data risks and control gaps as part of our Enterprise Risk Management (ERM) program
- Be the go-to governance partner for Data and Security on access, classification, and tooling questions
- Help define guardrails as we expand AI and agentic use of corporate data in analytics workflows
Who You Are (Must-Haves)
- 5+ years in data governance, data security, GRC, privacy engineering, or a related field
- At least 2 years working with modern data platforms (lakehouse/warehouse, SQL engines, BI, semantic layers)
- Solid grasp of data governance frameworks (DAMA-DMBOK, NIST, or similar) and how to apply them in a company that moves quickly
- You've built or run data classification, access control, or entitlement review programs, not just written the policies
- Familiar with cloud data platforms (GCP a plus) and typical analytics tooling
- Working knowledge of privacy and regulatory requirements in financial services (GDPR, CCPA, cross-border transfers, and similar)
- Experience supporting SOC 2, ISO 27001, or similar audits
- You work well with engineering teams and know how to push for good controls without becoming a bottleneck
- Strong written and verbal communication skills
- Organized, detail-oriented, and comfortable in a fast-paced remote environment
- Comfortable as an IC with no direct reports
Who You Might Be (Nice-to-Haves)
- Fintech, brokerage, or regulated financial services background
- Hands-on experience with Trino, Apache Ranger, dbt, Cube, Metabase, Airflow, or Iceberg
- Experience reviewing AI/ML and analytics tools
- Privacy program or vendor/DPA review experience
- CIPT, CIPM, CISM, CISSP, CDMP, CRISC, or similar certifications
- You've been the first governance hire at a growing company before
- Experience with Japan or EU data residency and cross-border data issues
- Exposure to ERM or operational risk
- Remote or distributed team experience
How We Take Care of You:
- Competitive Salary & Stock Options
- Health Benefits
- New Hire Home-Office Setup: One-time USD $500
- Monthly Stipend: USD $150 per month via a Brex Card
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.