CSIRT专员
Specialist, CSIRT
准备好开展职业生涯中最有影响力的工作了吗?在Coinbase,我们对增加经济自由的使命毫不妥协。标准很高,环境紧张,我们喜欢这样。这里不是安于现状的地方,而是让你突破自我认知极限的地方。如果你准备与那些不愿满足于“足够好”的人一起打造金融的未来,你就在正确的地方。Coinbase是一家以远程办公为主,但并非仅远程办公的公司。你将每季度参加高强度的线下工作会,称为“冲刺”。了解更多关于在Coinbase工作的内容。
作为Security Operations团队的Security Operations Specialist,你将保护Coinbase及其客户免受世界上最先进的攻击者的威胁。这个团队涵盖CDRE、内部威胁、Blockops和威胁情报,保护数十亿美元的数字资产,同时为接下来十亿个加密货币用户扩展安全覆盖范围。你将负责第一线的事件响应,构建检测和自动化能力,并与组织内其他团队合作,确保Coinbase在全球推出新的Web3产品时的安全性。
你将负责:
- 负责安全警报的二线分析和响应,领导事件管理直至解决,并推动事件后的改进
- 构建并维护可重复响应模式的操作手册,然后定义并实现自动化以消除手动操作
- 与Security Operations内的团队合作,根据攻击者调查结果制定监控策略
- 推动新兴Web3产品发布中的安全监控和事件响应
- 通过指导同事、分享知识以及在不同时区进行24/7轮班值班来增强团队能力
所需的技能和经验:
- 3年以上实际的安全运营经验,包括事件响应、警报分析以及在云、SaaS和容器环境中的网络/主机取证
- 在多种日志来源(云平台、SaaS应用、容器编排、并购整合)中识别检测缺口并建立覆盖能力的证明能力
- 熟练编写自动化流程脚本,以减少手动调查和响应时间(Python、Bash或同等语言)
- 对网络基础和操作系统(Windows、Linux、macOS)有基本了解,足以分析主机和网络级别的证据
- 有使用SIEM平台和威胁情报的经验
查看英文原文
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.
As a Security Operations Specialist on the Security Operations team, you'll defend Coinbase and its customers against some of the most sophisticated attackers in the world. This team - spanning CDRE, Insider Threat, Blockops and Threat Intelligence - protects billions of dollars in digital assets while scaling security coverage for the next billion crypto users. You'll own frontline incident response, build detection and automation capabilities, and partner across the organization to keep Coinbase safe as it launches new Web3 products globally.
What you'll do:
- Own second-line triage and response for security alerts, leading incident management through resolution and driving post-incident improvements
- Build and maintain runbooks for repeatable response patterns, then define and implement automation to eliminate manual toil
- Partner with teams across Security Operations to develop monitoring strategies informed by attacker investigation findings
- Drive Security monitoring and incident response for emerging Web3 product launches
- Strengthen team capabilities by mentoring peers, sharing knowledge, and participating in 24/7 rotational coverage across time zones
Required Skills and Experience:
- 3+ years of hands-on security operations experience including incident response, alert triage, and network/host forensics across cloud, SaaS, and container environments
- Demonstrated ability to identify detection gaps and build coverage across diverse log sources (cloud platforms, SaaS applications, container orchestration, M&A integrations)
- Proficiency scripting automation workflows that reduce manual investigation and response time (Python, Bash, or equivalent)
- Working knowledge of networking fundamentals and operating systems (Windows, Linux, macOS) sufficient to analyze host and network-level artifacts
- Experience working with SIEM platforms and threat intelligence tooling at scale, including tuning alerts and improving signal-to-noise ratios
- Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.
Position ID: P77687
#LI-Remote
Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).
Annual base salary range (excluding equity and bonus):
₹2,755,300—₹2,755,300 INR
- Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
- Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
- US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
- Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
- Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.