SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Alpaca is a US-headquartered global leader in agent-first brokerage infrastructure serving hundreds of financial institutions across 40 countries with institutional-grade APIs. The company operates as a licensed financial services provider supporting broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totaling over 10 million brokerage accounts.
As Lead, Data Governance, you will build and run Alpaca's data governance and data security program across the lakehouse, analytics tools, and internal data products. You'll establish standards for data classification, access control, and protection while working closely with Data Engineering and Data Science teams to implement these standards across a rapidly growing data environment.
Key responsibilities include:
- Building and maintaining data governance policies, classification standards, ownership models, and exception processes aligned with Security and Privacy requirements
- Owning data access governance for the lakehouse and analytics stack, including entitlement standards, periodic access reviews, and least-privilege access across tools like Trino, Ranger, Cube, and Metabase
- Collaborating with Data Engineering on technical controls such as Ranger policies, schema restrictions, and service account management
- Setting data quality standards and helping teams track improvements
- Maintaining current data inventory, metadata, and lineage documentation for compliance and audit purposes
- Reviewing data-related vendors and new use cases (analytics platforms, reverse ETL, AI query tools) with Security, Privacy, and Legal
- Supporting sensitive and cross-border data requests, including PII handling and regional data flows
- Preparing evidence for SOC 2, ISO 27001, CSA STAR, partner security reviews, and regulatory exams
- Tracking data risks and control gaps as part of Enterprise Risk Management
- Defining guardrails for AI and agentic use of corporate data in analytics workflows
This is a fully remote individual contributor role reporting to the Chief Information & Security Officer with dotted-line relationships to Data Engineering and Data Science teams. The role requires 5+ years in data governance, data security, GRC, or privacy engineering, plus 2+ years with modern data platforms. You should have hands-on experience building data classification, access control, and entitlement review programs, familiarity with cloud platforms (GCP preferred), and working knowledge of financial services privacy and regulatory requirements including GDPR, CCPA, and cross-border data transfers.