The opportunity
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom.
What you'll do
Own second-line triage and response for security alerts, leading incident: management through resolution and driving post-incident improvements
Build and maintain runbooks for repeatable response patterns, then define and: implement automation to eliminate manual toil
Partner with teams across Security Operations to develop monitoring: strategies informed by attacker investigation findings
Drive Security monitoring and incident response for emerging Web3 product launches
Strengthen team capabilities by mentoring peers, sharing knowledge, and: participating in 24/7 rotational coverage across time zones
+ years of hands-on security operations experience including incident: response, alert triage, and network/host forensics across cloud, SaaS, and container environments
What they're looking for
- Demonstrated ability to identify detection gaps and build coverage across: diverse log sources (cloud platforms, SaaS applications, container orchestration, M&A integrations)
- Proficiency scripting automation workflows that reduce manual investigation: and response time (Python, Bash, or equivalent)
- Working knowledge of networking fundamentals and operating systems (Windows,: Linux, macOS) sufficient to analyze host and network-level artifacts
- Experience working with SIEM platforms and threat intelligence tooling at: scale, including tuning alerts and improving signal-to-noise ratios