Himalayas logo
AlpacaAL

DevSecOps Engineer

Alpaca builds financial services APIs for everyone globally.

Alpaca

Employee count: 201-500

BR, CA + 5 more

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Who We Are:

Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our recent Series C funding round brought our total investment to over $170 million, fueling our ambitious vision.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 6 million brokerage accounts.

Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.

Alpaca is proudly backed by top-tier global investors, including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Unbound, SBI Group, Derayah Financial, Elefund, and Y Combinator.

Our Team Members:

We're a dynamic team of 230+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!

We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.

Your Role:

We are seeking a DevSecOps Engineer to own the intersection of security, reliability, and DevOps. This role will design and implement resiliency across our cloud platform and CI/CD pipelines, embed “security as code,” help lead incident response for high-severity outages, and partner with engineering teams to enable safe, fast delivery at scale.

You will be hands-on and strategic: automating remediation, hardening deployments, owning observability, and driving measurable reductions in security/infra related incident impact. This role reports to the CISO, with a dotted line into Engineering and works closely with DevOps, Product, and Engineering leadership.

The Security Team is 100% distributed and remote.

Things You Get To Do:

The core responsibilities of the DevSecOps Engineer role are focused on embedding security throughout our infrastructure and software development lifecycle, enhancing cyber resilience, and driving a strong security culture.

Security Engineering & Automation:

  • Secure SDLC Integration: Embed security into CI/CD pipelines by implementing and owning secure controls, including Infrastructure as Code (IaC) scanning, Software Composition Analysis (SCA), secrets checks, policy-as-code, and deployment guardrails.
  • Vulnerability Management: Lead the process of vulnerability and patch management, automating discovery, prioritization, and remediation across all cloud workloads and their dependencies.
  • Platform Hardening: Strengthen cloud and Kubernetes environments through secure configurations, network segmentation, workload identity management, and automated compliance against industry standards (e.g., CSA Star).
  • Supply Chain Security: Advance the security of the software supply chain, focusing on generating Software Bill of Materials (SBOMs), artifact signing, dependency governance, and implementing integrity controls.
  • Secure Patterns: Create secure "paved roads" for developers, providing hardened IaC modules, templates, tooling, and comprehensive documentation.

Resilience, Detection, and Response:

  • Cyber Resilience: Own and validate cyber-resiliency standards (secure failover, secure backups, Disaster Recovery playbooks) through secure rehearsals to ensure both the availability and integrity of systems and data
  • Security Deployment: Develop secure deployment patterns, such as canary rollouts, automated safe rollbacks, and guardrails to minimize blast radius
  • Detection & Forensics: Improve detection and response capabilities by building high-signal alerts, enhancing forensic logging, and providing robust security telemetry. Partner with the SecOps team on incident handling
  • Offensive Security: Alongside the Security team, help manage offensive security engagements (penetration testing, red team, bug bounty) and ensure findings are fed directly into remediation pipelines and risk prioritization

Architecture, Identity, and Governance:

  • Design & Threat Modeling: Conduct security reviews and threat modeling for all new services and major architecture changes to ensure designs are secure-by-default
  • Identity & Access Management (IAM): Strengthen the identity and access model by enforcing the principle of least privilege, strong authentication, and secure secrets lifecycle management
  • Compliance & Audit: Support compliance and audit readiness by operationalizing security controls, producing necessary evidence, and maintaining the health of these controls

Leadership & Culture:

  • Security Champion: Champion a strong security culture by partnering with DevOps and Engineering teams to uplift secure coding practices and guide risk-based decision-making
  • Metrics & Reporting: Define key security performance indicators (KPIs) such as time to detect, time to remediate, exposure scores, and percentage of infrastructure covered by automated controls, and report measurable improvements to leadership

Who You Are (Must-Haves):

  • Excited about Alpaca’s mission and what we’re building
  • 5+ years of experience across DevSecOps, security engineering, or cloud security in a modern cloud-native environment
  • Strong hands-on experience with CSPs, Kubernetes, Terraform, and container security
  • Deep understanding of secure CI/CD, including IaC security, dependency/SCA, secrets scanning, and policy-as-code
  • Solid background in identity & access security
  • Experience automating vulnerability management and patching workflows across cloud and container ecosystems
  • Strong familiarity with detection engineering, logging/telemetry, and partnering in incident response
  • Proficient in a scripting/programming language (Python, Go, or similar) for automation and security tooling
  • Comfortable working cross-functionally with DevOps and Engineering teams, explaining risk in practical terms, and influencing secure design
  • Comfortable participating in on-call rotations

Who You Might Be (Nice-to-Haves):

  • Experience securing financial, trading, or other highly regulated platforms
  • Knowledge of regulatory frameworks common in fintech (SOC 2, ISO 27001, PCI)
  • Experience with supply-chain security (SBOMs, Sigstore, artifact signing) or software integrity programs
  • Familiarity with offensive security, bug bounty triage, or penetration testing
  • Security or cloud certifications (CISSP, OSCP, GIAC, GCP/AWS Security)
  • Bachelor's degree in Computer Science, Information Security, or equivalent experience.
  • Business acumen to be able to balance tradeoffs between stakeholders and technology feasibility and budget constraints

How We Take Care of You:

  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time USD $500
  • Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Recruitment Privacy Policy

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Hiring timezones

United States +/- 0 hours, and 6 other timezones

About Alpaca

Learn more about Alpaca and their company culture.

View company profile

Alpaca builds financial services APIs for everyone globally. We bridge the gap between those who can access financial services and those who cannot, through inclusive technology.

We're a melting pot of diverse backgrounds from tech startup aficionados to individuals with deep financial experience. No matter your background or where you're from, we've got a role for you.

Build and scale your career

We're a team of ambitiously creative minds, set on delivering high quality and high impact results. We're always exploring and never satisfied with just enough. When problems get tough, we get energized and become even more laser-focused. We're keen on that last 10% of effort and believe that the details do matter. If this sounds like you, then you're in the right place.

Our teams are scaling and growing faster every day. If you're looking to challenge yourself and advance your career, Alpaca offers limitless opportunities. Are you ready to build with us?

Unwavering, goal-oriented culture

Our teams are goal-oriented. We care about doing the work and solving the problem together. We welcome questions from all levels because we know that no one knows all the answers. Your goal isn't to be the smartest in the room. Your goal is to help solve problems no one has solved before by driving impact in areas you're strongest. And with a positive mindset, we set out to own the unknown and thrive in situations where we have to learn to succeed.

Our goal together is to make sure that the right questions are heard no matter who they come from, and the right solutions are built no matter who builds them.

Global mindset, globally distributed

We are living in unprecedented times - our global economy is tightly interwoven while constantly expanding and transforming. The future of financial innovation will never belong to just one country. As we work to provide access to financial services for everyone on the planet, it's important for us to build a global team of agile talent with vibrantly diverse cultural experiences.

Our teams are not just global, we're also 100% remote and have team members in almost every time zone and continent (except Antarctica). By joining Alpaca you'll be part of a multicultural, international organization.

Radical, honest, and empathy-driven

We're a startup with products that are disrupting an old industry. We see the opportunity and it's clear to us that our impact is going to be massive. We want to be a team that's ready for the ups and downs. We move fast and try our best to bring honesty and clarity when we communicate. Each of us brings to the table unique life experiences and diverse backgrounds - these experiences are valued and we don't take it for granted. We want to learn about you and want you to learn about us, working together to build empathy every step of the way.

In order for us to achieve our goal of providing access to financial services for everyone on the planet, it is critical for us to maintain high-trust partnerships and act with honesty and empathy. During this journey together, we'll be learning about the world together, through our relationships with each other. This is just the beginning and we would love to work with you!

Employee benefits

Learn about the employee benefits and perks provided at Alpaca.

View benefits

Monthly Brex Card Stipend

Employees receive a monthly USD $150 stipend on a Brex card for additional work-related expenses.

Competitive Salary & Equity

Alpaca offers competitive salaries alongside stock options, ensuring employees share in the company's success.

Home-Office Setup Stipend

Alpaca provides a one-time USD $500 for home-office setup to create a comfortable and productive work environment.

Immediate Health Benefits

Health benefits at Alpaca start on day 1, covering medical, dental, and vision. In Canada, supplemental health care is included, and internationally, a stipend is provided to offset medical costs.

View Alpaca's employee benefits
Claim this profileAlpaca logoAL

Alpaca

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

31 remote jobs at Alpaca

Explore the variety of open remote roles at Alpaca, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Alpaca

Remote companies like Alpaca

Find your next opportunity by exploring profiles of companies that are similar to Alpaca. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan