Alpaca
Product Security Engineer
Job Summary
The role involves safeguarding Alpaca’s products and infrastructure by embedding security best practices into development processes, identifying and remediating vulnerabilities, and responding to security incidents. Candidates should have 6-8 years of experience in security operations, engineering, or DevSecOps, with proficiency in programming and cloud security, especially in Google Cloud and Kubernetes. The position emphasizes collaboration across teams, proactive threat detection, and promoting security awareness. It offers a remote, distributed work environment with comprehensive benefits, including health coverage and stock options.
Required Skills
Benefits
Job Description
Your Role:
We are seeking an experienced Product Security Engineer who can help expand our Security efforts and play a critical role in safeguarding Alpaca’s assets from evolving cyber threats to ensure the security and integrity of our products.
In this role, you will play a key part in ensuring the security of Alpaca’s products and infrastructure, protecting our APIs, trading platforms, and customer data from threats. You’ll collaborate closely with our engineering, product, and operations teams to embed security best practices into our development lifecycle, harden our systems, and respond to emerging threats. If you’re excited about security, cutting edge financial tech, and thrive in a fast-paced environment, we’d love to hear from you.
The role requires a deep understanding of Cybersecurity principles, application security, DevSecOps, incident response, cloud security, offensive security, and proactive threat detection with a proven track record of managing security risks and cross functional collaboration. The Security Team is 100% distributed and remote. This role will be reporting directly to the CISO.
Things You Get To Do:
- Collaborate with Product, Engineering, and DevOps to embed security into our API and platform development lifecycle, working hand-in-hand with our Engineering and Product teams
- Perform threat modeling and security reviews to spot risks early and keep our products secure
- Identify, triage, and remediate security vulnerabilities in our codebase, infrastructure, and third-party dependencies, and help respond and manage our bug bounty program
- Build and tweak automation tools for security testing and monitoring
- Participate in security incident response efforts, including investigation, containment, and post-mortem analysis, to ensure rapid resolution and continuous improvement
- Harden our cloud systems (Google Cloud, Kubernetes) and products to meet industry standards and protect against evolving threats
- Team up with product and DevOps crews to make security seamless without slowing us down
- Promote a security-first mindset by providing guidance, training, and documentation to team members on secure coding practices and emerging threats
- Assist with compliance audits and assessments as necessary
- Conduct security research and contribute to the development of new security tools and techniques.
Who You Are (Must-Haves):
- Excited about Alpaca’s mission and what we’re building
- 6-8 years of mixed experience in a security operations, security engineering, product security, and DevSecOps
- Proficiency in at least one programming language (e.g., Go, Python etc.) and the ability to review and write secure code
- Experience with API security (e.g., OAuth, JWT, WAF, rate limiting)
- Experience with cloud security (e.g., Google Cloud, AWS) including DevSecOps and embedding security in the CI/CD pipeline
- A strong understanding of how to secure containerized environments (e.g., Kubernetes, Docker)
- Familiarity with security tools such as static code analyzers, vulnerability scanners, and penetration testing frameworks
- Knowledge of common security vulnerabilities (e.g., OWASP Top 10) and mitigation strategies
- Strong analytical and problem-solving skills
- Excellent communication skills and committed to work collaboratively across the Firm
- Comfortable thriving in a distributed, remote-first team with asynchronous collaboration across time zones
- A curious mindset, empathy for our users and teams, and a commitment to accountability—aligned with Alpaca’s core values of "Stay Curious," "Have Empathy," and "Be Accountable."
- Available for on-call rotations and after hour responses as needed
Who You Might Be (Nice-to-Haves):
- Bachelor’s degree in Information Technology or a related field
- Security related certifications such as CISSP, GIAC, OSCP, CRTO, K8s is a plus
- Experience in securing and monitoring APIs
- Understanding of financial and privacy regulations
- Experience in the financial services industry
- Business acumen to be able to balance tradeoffs between stakeholders and technology feasibility and budget constraints
How We Take Care of You:
- Competitive Salary & Stock Options
- Health Benefits
- New Hire Home-Office Setup: One-time USD $500
- Monthly Stipend: USD $150 per month via a Brex Card
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
Alpaca
Alpaca's easy to use APIs allow developers and businesses to trade algorithms, build apps and embed investing into their services.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.