Manager, GRC

USD 194,000-228,200 per year
MIDDLE
✅ Remote

Tech Stack

AI @ 3 Audit @ 6 Change Management @ 6 Compliance @ 6 GenAI Generative AI @ 3 Mentoring @ 3 Security Team Management

Details

Coinbase is hiring a Manager, GRC to join the Technology Risk & Controls team within Security. The role leads second-line-of-defense advisory coverage across critical technology and security domains, evaluating risk posture, improving control design, and helping engineering, infrastructure, and security leaders make risk-informed decisions. The position includes team management as well as direct ownership of advisory coverage for domains such as disaster recovery and resiliency, SDLC, artificial intelligence, identity and access management, and supply chain.

Coinbase is a remote-first, but not remote-only, company. Employees are expected to meet quarterly for in-person working sessions called “surges.”

Responsibilities

  • Lead second-line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues.
  • Partner with engineering and technology teams to evaluate domain posture and identify additional control, remediation, or governance improvements.
  • Review and challenge the design of new and existing risks and controls to ensure mitigations are scalable, effective, and aligned with business, risk, and regulatory expectations.
  • Coordinate across risk, controls, policy, audit, and assurance teams to translate incidents, audit findings, and regulatory expectations into actionable improvements.
  • Intake, triage, and calculate inherent and residual risk with subject matter experts and risk owners.
  • Facilitate risk treatment decisions and validate the execution of mitigation plans.
  • Communicate quantitative and qualitative risk tradeoffs and connect risks, controls, policies, incidents, and findings into clear narratives for prioritization and reporting.
  • Build, grow, and coach a team of technology and security analysts and senior analysts.
  • Foster a culture of agility, innovation, and continuous performance feedback.

Requirements

  • 8+ years of experience in technology risk, IT controls, IT audit, cybersecurity risk, or compliance.
  • Hands-on experience delivering full-stack GRC services, including risk management, control design, continuous monitoring, and governance documentation.
  • Deep understanding of technical design and governance principles across domains such as infrastructure resiliency, SDLC, change management, or incident response.
  • Experience evaluating risks and control designs, identifying weaknesses, and partnering with stakeholders to improve risk outcomes and control maturity.
  • Proven experience managing and mentoring analysts, developing their capabilities and careers, and holding teams accountable for deliverables and timelines.
  • Experience influencing cross-functional stakeholders, navigating ambiguity, and translating complex risk and compliance concepts into clear functional requirements for technical and non-technical audiences.
  • Ability to use generative AI responsibly with human oversight to deliver business-ready outputs and improve workflow efficiency, cost, and quality.

Compensation

  • Annual base salary: $193,970–$228,200 USD, excluding equity and bonus.
  • Total compensation may also include equity, bonus eligibility, and medical, dental, vision, and 401(k) benefits.

Additional Information

  • Position ID: P78170.
  • Candidates may submit a maximum of three applications within a six-month period.
  • Coinbase is an Equal Opportunity Employer.
  • US applicants are provided with Employee Rights, Know Your Rights, and E-Verify notices.
  • Reasonable accommodations are available upon request.
  • Application submission is subject to Coinbase’s Candidate Privacy Notice and, for US applicants, the Arbitration of Disputes agreement.

More jobs at Coinbase

Similar jobs