Back to Jobs
Alpaca
Data Science & Analytics 1d ago

Lead, Data Governance

Alpaca
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

SQLBestseller 🔥
Learn in 9 Hours
Data SecurityPrivacy EngineeringData GovernanceGRC

Want to know if you're a match for this job?

Calculate My Match Score

As Lead, Data Governance, you will help build and run Alpaca's data governance and data security program across our lakehouse, analytics tools, and internal data products. You'll set the standards for how we classify data, who can access it, and how we protect it, working closely with Data Engineering and Data Science to put those standards into practice.

Our data environment has grown quickly. We run several data solutions, and we handle more cross-region data every year across the US, Japan, EU, and other markets. We are also evaluating new analytics and AI tools on a regular basis. Access controls have not always kept pace, and we need someone who can help us catch up and stay ahead of partner and regulatory expectations.

The team is fully remote. This is an individual contributor role with no direct reports. You'll report to our Chief Information & Security Officer (CISO) and work closely with Data Engineering and Data Science through a dotted-line relationship.

Things You Get To Do

  • Build and maintain our data governance policies, classification standards, ownership model, and exception process, in line with Security and Privacy requirements
  • Own data access governance for the lakehouse and analytics stack, including entitlement standards, periodic access reviews, and least-privilege access across Trino, Ranger, Cube, Metabase, and related tools
  • Work with Data Engineering on the technical side of controls such as Ranger policies, schema restrictions, and service account management
  • Set data quality standards and help Data teams track and improve against them
  • Keep our data inventory, metadata, and lineage documentation current for compliance and audit purposes
  • Review data-related vendors and new use cases (analytics platforms, reverse ETL, AI query tools, notebooks, and similar) with Security, Privacy, and Legal
  • Support sensitive and cross-border data requests, including PII handling and regional data flows for Engineering, Operations, and New Markets
  • Prepare evidence for SOC 2, ISO 27001, CSA STAR, partner security reviews, and regulatory exams
  • Track data risks and control gaps as part of our Enterprise Risk Management (ERM) program
  • Be the go-to governance partner for Data and Security on access, classification, and tooling questions
  • Help define guardrails as we expand AI and agentic use of corporate data in analytics workflows

Who You Are (Must-Haves)

  • 5+ years in data governance, data security, GRC, privacy engineering, or a related field
  • At least 2 years working with modern data platforms (lakehouse/warehouse, SQL engines, BI, semantic layers)
  • Solid grasp of data governance frameworks (DAMA-DMBOK, NIST, or similar) and how to apply them in a company that moves quickly
  • You've built or run data classification, access control, or entitlement review programs, not just written the policies
  • Familiar with cloud data platforms (GCP a plus) and typical analytics tooling
  • Working knowledge of privacy and regulatory requirements in financial services (GDPR, CCPA, cross-border transfers, and similar)
  • Experience supporting SOC 2, ISO 27001, or similar audits
  • You work well with engineering teams and know how to push for good controls without becoming a bottleneck
  • Strong written and verbal communication skills
  • Organized, detail-oriented, and comfortable in a fast-paced remote environment
  • Comfortable as an IC with no direct reports

Who You Might Be (Nice-to-Haves)

  • Fintech, brokerage, or regulated financial services background
  • Hands-on experience with Trino, Apache Ranger, dbt, Cube, Metabase, Airflow, or Iceberg
  • Experience reviewing AI/ML and analytics tools
  • Privacy program or vendor/DPA review experience
  • CIPT, CIPM, CISM, CISSP, CDMP, CRISC, or similar certifications
  • You've been the first governance hire at a growing company before
  • Experience with Japan or EU data residency and cross-border data issues
  • Exposure to ERM or operational risk
  • Remote or distributed team experience

How would you rate this job post?

See what other professionals think about this role.

banner

Alpaca is a developer-first API brokerage platform and a fully registered, self-clearing US broker-dealer. Their mission is to open financial services to everyone on the planet. Instead of building a flashy consumer trading app like Robinhood, Alpaca built the underlying infrastructure. They offer powerful, modern APIs that allow algorithmic traders, hedge funds, and global FinTech startups to instantly build customizable investing applications. Whether a developer wants to write a Python script to automate their own stock trades, or an international startup wants to offer US stock investing to its users in Latin America or the Middle East, Alpaca provides the complete backend infrastructure to make it happen.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More