Coinbase
Senior Manager, Security Audit
financefull-timeRemote - USA
SALARY
Not listed
WORK TYPE
hybrid
JOB TYPE
full-time
INDUSTRY
crypto
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
About the Role
Coinbase is looking for a Senior Manager, Security Audit to lead the Internal Audit team's global coverage of information security, cybersecurity, and infrastructure/application security. Reporting to the Global Head of Internal Audit, you will own the security audit portfolio, spanning identity and access management, threat detection, incident response, cloud security, application security, and crypto-native controls (wallets, cold storage, key management), while managing a small team and carrying your own book of complex audits.
What you'll do:
- Own and lead Coinbase's global security audit portfolio covering IAM, threat detection, incident response, security architecture, cryptography/key management, vulnerability management, application security, and crypto-native security (wallets, cold storage), third-party/outsourced security oversight.
- Partner with Security Engineering, Detection & Response, and AppSec teams as the cybersecurity subject matter expert, providing independent audit perspective and advisory value while maintaining third-line objectivity.
- Manage and develop a team of security auditors while personally leading high-complexity, high-risk security engagements across multiple jurisdictions.
- Synthesize complex technical security findings into clear, risk-prioritized reports for executive leadership, the Audit Committee, and the Board.
- Drive proactive identification of emerging threats, including crypto/blockchain attack vectors, AI/ML security risks, and supply chain risks, adjusting audit coverage and methodology accordingly.
- Champion security data analytics and AI tooling (e.g., automated log/evidence analysis) to modernize the security audit function.
Required Skills and Experience:
- 12+ years in internal audit or security engineering/operations with demonstrated leadership of cybersecurity-focused audits or security programs, including direct team management while carrying an individual portfolio.
- Deep, hands-on expertise in at least 2-3 of: IAM, threat detection/SOC, incident response, security architecture, cryptography/key management, cloud security (AWS/GCP), or application security.
- Relevant security certification required: CISSP, CISM, CCSP, or CCSK (CISA a plus).
- Proven ability to navigate multi-jurisdictional cybersecurity regulatory regimes (NYDFS, SOC frameworks, OCC guidance, multi-state examiner requirements) and translate requirements into audit coverage.
- Demonstrated success communicating deeply technical security concepts to executive and Board-level audiences through written reports and presentations.
- Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply