
Cyber and AI Risk Analyst
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in United States.
• Assist in the implementation of Alpaca’s cybersecurity risk management initiatives.
• Execute cyber risk evaluations across cloud infrastructure, APIs, trading platforms, and internal systems.
• Aid in the identification, documentation, and assessment of AI-related risks, including model risk, data privacy, bias, explainability, adversarial threats, and model misuse.
• Contribute to the creation and maintenance of AI governance controls that align with evolving regulatory requirements, such as the EU AI Act.
• Conduct security and AI risk assessments for third-party vendors.
• Participate in control testing across various frameworks, including SOC 2, ISO 27001, CSA Star, NIST CSF, and emerging AI governance standards.
• Monitor remediation efforts while maintaining risk registers and reporting dashboards.
• Facilitate internal and external audits by organizing necessary documentation and evidence.
• Keep abreast of regulatory advancements related to cybersecurity, financial services, and AI governance.
• Assist in enhancing policies, standards, and procedures for both cybersecurity and AI domains.
• Support the creation of a systematic evaluation process for AI tools/models (intake → review → decision) applicable to both new and existing AI solutions.
• Aid in the establishment of Alpaca's AI usage guidelines and standards, ensuring the safe implementation of AI-enabled developer tools and assistants.
• Assist in maintaining standards for AI logging and monitoring (audit logging, evidence) pertaining to AI systems.
• Utilize AI tools in daily operations and assess the efficacy of AI-related controls.
• A minimum of 1 year of experience in cybersecurity, risk management, IT audit, GRC, or a related area; internships, coursework, or equivalent experience will be considered.
• Basic understanding of cybersecurity principles, including network security, cloud security, IAM, application security, and vulnerability management.
• Familiarity with prevalent frameworks such as NIST CSF, ISO 27001, SOC 2, or similar standards.
• Understanding of AI/ML concepts and relevant risks (data governance, model bias, hallucinations, prompt injection, model misuse, etc.); expertise is not required, but curiosity is essential.
• Excellent written communication and documentation abilities.
• Capability to evaluate technical risks and effectively communicate them to non-technical stakeholders.
• Experience in collaborating across functions with engineering and product teams.
• Highly organized with an acute attention to detail.
• Comfort in a fast-paced work environment.
• A genuine interest in AI with a strong eagerness to learn, actively experimenting with AI tools, and aspiring to enhance AI fluency as the field progresses.
• Comfort in utilizing AI tools regularly and a willingness to explore newer agentic/assistant-based technologies.
• Competitive salary and stock options.
• Comprehensive health benefits.
• New hire home-office setup: one-time USD $500.
• Monthly stipend of USD $150 via a Brex Card.
CVS Health
One Impression
Volga Partners
Mercor
Get handpicked remote jobs straight to your inbox weekly.