freehire launches on Product Hunt on 26 August.

Follow →

Senior Manager, Security Audit

Open 58d posting dated 3 days ago

Summary

Lead global security audits for Coinbase, covering IAM, threat detection, cloud security, and crypto-native controls while managing a team and reporting findings to executives.

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

Coinbase is looking for a Senior Manager, Security Audit to lead the Internal Audit team's global coverage of information security, cybersecurity, and infrastructure/application security. Reporting to the Global Head of Internal Audit, you'll own the security audit portfolio, spanning identity and access management, threat detection, incident response, cloud security, application security, and crypto-native controls (wallets, cold storage, key management), while managing a small team and carrying your own book of complex audits.

What you'll do:
  • Own and lead Coinbase's global security audit portfolio covering IAM, threat detection, incident response, security architecture, cryptography/key management, vulnerability management, application security, and crypto-native security (wallets, cold storage), third-party/outsourced security oversight
  • Partner with Security Engineering, Detection & Response, and AppSec teams as the cybersecurity subject matter expert, providing independent audit perspective and advisory value while maintaining third-line objectivity.
  • Manage and develop a team of security auditors while personally leading high-complexity, high-risk security engagements across multiple jurisdictions.
  • Synthesize complex technical security findings into clear, risk-prioritized reports for executive leadership, the Audit Committee, and the Board.
  • Drive proactive identification of emerging threats, including crypto/blockchain attack vectors, AI/ML security risks, and supply chain risks, adjusting audit coverage and methodology accordingly.
  • Champion security data analytics and AI tooling (e.g., automated log/evidence analysis) to modernize the security audit function.
Required Skills and Experience:
  • 12+ years in internal audit or security engineering/operations with demonstrated leadership of cybersecurity-focused audits or security programs, including direct team management while carrying an individual portfolio.
  • Deep, hands-on expertise in at least 2-3 of: IAM, threat detection/SOC, incident response, security architecture, cryptography/key management, cloud security (AWS/GCP), or application security.
  • Relevant security certification required: CISSP, CISM, CCSP, or CCSK (CISA a plus).
  • Proven ability to navigate multi-jurisdictional cybersecurity regulatory regimes (NYDFS, SOC frameworks, OCC guidance, multi-state examiner requirements) and translate requirements into audit coverage.
  • Demonstrated success communicating deeply technical security concepts to executive and Board-level audiences through written reports and presentations.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Req ID: #P76564

#LI-Remote

Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)).

Annual base salary range (excluding equity and bonus):
$201,365$236,900 USD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • Linkedin Profile URL
  • Are you at least 18 years of age? choose one
  • Have you previously been employed by Coinbase in any capacity? choose one
  • Please upload proof of certification or licensure: upload · optional
  • Have you owned or co-owned an IT audit portfolio (determining what gets audited and when), and have you presented audit results to a Board or Audit Committee? Feel free to be brief.
  • Describe your IT audit scope. What technology areas have you covered (e.g., cloud, IAM, security, applications), and have you used any coding, SQL, or AI tools in your audit work? Feel free to be brief - simple and concise is fine here. written answer
  • How did you hear about this job? choose one
  • Please confirm receipt of the above linked Global Data Privacy Notice and US Arbitration Agreement. choose one
  • I understand that Coinbase may use AI tools to assist in the application and interview process. choose one
  • Which of the following best describes how you use AI tools today? choose one
  • Are you legally authorized to work in the country where this position is located? choose one
  • Will you require sponsorship for employment visa status now or in the future? choose one
  • Are you a current government official or were you a government official in the last five years (e.g., employee of a government agency or a government owned/controlled company, holder of public office or a civil service position)? choose one
  • Are you a close relative of a government official (i.e., child/step-child, spouse/partner, parent/guardian, aunt/uncle, first cousin, in-law)? choose one
  • To your knowledge, do you or a close relative currently hold a role, have a significant financial interest in, or maintain a close personal relationship with a senior leader at a company connected to Coinbase that could create an actual or perceived conflict of interest? choose one
  • To your knowledge, were you referred to this position by a senior leader or decision‑maker at a current or prospective institutional client, business partner, or vendor of Coinbase? choose one

See also