Incident Operations Lead (EMEA/AMER)
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Key Skills for This Role
Full Job Posting
Role
Lead the team that commands Alpaca's most critical incidents. You will build the function and then keep raising its bar: the severity model, the escalation and communication paths, 24x7 follow-the-sun coverage, and the KPIs that prove it is improving. You will do that across boundaries - with the engineering teams who own the services, with SRE on reliability standards and on-call readiness, with Risk on financial and regulatory materiality, with our partner communications teams on what reaches a customer, and with reliability programme management on what happens after.
You will own how well we respond. Not the fix, not the partner communication, and not the reliability standard. Holding that line is a deliberate part of the design and a core part of the job.
Things You Get To Do
Build the team and stand up 24x7 command. Recruit and certify Incident Commanders, build a follow-the-sun rotation across APAC, EMEA and AMER with warm handoffs at every regional boundary, and carry a rostered slot yourself. Keep the team sharp between real incidents with game days, tabletop exercises and simulations, and coach them through the live ones. Build a blameless review culture that treats an outlier as a process gap rather than a person's failure.
Own the process, and keep raising it. Drive severity maturity with Risk on financial and regulatory materiality - in a regulated brokerage a severity call can also start a reporting clock, so the model has to map cleanly onto those thresholds. Own the escalation path and what happens when a page goes unanswered, agree the thresholds for taking an incident to engineering leadership, and keep the service catalogue and its ownership current - time spent working out who owns a failing service is customer impact.
Own both bridges. Your team connects the engineers and technical support fixing the problem, who need uninterrupted focus, to the partner communications teams, who need a continuous and accurate feed. You open the channel, supply the facts and hold the update cadence to account. Afterwards, your team runs the retrospective with SRE - who own the technical depth - and builds the post-incident package while the room is still warm, every item ticketed, owned and tagged, delivered inside a service level you define and then hold, before reliability programme management drives it to closure. You then synthesise the discussion into short, digestible learnings and publish them to the whole engineering organisation, so one team's failure becomes everyone's lesson instead of a document three people read.
Own the KPIs. Time to respond and time to mitigate end to end, including the definitions and data hygiene beneath them: what separates mitigated from resolved, and whether a timestamp means what it claims. Establish a defensible baseline before committing to targets, then move them by severity. Review and approval, not authorship, is where postmortems stall, so report overdue reviews by team and incident with a next action against each.
Build it as a product, then automate it with AI. Everything is documented, versioned and deployable, so you can stand up command from the artefacts alone; the process needs to scale considerably faster than the team. The automation we are after is AI workflows and agents rather than scripts and dashboards - agents that set an incident up, assemble the timeline as it runs, draft the RCA and the action package, and chase the update that is due or the review that is overdue. You own that roadmap: what an agent may do unsupervised, what still needs a commander's judgement, and the decision-tree quality that makes either of them safe.
Who You Are (Must-Haves)
You have stood up an incident command or major-incident function, not only worked inside one - you have owned the severity model, built the roster and driven adoption across teams.
5+ years in production engineering, SRE or technical operations, including hands-on command of high-severity incidents.
You have led a distributed team across time zones and run a 24x7 rotation.
You get engineers you do not manage to do things, and you can defend a severity call to someone who disagrees with it.
You have built reliability metrics people trust, and you know the difference between improving a number and improving reality.
You are disciplined about scope. You can say "that is not ours" and route it, in the middle of an outage, without leaving a gap.
You write well enough that your process documents actually get used, you can hold a bridge calm under pressure, and you can brief an executive mid-incident without either downplaying it or dramatising it.
You understand FinTech and the trust stakes of API-driven financial platforms.
You use AI and agentic automation to remove toil rather than to add tooling.
Who You Might Be (Nice-to-Haves)
Formal incident command training - ITIL, Major Incident Management or crisis management.
You have run a certification, game day or drill programme, or built a pool of certified responders beyond your own headcount.
Experience with modern incident management and on-call platforms.
You have built a service catalogue or ownership registry that people actually maintained.
You have worked with programme management or reliability functions to convert incident follow-ups into funded roadmap work.
Familiarity with incident reporting obligations in regulated financial services - DORA, Reg SCI, FINRA or equivalent.
Online securities trading or capital markets experience, or another regulated, market-hours-sensitive domain.
You have deployed the same operating model into a second region or entity.
How We Take Care of You:
Competitive Salary & Stock Options
Health Benefits
New Hire Home-Office Setup: One-time USD $500
Monthly Stipend: USD $150 per month via a Brex Card
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
Recruitment Privacy Policy
About Alpaca
US-based brokerage infrastructure company providing execution and custody solutions for stocks, ETFs, options, and cryptocurrencies through its API-first platform.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Alpaca
Brokerage Operations Manager - Saudi
Riyadh, KSA
Who We Are: Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Amongst our subsidiaries, Alpaca is a licensed fina
Manager / Senior Manager, Total Rewards & Key Projects
North Salt Lake, USA
Head of Business Development - Middle East
Dubai, UAE
Alpaca is seeking a regional business development leader to build its Middle East presence across the UAE, Saudi Arabia, and broader GCC. The role owns strategic relationships, commercial opportunities, ecosystem engagem
Brokerage Operations Manager - Saudi
Riyadh, KSA
Head of Tax
, USA
Team Lead Engineer - Crypto
North Salt Lake, USA
Content Marketing Manager, Crypto
North Salt Lake, USA
Manager / Senior Manager, Total Rewards & Key Projects
North Salt Lake, USA
Senior Sales Engineer
North Salt Lake, USA
Senior Product Designer, Operations Tools
North Salt Lake, USA
Head of Business Development - Middle East
Dubai, UAE
