Ready to be pushed beyond what you think you’re capable of?
At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.
To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems.
Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be.
While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.
Team Paragraph:
Join Coinbase's Internal Audit team as an IT Manager and own end-to-end delivery of complex IT and security audits across our cloud infrastructure, security operations, and crypto-native systems. We're looking for someone who brings hands-on experience with modern cloud infrastructure, security operations, and AI-enabled workflows, ideally from a fast-paced, engineering-driven environment. Reporting to the IT Audit Senior Manager, you'll shape how we audit and drive continuous modernization of our approach. This role requires deep technical credibility, strong EQ to partner effectively across Engineering and Security, and a genuine AI-forward mindset.
What you’ll be doing (ie. job duties)
- Own end-to-end delivery of IT and security audits, from risk assessment and scoping through planning, fieldwork, testing, reporting, and issue validation—covering cloud infrastructure (AWS, GCP), security operations, identity and access management, data protection, IT asset management, vendor/third-party risk, and key in-scope products and services including blockchain infrastructure, centralized and self-hosted wallets, and cold storage.
- Drive AI-enabled audit execution, designing and implementing data analytics, automation, and Generative AI solutions to modernize how we audit (e.g., continuous monitoring, anomaly detection, automated evidence retrieval, AI-assisted workpaper drafting)—while maintaining rigorous human-in-the-loop validation to ensure accuracy and audit-quality conclusions.
- Execute audits aligned with the multi-year IT and security audit roadmap, coordinating coverage with co-sourced partners and cross-functional risk initiatives while ensuring alignment with Coinbase's enterprise risk profile, technology strategy, and regulatory expectations across regions (US, EMEA, APAC).
- Drive high-quality, risk-based findings and executive-level reporting, distilling key themes, emerging risks, and root causes into clear, concise materials for senior management and the Chief Audit Executive—ensuring findings are appropriately documented and supported by evidence.
- Partner with technology and security leadership across Engineering, Security, Infrastructure, Product, and Operations to build trusted relationships, challenge control design, and advise on pragmatic, risk-based, scalable remediation while maintaining third-line independence.
- Drive disciplined issue management, ensuring timely, risk-based remediation by management, high-quality root cause analysis, and validation of remediation activities—escalating delays or thematic concerns to senior leadership as needed.
- Evaluate and develop talent, assessing candidates and helping build a high-performing, technically credible audit team.
What we look for in you (ie. job requirements):
- 7+ years of experience in IT/security internal audit, technology risk, or first-line security/engineering roles with significant controls exposure.
- Experience working in a fast-paced, cloud-native, or engineering-driven environment where technology and security practices evolve rapidly.
- Hands-on audit experience with cloud platforms (AWS, GCP), including IAM policies, security configurations, logging/monitoring, and CI/CD pipelines. You've done real IT and security testing, not just controls walkthroughs.
- AI-forward mindset with demonstrated experience applying Python, SQL, or AI tools to audit or security work, building workflows rather than just prompting. We will probe deeply on this.
- Relevant professional certifications (e.g., CISA, CISSP, CIA, CISM) required; CPA or CFE a plus.
- Working knowledge of key frameworks such as NIST CSF, COBIT, SOC 2, and ITIL
- High EQ and collaborative style. You build trusted relationships with technical stakeholders, bring strong interpersonal skills, and can challenge effectively without creating friction.
- Proven ability to translate complex technical findings into clear, executive-ready narratives for both technical and non-technical audiences.
- Ability to manage multiple audits and initiatives across time zones (EMEA, APAC) with minimal oversight.
- Demonstrated leadership and team‑development experience, including mentoring, coaching, and managing direct reports.
- Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human-in-the-loop practices to deliver business-ready outputs and drive measurable improvements in efficiency, cost, and quality.
Nice to haves
- Experience auditing or building blockchain infrastructure, crypto custody, or wallet systems (hot/cold storage).
- Background in a high-growth or rapidly scaling environment with complex, evolving technology stacks.
- Experience with GRC platforms (Workiva, Archer, AuditBoard) or building custom audit automation tooling.
- Familiarity with DORA, MiCA, or crypto-specific regulatory frameworks.
Location: Remote-first = can work remotely or in office at your discretion but must reside in US
P76564
Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)).
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal OpportunityCoinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here).
Global Data Privacy Notice for Job Candidates and ApplicantsDepending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here.
AI DisclosureFor select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description.
For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate.
The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
Top Skills
Similar Jobs at Coinbase
What you need to know about the Boston Tech Scene
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories


.png)