Senior Analyst, Cloud Security Compliance
Remote - USA
We’re Coinbase. We’re the world’s most trusted way to join the crypto revolution, serving more than 89 million accounts in more than 100 countries.
Our mission is to increase economic freedom around the world, and we couldn’t do this without hiring the best people. We’re a group of hard-working overachievers who are deeply focused on building the future of finance and Web 3.0 for our users across the globe, whether they’re trading, storing, staking or using crypto. Know those people who always lead the group project? That’s us.
There are a few things we look for across all hires we make at Coinbase, regardless of role or team. First, we look for candidates who will thrive in a culture like ours, where we default to trust, embrace feedback, and disrupt ourselves. Second, we expect all employees to commit to our mission-focused approach to our work. Finally, we seek people who are excited to learn about and live crypto, because those are the folks who enjoy the intense moments in our sprint and recharge work culture. We’re a remote-first company looking to hire the absolute best talent all over the world.
Ready to #LiveCrypto? Who you are:
- You’ve got positive energy. You’re optimistic about the future and determined to get there.
- You’re never tired of learning. You want to be a pro in bleeding edge tech like DeFi, NFTs, DAOs, and Web 3.0.
- You appreciate direct communication. You’re both an active communicator and an eager listener - because let’s face it, you can’t have one without the other. You’re cool with candid feedback and see every setback as an opportunity to grow.
- You can pivot on the fly. Crypto is constantly evolving, so our priorities do, too. What you worked on last month may not be what you work on today, and that excites you. You’re not looking for a boring job.
- You have a “can do” attitude. Our teams create high-quality work on quick timelines. Owning a problem doesn’t scare you, but rather empowers you to take 100% responsibility for achieving our mission.
- You want to be part of a winning team. We’re stronger together, and you’re a person who embraces being pushed out of your comfort zone.
Coinbase stores more digital currency than any company in the world, making us a top tier target on the internet. Security is core to our mission and has been a key competitive differentiator for us as we scale worldwide. Essential to scaling is building and running a security compliance program that reflects how we protect the data and assets in our care, to open the doors with customers, regulators, auditors, and other external stakeholders. If you love working with fast moving companies to build security compliance engines from the ground up and create positive change across the business, we’d like to speak with you about joining our team.
Coinbase is looking for a security compliance senior analyst to help drive and implement the security compliance roadmap and collaborate with teams across the company to understand and meet our security requirements.
What you’ll be doing (ie. job duties):
- Work cross functionally with Security, IT, Infrastructure, Engineering, Data, and Finance to advise over security best practices and provide guidance on SOC 2, ICFR controls as well as financial services regulatory reporting requirements
- Perform assessments of Security and IT control environment for new products, services or entities, tracking remediation efforts to completion, and facilitating audits of the same by external auditors
- Contribute to control management strategy which, once operationalized, will enable ongoing analysis of control design and operating effectiveness, identifying and analyzing gaps, producing meaningful remediation plans, and tracking implementation of control remediation to completion
- Assist with planning and implementation of automation for control testing and related evidence collection
- Work closely with internal and external auditors to educate them on the technology and control environment, and operate as a liaison between auditors and control owners during key audit initiatives. Will include coordinating key activities spanning documentation requests, walkthroughs, testing, progress reporting and audit close/reporting
- Track and document progress, escalations, and issue resolution for communication to management and team stakeholders
- Coordinate with Engineering partners to learn about the platforms and services that support and enable our cloud product catalog, and produce technical write-ups on their design and operation
- Build relationships with a broad range of Coinbase employees at all levels to accomplish program objectives and further Coinbase Security GRC goals
- Identify and drive process improvements for streamlining Security Compliance operations, and work with your Security peers to define feedback loops across global security governance, risk, and compliance functions
What we look for in you (ie. job requirements):
- 5+ years of IT security or audit/compliance or equivalent experience
- Experience leading or facilitating SOC 1 & 2 or IT SOX audits of cloud environments (either as an auditor or compliance resource coordinating between auditors and control owners).
- Working knowledge of the range of security requirements articulated in industry leading security frameworks like CSA CCM, NIST CSF/800-53, ISO 27001/2, PCI or CIS Top 20, including how they operate and extend into cloud environments.
- Working knowledge of cloud technologies/ecosystems (AWS and GCP preferred).
- Working knowledge of core CI/CD concepts, how it contrasts with legacy development models and the tools commonly employed within a DevOps program.
- Prior experience working closely with auditors and/or external regulators
- Experience leading compliance initiatives from start to finish
- Outstanding written and spoken communication skills
- Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision
- Ability to multitask, prioritize work and meet deadlines in a fast paced environment
- Focus on precision and accuracy, and the drive to clarify ambiguity
Nice to haves:
- Hands-on experience interacting with cloud ecosystems (e.g., AWS) via console or CLI interfaces
- BA or BS in a technical field or equivalent experience
- Prior experience at a big 4 accounting firm
- Security certifications e.g. CISA, CISSP, CISM or other relevant certifications
- Experience mapping common controls across multiple frameworks in a GRC tool
- Prior experience automating audit evidence collection
- Financial services experience
Notice for Colorado applicants as required by sb19-085 (8-5-20). Target annual salary for this role performed in Colorado, is $162,350 + target bonus + target equity + benefits (including medical, dental, vision and 401(k)).
Please note that for employees based in the US, Philippines, Canada or Singapore, if your role requires you to be present in a Coinbase office or if you choose to be physically present in a Coinbase office or sponsored location, you will be required to be fully vaccinated from COVID-19 (as defined by applicable law). If you receive an offer, you will receive additional information about the grounds and process for an exemption.
Commitment to Equal Opportunity
Coinbase is committed to diversity in its workforce and is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view Pay Transparency, Employee Rights and Equal Employment Opportunity is the Law notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to accommodations[at]coinbase.com and let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here).
Global Data Privacy Notice for Job Candidates and Applicants
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required.
Other jobs like this
Senior Azure Cloud Security EngineerAnsible Automation AWS Azure CircleCI DevOps Docker Encryption GCP Incident response +9
401(k) matching Career development Equity Flex hours Flex vacation +6
Staff Cloud Security Engineer (Remote- North America)Automation AWS Azure CEH CISA Cloudflare FedRAMP GCP ISO 27001 Kubernetes +2
Career development Competitive pay Flex hours Flex vacation Parental leave +3
Explore more Cyber Security career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.
- Open Cyber Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Penetration Tester jobs
- Open Senior DevSecOps Engineer jobs
- Open Application Security Engineer/Architect jobs
- Open Senior Security Operations Engineer jobs
- Open Cyber Threat Intelligence Analyst jobs
- Open Staff Security Engineer jobs
- Open Head of Information Security jobs
- Open Lead Security Engineer jobs
- Open SOC Analyst jobs
- Open Cyber Security Analyst jobs
- Open Information System Security Officer (ISSO) jobs
- Open Cybersecurity Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Sr. Security Engineer jobs
- Open Cloud Security Automation Specialist jobs
- Open Senior Threat Intelligence Analyst jobs
- Open Offensive Security Engineer jobs
- Open Information Security Officer jobs
- Open Cloud Security Operations Lead jobs
- Open Azure Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open DevOps-related jobs
- Open Application security-related jobs
- Open Analytics-related jobs
- Open Audits-related jobs
- Open PCI-related jobs
- Open OWASP-related jobs
- Open Threat intelligence-related jobs
- Open Clearance-related jobs
- Open Security assessments-related jobs
- Open IDS-related jobs
- Open Forensics-related jobs
- Open Splunk-related jobs
- Open Ruby-related jobs
- Open CEH-related jobs
- Open Encryption-related jobs
- Open CISM-related jobs
- Open GDPR-related jobs
- Open Agile-related jobs
- Open Open Source-related jobs
- Open Threat detection-related jobs
- Open OSCP-related jobs
- Open Intrusion detection-related jobs
- Open Machine Learning-related jobs
- Open DevSecOps-related jobs