高级经理,安全审计
Senior Manager, Security Audit
准备好开展职业生涯中最有影响力的工作了吗?在Coinbase,我们对增加经济自由的使命毫不妥协。标准很高,环境紧张,我们喜欢这样。这里不是安于现状的地方,而是让你突破自我认知极限的地方。如果你准备与那些不愿满足于“足够好”的人一起打造金融的未来,你就在正确的地方。Coinbase是一家以远程办公为主,但并非仅限于远程的公司。你将每季度参加一次高强度的线下工作会,称为“冲刺”(surges)。了解更多关于在Coinbase工作的信息。
Coinbase正在寻找一位高级经理,负责安全审计,领导内部审计团队在全球范围内的信息安全、网络安全和基础设施/应用安全的覆盖。向全球内部审计主管汇报,你将负责安全审计组合,涵盖身份和访问管理、威胁检测、事件响应、云安全、应用安全以及原生加密货币控制(钱包、冷存储、密钥管理),同时管理一个小团队并亲自处理复杂的审计任务。
你会做以下事情:
- 负责并领导Coinbase全球安全审计组合,涵盖IAM(身份和访问管理)、威胁检测、事件响应、安全架构、密码学/密钥管理、漏洞管理、应用安全以及原生加密货币安全(钱包、冷存储),以及第三方/外包安全监督
- 与安全工程、检测与响应及AppSec团队合作,作为网络安全领域专家,提供独立的审计视角和咨询价值,同时保持第三线的客观性
- 管理和发展安全审计团队,亲自领导跨多个司法管辖区的高复杂度、高风险安全项目
- 将复杂的网络安全发现转化为清晰、按风险优先级排序的报告,供高管层、审计委员会和董事会阅读
- 主动识别新兴威胁,包括加密货币/区块链攻击路径、AI/ML安全风险和供应链风险,并相应调整审计范围和方法
- 推动安全数据分析和AI工具(例如自动化日志/证据分析)的使用,以现代化安全审计职能
所需技能和经验:
- 12年以上内部审计或安全工程/运营经验,有网络安全相关审计或安全项目的领导经验
查看英文原文
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.
Coinbase is looking for a Senior Manager, Security Audit to lead the Internal Audit team's global coverage of information security, cybersecurity, and infrastructure/application security. Reporting to the Global Head of Internal Audit, you'll own the security audit portfolio, spanning identity and access management, threat detection, incident response, cloud security, application security, and crypto-native controls (wallets, cold storage, key management), while managing a small team and carrying your own book of complex audits.
What you'll do:
- Own and lead Coinbase's global security audit portfolio covering IAM, threat detection, incident response, security architecture, cryptography/key management, vulnerability management, application security, and crypto-native security (wallets, cold storage), third-party/outsourced security oversight
- Partner with Security Engineering, Detection & Response, and AppSec teams as the cybersecurity subject matter expert, providing independent audit perspective and advisory value while maintaining third-line objectivity.
- Manage and develop a team of security auditors while personally leading high-complexity, high-risk security engagements across multiple jurisdictions.
- Synthesize complex technical security findings into clear, risk-prioritized reports for executive leadership, the Audit Committee, and the Board.
- Drive proactive identification of emerging threats, including crypto/blockchain attack vectors, AI/ML security risks, and supply chain risks, adjusting audit coverage and methodology accordingly.
- Champion security data analytics and AI tooling (e.g., automated log/evidence analysis) to modernize the security audit function.
Required Skills and Experience:
- 12+ years in internal audit or security engineering/operations with demonstrated leadership of cybersecurity-focused audits or security programs, including direct team management while carrying an individual portfolio.
- Deep, hands-on expertise in at least 2-3 of: IAM, threat detection/SOC, incident response, security architecture, cryptography/key management, cloud security (AWS/GCP), or application security.
- Relevant security certification required: CISSP, CISM, CCSP, or CCSK (CISA a plus).
- Proven ability to navigate multi-jurisdictional cybersecurity regulatory regimes (NYDFS, SOC frameworks, OCC guidance, multi-state examiner requirements) and translate requirements into audit coverage.
- Demonstrated success communicating deeply technical security concepts to executive and Board-level audiences through written reports and presentations.
- Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.
Req ID: #P76564
#LI-Remote
Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)).
Annual base salary range (excluding equity and bonus):
$201,365—$236,900 USD
- Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
- Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
- US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
- Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
- Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.