Incident Operations Lead (EMEA/AMER)
Who We Are:
Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more.
Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.
Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.
Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.
Our Team Members:
We're a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!
We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.
Role
Lead the team that commands Alpaca's most critical incidents. You will build the function and then keep raising its bar: the severity model, the escalation and communication paths, 24x7 follow-the-sun coverage, and the KPIs that prove it is improving. You will do that across boundaries - with the engineering teams who own the services, with SRE on reliability standards and on-call readiness, with Risk on financial and regulatory materiality, with our partner communications teams on what reaches a customer, and with reliability programme management on what happens after.
You will own how well we respond. Not the fix, not the partner communication, and not the reliability standard. Holding that line is a deliberate part of the design and a core part of the job.
Things You Get To Do
- Build the team and stand up 24x7 command. Recruit and certify Incident Commanders, build a follow-the-sun rotation across APAC, EMEA and AMER with warm handoffs at every regional boundary, and carry a rostered slot yourself. Keep the team sharp between real incidents with game days, tabletop exercises and simulations, and coach them through the live ones. Build a blameless review culture that treats an outlier as a process gap rather than a person's failure.
- Own the process, and keep raising it. Drive severity maturity with Risk on financial and regulatory materiality - in a regulated brokerage a severity call can also start a reporting clock, so the model has to map cleanly onto those thresholds. Own the escalation path and what happens when a page goes unanswered, agree the thresholds for taking an incident to engineering leadership, and keep the service catalogue and its ownership current - time spent working out who owns a failing service is customer impact.
- Own both bridges. Your team connects the engineers and technical support fixing the problem, who need uninterrupted focus, to the partner communications teams, who need a continuous and accurate feed. You open the channel, supply the facts and hold the update cadence to account. Afterwards, your team runs the retrospective with SRE - who own the technical depth - and builds the post-incident package while the room is still warm, every item ticketed, owned and tagged, delivered inside a service level you define and then hold, before reliability programme management drives it to closure. You then synthesise the discussion into short, digestible learnings and publish them to the whole engineering organisation, so one team's failure becomes everyone's lesson instead of a document three people read.
- Own the KPIs. Time to respond and time to mitigate end to end, including the definitions and data hygiene beneath them: what separates mitigated from resolved, and whether a timestamp means what it claims. Establish a defensible baseline before committing to targets, then move them by severity. Review and approval, not authorship, is where postmortems stall, so report overdue reviews by team and incident with a next action against each.
- Build it as a product, then automate it with AI. Everything is documented, versioned and deployable, so you can stand up command from the artefacts alone; the process needs to scale considerably faster than the team. The automation we are after is AI workflows and agents rather than scripts and dashboards - agents that set an incident up, assemble the timeline as it runs, draft the RCA and the action package, and chase the update that is due or the review that is overdue. You own that roadmap: what an agent may do unsupervised, what still needs a commander's judgement, and the decision-tree quality that makes either of them safe.
Who You Are (Must-Haves)
- You have stood up an incident command or major-incident function, not only worked inside one - you have owned the severity model, built the roster and driven adoption across teams.
- 5+ years in production engineering, SRE or technical operations, including hands-on command of high-severity incidents.
- You have led a distributed team across time zones and run a 24x7 rotation.
- You get engineers you do not manage to do things, and you can defend a severity call to someone who disagrees with it.
- You have built reliability metrics people trust, and you know the difference between improving a number and improving reality.
- You are disciplined about scope. You can say "that is not ours" and route it, in the middle of an outage, without leaving a gap.
- You write well enough that your process documents actually get used, you can hold a bridge calm under pressure, and you can brief an executive mid-incident without either downplaying it or dramatising it.
- You understand FinTech and the trust stakes of API-driven financial platforms.
- You use AI and agentic automation to remove toil rather than to add tooling.
Who You Might Be (Nice-to-Haves)
- Formal incident command training - ITIL, Major Incident Management or crisis management.
- You have run a certification, game day or drill programme, or built a pool of certified responders beyond your own headcount.
- Experience with modern incident management and on-call platforms.
- You have built a service catalogue or ownership registry that people actually maintained.
- You have worked with programme management or reliability functions to convert incident follow-ups into funded roadmap work.
- Familiarity with incident reporting obligations in regulated financial services - DORA, Reg SCI, FINRA or equivalent.
- Online securities trading or capital markets experience, or another regulated, market-hours-sensitive domain.
- You have deployed the same operating model into a second region or entity.
How We Take Care of You:
- Competitive Salary & Stock Options
- Health Benefits
- New Hire Home-Office Setup: One-time USD $500
- Monthly Stipend: USD $150 per month via a Brex Card
_Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
_
Job Details
Experience
Management