Head of Information Security (APAC)
$500 per monthAlpaca
Head Of Information Security (APAC)
Remote - APAC
Who We Are:
Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our recent Series D funding round brought our total investment to over $320 million, fueling our ambitious vision.
Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totaling over 9 million brokerage accounts.
Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.
Alpaca is proudly backed by top-tier global investors, including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Unbound, SBI Group, Derayah Financial, Elefund, and Y Combinator.
Our Team Members:
We're a dynamic team of 380+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond! We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.
Your Role:
Reporting to the Global CISO, the Head of Information Security (APAC) drives Alpaca's regional security, risk, and compliance, focusing on APAC regulations (APPI, FSA, MAS).
You will be the regional security authority, collaborating with global teams (Security, Engineering, Legal, Compliance, Product) to align infrastructure, the trading platform, and internal systems with both global standards and local regulatory needs.
This role merges security engineering, local compliance, risk management, and stakeholder engagement. You translate regional regulatory requirements into actionable security controls, ensuring a secure, scalable, and compliant platform. You will also be the main contact for regulators, auditors, and local stakeholders, enabling confident operations in highly regulated financial markets.
Things You Get To Do:
Regional Security & Compliance Leadership
- Manage Alpaca's APAC information security program
- Interpret and implement local regulatory requirements into security controls
- Serve as the APAC security compliance and regulatory expert
- Ensure alignment with Global Security, Legal, and Compliance on financial services and data protection regulations
Security Risk Management
- Lead risk identification, assessment, and mitigation for cloud infrastructure, APIs, and trading systems
- Manage and evolve regional risk registers, reporting, and governance
- Ensure adherence to global frameworks (ISO 27001, SOC 2, CSA STAR)
Cloud & Platform Security Collaboration
- Partner with Engineering for secure-by-design, cloud-native infrastructure
- Provide guidance on IAM, Network security architecture, Secure SDLC, Infrastructure hardening/monitoring
- Review architecture to embed security and compliance early
Regulatory Audits & External Engagement
- Lead and support regulatory exams, audits, and assessments
- Act as the primary liaison for Regulators, external auditors, and local compliance partners
- Report findings to the global security team and assist with triage and mitigation
Policy, Governance & Controls
- Develop and maintain regional security policies, standards, and procedures as required
- Localize global policies for APAC regulatory environments
- Drive control implementation and testing across security and compliance frameworks
Who You Are (Must-Haves):
- 6+ years of experience in information security, cybersecurity, or GRC, preferably in fintech or financial services
- Fluent in Japanese and English (written and verbal)
- An excellent understanding of cloud security, application and infrastructure security, and risk management frameworks
- Experience with security and compliance frameworks (ISO 27001, SOC 2, etc.)
- Direct experience working with or supporting regulatory requirements in Japan (e.g. APPI / FSA) and/or APAC
- Proven experience handling audits, regulatory exams, or compliance programs
- Ability to work cross-functionally with engineering, product, and compliance teams
- Strong communication skills, with the ability to translate technical risks into business impact
Who You Might Be (Nice-to-Haves):
- Experience in brokerage, trading platforms, or financial infrastructure
- Experience with data privacy regulations (APPI, GDPR, etc.)
- Security certifications (e.g. CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor)
- Experience building or scaling regional security programs
- Exposure to DevSecOps practices and modern cloud-native architectures
- Familiarity with AI/ML risk considerations in financial systems
How We Take Care of You:
- Competitive Salary & Stock Options
- Health Benefits
- New Hire Home-Office Setup: One-time USD $500
- Monthly Stipend: USD $150 per month via a Brex Card
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
Recruitment Privacy Policy
- ...life optimizations. Learn More: Responsible for the strategic and technical leadership and direct management of MathWorks’ Information Security team, overseeing the company’s corporate security. Provides operational direction to ensure protection of data,...SuggestedFor contractorsWork experience placementWork at officeRemote workFlexible hoursShift work
$135k - $222.75k
...- $222,750.00 Supervisory Organization VP Chief Information Officer Country United States of America Address... ...Executives (EEO-SubCategory) General Summary The Head of Information and Network Security is responsible for providing leadership, direction and...SuggestedWork at officeRemote work$135k - $222.75k
...Dallas Area Rapid Transit Inc is seeking a Head of Information and Network Security based in Dallas, TX. The role involves leadership in data security, disaster recovery, and business continuity, with a focus on building relationships across teams to establish security...SuggestedRemote work- ...Video’s Going Home with Tyler Cameron, Roku’s Reptile Royalty, OWN’s Love & Marriage: Huntsville and many others. The Head of Information Security is responsible for establishing and leading ITV America’s information security program with a focus on Content Security,...SuggestedWork at office
- ...remove friction, reduce risk, and expand into new markets with confidence. The Role We are looking for an experienced Head of Information Security who will shape and lead our security strategy. In this role you report to the VP IT & Infrastructure and collaborate...SuggestedWork at officeRemote workFlexible hours
- ...About This Opportunity We are seeking a strategic and experienced Head of Information Security (CISO/VP level) to lead, scale, and govern our enterprise cybersecurity program. In this executive role, you will define the organization's multi‑year security roadmap, align...Full timeWork at officeRemote workMonday to Friday
$280k - $320k
...Security at most companies is reactive. A checkbox for auditors. A speed bump for engineers... ..., seen, and remembered. Why Head of IT & Security We're an AI company... ...further. You'll own Sendbird's comprehensive information security programs, manage and evolve our...Temporary workWork at officeLocal areaFlexible hours3 days per week- ...Get AI-powered advice on this job and more exclusive features. The Head of Information Security will lead the organization’s cybersecurity and IT risk management program, ensuring the confidentiality, integrity, and availability of enterprise systems, data, and services...Full timeContract work
- ...Cleverbridge is hiring a Head of Information Security to shape and lead their security strategy. This role involves collaborating with various teams to integrate security into software development and ensuring compliance with standards like PCI-DSS and SOC 2. The ideal...Remote work
$135k
A healthcare organization in Atlanta is seeking a Manager of Security Operations who will lead a team of security analysts and engineers... ...bachelor's degree in a related field, a minimum of 5 years in information security with leadership experience, and strong communication...Flexible hours- Finastra in Atlanta seeks a Head of Information Security Program Management to oversee critical cybersecurity projects. This role requires managing project managers and delivering on security initiatives while ensuring adherence to budget and timelines. The ideal candidate...Flexible hours
- ...and tackle tough tasks to ensure our momentum never slows. Head of Security and IT This role owns Nile's overall security and... ...workforce. Some specific job duties are as follows. Own Information Security and IT for Nile, reporting to senior leadership....Worldwide
- ...visit ( About the Role As Bitdeer AI Cloud's first dedicated security leader for the Americas, you will own the full-stack security... ...related technical field. Experience: 10+ years of hands-on information security experience, with at least 5 years strictly focused on...Local area
- ...Head of Infrastructure Security | Global Alternative Investment Firm Head of Infrastructure Security | Global Alternative Investment Firm... ...technical domains ~ Bachelor’s degree in Computer Science, Information Security, or a related field ~(Preferred) A track...Full timeWork at officeRemote work
$250k - $375k
...nicest group of individuals, including researchers from MIT, Harvard, and Berkeley, to world-class engineers from industry: Citadel Securities, Cockroach Labs, Datadog, DE Shaw, ServiceNow, Glean, Perplexity, Pinecone, and more, to take on one of the hardest problems for...Full timeWork at officeFlexible hours- ...City Thunder and the NBA on providing a security and state of the art network.* Implement... ...cost benefit analysis. Ensures that such information is complete and accurate and presented... ...of this position are described under the headings above. They may be subject to change at...Contract workFor contractorsFor subcontractorWork at officeShift workNight shift
$140k - $160k
...Commonwealth of VA Careers is seeking a Chief of Information Security & Privacy in Richmond, Virginia. This senior leadership position involves setting the strategic direction for the Health Benefit Exchange's privacy and security governance, risk, and compliance programs...- ...stack. M0 keeps them independent, so your stablecoin stays yours. M0 is seeking a sharp, execution-focused Head of Security & Risk to build and own the information security and risk function from the ground up. This is a foundational IC role at a critical inflection...Contract workWork at officeRemote workWorldwide
- ...Head Of Cyber Defense As the Head of Cyber Defense within Vanguard's Cyber Security Operations Center (CSOC), you will serve as a senior leader responsible for advancing... .... Graduate degree preferred. Certified Information Systems Security Professional (CISSP) and/...
$160k - $225k
...Axinn, Veltrop & Harkrider LLP is seeking a Manager/Senior Manager of Information Security to establish and lead a comprehensive security program in Hartford, CT. This role requires a minimum of 10 years in information security, providing strategic direction and oversight...- ...A leading technology company is seeking a strategic leader for its Information Security team in Natick, Massachusetts. The role demands significant expertise in cybersecurity, risk management, and compliance with regulations. Responsibilities include developing a cybersecurity...Work at officeRemote work
- ...generation autonomous systems platform serving defense, national security, public safety, and commercial markets. Through advanced... ...We're Looking For ~ Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline...
- ...level leadership to safeguard critical assets andmaintainoperational resilience. A CISO will provide strategic oversight of information security, ensure compliance with industry standards, and drive a unified risk‑management approach across the enterprise. This role will...
- ...Northern Kentucky, as well as the Indianapolis, Indiana and Cincinnati, Ohio metropolitan markets. Job Title: Director of Information Security FLSA Status: Exempt Department: Information Security Hours of Operation: Monday - Friday 7:00am - 4:...Temporary workWork at officeMonday to FridayFlexible hours
- ...Director Of Information And Security Our client is seeking a Director of Information and Security to lead global IT operations across cybersecurity, infrastructure, cloud services, server management, DevOps, Disaster Recovery as a Service (DRaaS), and desktop support...
$147.55k - $265.58k
...Area The Information Security department is responsible for setting enterprise security policies and standards that are designed to protect the confidentiality, integrity and availability of Morningstar information. The security team offers guidance and technical expertise...Contract workTemporary workWork at officeFlexible hours- ...Position Overview: The Director of Information Security is responsible for the design, development and implementation of enterprise cybersecurity solutions and will report to the Vice President of Information Security. This position is the highest-level technical...Work at officeLocal areaRemote work
- ...Director of Information Security Duration: Full-Time Location: Remote About BigRio : BigRio is a Digital Transformation consulting firm headquartered in Boston, MA, specializing in data and analytics, custom development, software implementation, data...Full timeRemote work
$217k - $300k
...Flourish Ventures is seeking an Associate General Counsel in San Francisco to lead the Privacy & Security team. This role involves managing the privacy program in compliance with laws and advising on AI governance. The individual will work cross-functionally with various...- ...Head of Security, HPC/Gen AI About the Company A private applied technology organization building security in a highly technical engineering environment. Industry Information Technology and Services Type Privately Held About the Role The Company...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Head of Information Security (APAC). Be the first to apply!
- assistant director of security United States
- director of security United States
- director of corporate security United States
- head of security United States
- chief security officer United States
- information security lead United States
- information security internship United States
- entry level information security analyst United States
- information security United States
- sr information security engineer United States

