The opportunity
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom.
What you'll do
Own and lead Coinbase's global security audit portfolio covering IAM, threat: detection, incident response, security architecture, cryptography/key management, vulnerability management, application security, and crypto-native security (wallets, cold storage), third-party/outsourced security oversight
Partner with Security Engineering, Detection & Response, and AppSec teams as: the cybersecurity subject matter expert, providing independent audit perspective and advisory value while maintaining third-line objectivity.
Manage and develop a team of security auditors while personally leading: high-complexity, high-risk security engagements across multiple jurisdictions.
Synthesize complex technical security findings into clear, risk-prioritized: reports for executive leadership, the Audit Committee, and the Board.
Drive proactive identification of emerging threats, including: crypto/blockchain attack vectors, AI/ML security risks, and supply chain risks, adjusting audit coverage and methodology accordingly.
Champion security data analytics and AI tooling (e.g., automated log/evidence: analysis) to modernize the security audit function.
What they're looking for
- + years in internal audit or security engineering/operations with: demonstrated leadership of cybersecurity-focused audits or security programs, including direct team management while carrying an individual portfolio.
- Deep, hands-on expertise in at least 2-3 of: IAM, threat detection/SOC, incident response, security architecture, cryptography/key management, cloud security (AWS/GCP), or application security.
- Relevant security certification required: CISSP, CISM, CCSP, or CCSK (CISA a plus).
- Proven ability to navigate multi-jurisdictional cybersecurity regulatory: regimes (NYDFS, SOC frameworks, OCC guidance, multi-state examiner requirements) and translate requirements into audit coverage.