The opportunity
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom.
What you'll do
Lead second line advisory coverage for key technology and security domains,: assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business.
Partner with engineering and technology teams to evaluate domain posture and: identify where additional controls, remediation, or governance improvements are needed.
Review and challenge the design of new and existing risks and their: corresponding controls to ensure our mitigations are scalable, effective, and aligned to business, risk, and regulatory expectations.
Drive coordination across risk, controls, policy, audit, and assurance teams: to translate incidents, audit findings, and regulatory expectations into actionable improvements that strengthen the technology control environment.
Intake, triage, and calculate inherent and residual risk with subject matter: experts and risk owners, facilitating risk treatment decisions and validating execution of mitigation plans.
Enable leadership decision-making by communicating quantitative and: qualitative risk tradeoffs and connecting risks, controls, policies, incidents, and findings into clear narratives that support prioritization and reporting.
What they're looking for
- Build, grow, and coach a team of technology and security analysts and senior: analysts, fostering a culture of agility, innovation, and continuous performance feedback.
- + years in technology risk, IT controls, IT audit, cybersecurity risk, or: compliance, with hands-on experience delivering full-stack GRC services (risk management, control design, continuous monitoring, governance documentation) - not a controls-only or risk-only background.
- Deep understanding of technical design and governance principles across one: or more domains such as infrastructure resiliency, SDLC, change management, or incident response, with demonstrated ability to challenge status quo and drive improvement.
- Hands-on experience evaluating risks and control design, identifying: weaknesses, and partnering with stakeholders to improve risk outcomes and control maturity.