Portfolio Jobs

Polychain Capital
Polychain Capital
Create a profile to get alerted when relevant jobs to you are posted by our network.

Security Risk Specialist



United States · Remote
Posted on Thursday, June 20, 2024

At Coinbase, our mission is to increase economic freedom around the world, and we couldn’t do this without hiring the best people. We’re a group of hard-working overachievers who are deeply focused on building the future of finance and Web3 for our users across the globe, whether they’re trading, storing, staking or using crypto. Know those people who always lead the group project? That’s us.

There are a few things we look for across all hires we make at Coinbase, regardless of role or team. First, we look for candidates who will thrive in a culture like ours, where we default to trust, embrace feedback, and disrupt ourselves. Second, we expect all employees to commit to our mission-focused approach to our work. Finally, we seek people who are excited to learn about and live crypto, because those are the folks who enjoy the intense moments in our sprint and recharge work culture. We’re a remote-first company looking to hire the absolute best talent all over the world.

Ready to #LiveCrypto? Who you are:

  • You’ve got positive energy. You’re optimistic about the future and determined to get there.
  • You’re never tired of learning. You want to be a pro in bleeding edge tech like DeFi, NFTs, DAOs, and Web 3.0.
  • You appreciate direct communication. You’re both an active communicator and an eager listener - because let’s face it, you can’t have one without the other. You’re cool with candid feedback and see every setback as an opportunity to grow.
  • You can pivot on the fly. Crypto is constantly evolving, so our priorities do, too. What you worked on last month may not be what you work on today, and that excites you. You’re not looking for a boring job.
  • You have a “can do” attitude. Our teams create high-quality work on quick timelines. Owning a problem doesn’t scare you, but rather empowers you to take 100% responsibility for achieving our mission.
  • You want to be part of a winning team. We’re stronger together, and you’re a person who embraces being pushed out of your comfort zone.

Coinbase is looking for an experienced Security Risk Management Specialist to join the team. The Security Risk Specialist will help steer the security risk management program, enabling all security and privacy teams to manage and drive decision making about security risks. As the Security Risk Management Specialist, you hold domain expertise in security risk management standards and frameworks, especially quantitative risk frameworks, and will make these applicable and usable for fast-moving technical teams.

What you’ll be doing (ie. job duties)

  • Analysis of multiple variables, including but not limited to, threat intelligence and risks, to inform threat models/risk scoring methodologies.
  • Assessments: Facilitate technical security risk assessments across our production and corporate environments, enabling security and privacy teams to describe risk in both qualitative and quantitative terms
  • Maintain the Security Risk Register data: quality control of data, tooling support and automation/process improvements
  • Manage security risks via the risk lifecycle:
    • Intake to the risk register, triage, residual risk calculation, and analysis with subject matter experts and risk owners
    • Facilitate agreement and execution of mitigation plans across stakeholders
    • Enable teams and leadership to risk-based decisions and trade-offs impacting, security investment strategies and project prioritization
    • Document and monitor risk treatment decisions to accept or remediate risks
    • Support reporting out on findings, metrics, and recommend mitigations to security and business leadership
    • Ad-hoc meeting planning support for risk meetings with security leadership and business risk owners
  • Communications/Training: Develop/maintain communication/training plans to roll out the security risk program across the organization
  • Global Engagement: Collaborate with stakeholders to help scale the program’s risk framework across Coinbase entities, products, and geographies/markets
  • Enterprise Risk: Work in lockstep with Enterprise Risk Management to escalate risks the enterprise risk register and report relevant metrics to senior leadership
  • Legal: Regularly collaborate with GRCP teams, Legal and Compliance for risks, assessments, and reporting to meet regulatory requirements
  • Audits: support data compilation to respond to US and international audit/regulator inquiries
  • Industry pulse: Maintain awareness of international regulation, emerging threats, forecasts, policies, and benchmarks
  • Maintain team runbooks, team intra-web pages, and risk register metrics dashboards

What we look for in you (ie. job requirements):

  • 2-3+ years of experience working in Security Risk and/or GRCP/Compliance
  • Security Risk domain knowledge: security and cyber security risks, standards and frameworks i.e. ISO 27001/5, NIST CSF, FAIR risk quant methodology, etc.
  • Experience with controls/risk management frameworks to measure controls/risks, monitor controls/risks, and validating/racking/evidencing remediation
  • Ability to dig into technical risk solutions and to work on technical quantitative risk assessments
  • Comfortable working with GRCP tools e.g. Jira, Archer etc. and quant and qualitative data analytics
  • Ability to translate controls/risk standards out of compliance speak and into functional requirements
  • Knowledge of risk/control best practices and knowledge of major regulatory/legal frameworks (US/international)
  • Clear/concise communicator and writer; experience drafting/operationalizing project plans across stakeholders, holding teams accountable, and deliverables
  • Ability to manage a queue against strategic priorities and shows expertise in being able to handle multiple assessments at a time
  • You are willing to learn and apply processes unique to the challenges at Coinbase
  • You are comfortable operating on an unpaved road and dealing with ambiguity
  • Excellent organization and project management skills in a fast-moving and demanding environment
  • Willingness to embrace a steep learning curve and stretch opportunities to learn new skills

Nice to haves:

  • FinTech, TradFi, consulting, business operations technical program management or other customer-facing disciplines
  • Strong knowledge of risk/control issues in relation to evolving technology (e.g., mobile, cloud, data lakes, machine learning)
  • Security Risk: a certification is a plus, but not a requirement: information security risk management qualifications like CISA, CISSP, CISM, and FAIR.
  • Coding knowledge a plus, but not a requirement e.g. learn to build data joins / integrations with GRCP tools and/or input requirements into tooling design plans
  • Experience building risk/controls aligned to a standards framework
  • Demonstrated beginner/intermediate knowledge of crypto/blockchain/web3

PID#: P60084

Pay Transparency Notice: Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include target bonus + benefits (including medical, dental, vision and 401(k)).

Pay Range:
$113,900$134,000 USD

Commitment to Equal Opportunity

Coinbase is committed to diversity in its workforce and is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Know Your Rights notice here. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law.

Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here).

Global Data Privacy Notice for Job Candidates and Applicants

Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here.