Used Tools & Technologies
Not specified
Required Skills & Competences ?
Security @ 3 Machine Learning @ 6 Leadership @ 3 Mentoring @ 3 Jira @ 3 FinTech @ 3 Project Management @ 3 Audit @ 3 Compliance @ 3 Web3 @ 3Details
Ready to be pushed beyond what you think you’re capable of?
At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.
To achieve our mission, Coinbase is seeking a candidate passionate about crypto and blockchain technology who thrives under pressure, collaborates with high-caliber colleagues, and actively seeks feedback to keep leveling up. The work culture is intense; many roles are remote-first but not remote-only, and in-person participation is required throughout the year (team and company offsites are held multiple times annually).
Responsibilities
- Enable risk-informed business outcomes by communicating quantitative and qualitative tradeoffs to teams and leadership.
- Manage risks throughout the risk lifecycle: intake, triage, analyze, calculate inherent/residual risk, facilitate risk treatment decisions, validate execution of mitigation plans, and participate in continuous monitoring.
- Maintain the source-of-truth risk register: quality control of data, tooling support, and implement automation/process improvements to improve risk management data and tooling.
- Iterate on program elements by analyzing multiple variables to improve threat models and risk scoring methodologies.
- Report on risk posture: prepare synchronous and asynchronous reports on findings, metrics, and recommended mitigations for business leadership; participate in ad-hoc and scheduled leadership meetings.
- Develop and execute communications and training plans to roll out the technology risk program across the organization; maintain runbooks, intra-team pages, and risk register dashboards.
- Build, grow, and coach a team of technology and security risk analysts; provide ongoing performance feedback and foster a culture of agility and innovation.
- Align with Enterprise Risk Management to escalate relevant risks and report metrics to senior leadership.
- Collaborate globally to scale the risk framework across Coinbase entities, products, and geographies; work with GRC, Legal, and Compliance to meet regulatory requirements.
- Support audit and regulatory inspections by compiling data to respond to US and international audit/regulator inquiries.
- Maintain an industry pulse on international regulation, emerging threats, forecasts, policies, and benchmarks.
Requirements
- 8+ years experience in a 1st or 2nd Line of Defense risk management function and/or Governance, Risk, and Compliance (GRC) organization.
- Domain knowledge and best practices: familiarity with standards and frameworks such as ISO 27001/5, NIST CSF, COBIT, ITIL, DORA, and FAIR risk quantification methodology.
- Technology risk domain expertise: ability to work on technical quantitative risk assessments across IT domains (asset management, resilience, systems development lifecycle, infrastructure).
- Comfortable with project management tooling (e.g., Jira, Archer) and quantitative/qualitative data analytics tooling.
- Clear and concise communicator and writer; experience drafting and operationalizing project plans, holding teams accountable, and documenting deliverables for both junior and senior stakeholders.
- Experience managing and mentoring analysts to grow and mature their capabilities and careers.
- Working knowledge of major regulatory/legal frameworks (US/international) that drive requirements across technology organizations.
- Ability to navigate ambiguity and complexity, manage a queue of strategic priorities, and handle multiple assessments concurrently.
- Drive for continuous learning and willingness to embrace a steep learning curve.
- Excellent organization and project management skills in a fast-moving and demanding environment.
Nice to haves
- Experience in FinTech, TradFi, consulting, technical program management, or other customer-facing disciplines.
- Strong knowledge of risk/control issues related to evolving technology (crypto, mobile, cloud, data lakes, machine learning).
- Certifications (optional): CRISC, CISA, CISSP, CISM, FAIR.
- Coding knowledge (helpful for data joins, GRC integrations, and data visualization) — a plus but not required.
- Demonstrated beginner/intermediate knowledge of crypto/blockchain/web3.
Benefits
- Full-time offers include bonus eligibility, equity eligibility, and benefits (medical, dental, vision, 401(k)).
- Medical, dental, and vision plans with generous employee contributions.
- Health Savings Account with company contributions.
- Disability and life insurance.
- 401(k) plan with company match.
- Wellness stipend, mobile/internet reimbursement, connections stipend, volunteer time off, fertility counseling and benefits.
- Generous time off/leave policy and the option of getting paid in digital currency.
Additional details
- Position ID: P69486
- Location / Work model: remote-first (in-person participation required throughout the year). #LI-Remote
- Pay Range (target annual salary): $193,970 — $228,200 USD (full-time offers also include bonus + equity + benefits).