Manager, GRCActive$46K–$183K

The opportunity

Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom.

What you'll do

  • Lead second line advisory coverage for key technology and security domains,: assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business.

  • Partner with engineering and technology teams to evaluate domain posture and: identify where additional controls, remediation, or governance improvements are needed.

  • Review and challenge the design of new and existing risks and their: corresponding controls to ensure our mitigations are scalable, effective, and aligned to business, risk, and regulatory expectations.

  • Drive coordination across risk, controls, policy, audit, and assurance teams: to translate incidents, audit findings, and regulatory expectations into actionable improvements that strengthen the technology control environment.

  • Intake, triage, and calculate inherent and residual risk with subject matter: experts and risk owners, facilitating risk treatment decisions and validating execution of mitigation plans.

  • Enable leadership decision-making by communicating quantitative and: qualitative risk tradeoffs and connecting risks, controls, policies, incidents, and findings into clear narratives that support prioritization and reporting.

What they're looking for

  • Build, grow, and coach a team of technology and security analysts and senior: analysts, fostering a culture of agility, innovation, and continuous performance feedback.
  • + years in technology risk, IT controls, IT audit, cybersecurity risk, or: compliance, with hands-on experience delivering full-stack GRC services (risk management, control design, continuous monitoring, governance documentation) - not a controls-only or risk-only background.
  • Deep understanding of technical design and governance principles across one: or more domains such as infrastructure resiliency, SDLC, change management, or incident response, with demonstrated ability to challenge status quo and drive improvement.
  • Hands-on experience evaluating risks and control design, identifying: weaknesses, and partnering with stakeholders to improve risk outcomes and control maturity.