
Senior Insider & Data Risk Analyst
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in Europe.
• Take ownership of insider risk investigations from initiation to conclusion, which includes managing case timelines, containment efforts, escalation protocols, documented findings, and lessons learned.
• Enhance Alpaca's Insider Risk Management Program by refining case management processes, implementing risk tiering, and establishing repeatable workflows.
• Operate and optimize Data Loss Prevention tools across various environments and endpoints, focusing on improving signal quality and minimizing false positive rates.
• Advance data classification initiatives and align DLP controls with data sensitivity levels.
• Investigate incidents of data exfiltration, misuse, and policy breaches; develop and refine detection mechanisms and monitoring strategies.
• Examine risks associated with misuse and exfiltration across source code, Google, AWS, Azure, third-party applications, Slack, and access to trading and platform systems.
• Collaborate with People/HR, Legal, Compliance, Engineering, and IT departments on sensitive case matters.
• Evaluate risks stemming from unauthorized AI/agentic tools and exposure of sensitive data.
• Utilize Agentic AI to further develop the Insider Risk program.
• Lead assessments of insider and data risks while maintaining risk registers.
• Support both internal and external audits as well as regulatory compliance requirements.
• Contribute to security awareness and training materials related to insider risk and data handling.
• Act as the escalation point for insider risk issues within the Security team and mentor colleagues in investigations and case management.
• Keep abreast of developments in insider risk, data protection, privacy, and financial services regulations.
• Minimum of 4 years of experience in insider risk, DLP operations, digital forensics, or security investigations, including hands-on case management in sensitive personnel matters.
• Proven experience leading investigations and managing cases with discretion, integrity, and sound judgment.
• Practical experience operating DLP in SaaS and endpoint environments, along with the ability to fine-tune rules.
• Familiarity with workflow automation, AI, or SOAR platforms for alert triage and case orchestration.
• Strong understanding of data classification and governance principles.
• Working knowledge of SIEM and log analysis tools, such as ELK/Elastic or Splunk.
• Understanding of regulatory frameworks like NIST CSF, ISO 27001, SOC 2, GDPR, and APPI.
• Excellent written communication skills for creating investigation reports, case documentation, and executive summaries.
• High level of integrity and discretion when handling confidential information.
• Ability to work collaboratively with People/HR, Legal, Compliance, Engineering, and IT teams.
• Preferred: Experience in digital forensics or eDiscovery.
• Preferred: Knowledge of UEBA or insider risk detection platforms.
• Preferred: Skills in scripting or automation for detection and data analysis, such as Python or SQL.
• Preferred: Familiarity with major cloud platforms.
• Preferred: Experience with SOC 2, ISO 27001, or regulatory audits.
• Preferred: Relevant certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or similar.
• Preferred: Understanding of SEC/FINRA regulations, broker-dealer controls, and multi-jurisdiction privacy requirements.
• Preferred: Experience in security operations or incident response.
• Competitive Salary & Stock Options
• Health Benefits
• New Hire Home-Office Setup: One-time USD $500
• Monthly Stipend: USD $150 per month via a Brex Card
Circana
Zero Hash
World Kinect
The Hartford
Get handpicked remote jobs straight to your inbox weekly.