Description
Ready to be pushed beyond what you think you’re capable of?
At Coinbase, our mission is to increase economic freedom in the world.
We’re seeking a very specific candidate who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system.
As an Internal Audit IT Manager, you will own end-to-end delivery of complex IT and security audits across our cloud infrastructure, security operations, and crypto-native systems.
Key responsibilities include:
- Owning end-to-end delivery of IT and security audits, from risk assessment and scoping through planning, fieldwork, testing, reporting, and issue validation,covering cloud infrastructure (AWS, GCP), security operations, identity and access management, data protection, IT asset management, vendor/third-party risk, and key in-scope products and services including blockchain infrastructure, centralized and self-hosted wallets, and cold storage.
- Driving AI-enabled audit execution, designing and implementing data analytics, automation, and Generative AI solutions to modernize how we audit (e.g., continuous monitoring, anomaly detection, automated evidence retrieval, AI-assisted workpaper drafting),while maintaining rigorous human-in-the-loop validation to ensure accuracy and audit-quality conclusions.
- Executing audits aligned with the multi-year IT and security audit roadmap, coordinating coverage with co-sourced partners and cross-functional risk initiatives while ensuring alignment with Coinbase's enterprise risk profile, technology strategy, and regulatory expectations across regions (US, EMEA, APAC).
- Driving high-quality, risk-based findings and executive-level reporting, distilling key themes, emerging risks, and root causes into clear, concise materials for senior management and the Chief Audit Executive,ensuring findings are appropriately documented and supported by evidence.
- Partnering with technology and security leadership across Engineering, Security, Infrastructure, Product, and Operations to build trusted relationships, challenge control design, and advise on pragmatic, risk-based, scalable remediation while maintaining third-line independence.
- Driving disciplined issue management, ensuring timely, risk-based remediation by management, high-quality root cause analysis, and validation of remediation activities,escalating delays or thematic concerns to senior leadership as needed.
- Evaluating and developing talent, assessing candidates and helping build a high-performing, technically credible audit team.
Requirements include:
- 7+ years of experience in IT/security internal audit, technology risk, or first-line security/engineering roles with significant controls exposure.
- Experience working in a fast-paced, cloud-native, or engineering-driven environment where technology and security practices evolve rapidly.
- Hands-on audit experience with cloud platforms (AWS, GCP), including IAM policies, security configurations, logging/monitoring, and CI/CD pipelines.
- AI-forward mindset with demonstrated experience applying Python, SQL, or AI tools to audit or security work, building workflows rather than just prompting.
- Relevant professional certifications (e.g., CISA, CISSP, CIA, CISM) required; CPA or CFE a plus.
- Working knowledge of key frameworks such as NIST CSF, COBIT, SOC 2, and ITIL.
- High EQ and collaborative style.
- Proven ability to translate complex technical findings into clear, executive-ready narratives for both technical and non-technical audiences.
- Ability to manage multiple audits and initiatives across time zones (EMEA, APAC) with minimal oversight.
- Demonstrated leadership and team-development experience, including mentoring, coaching, and managing direct reports.
- Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human-in-the-loop practices to deliver business-ready outputs and drive measurable improvements in efficiency, cost, and quality.
Nice to have:
- Experience auditing or building blockchain infrastructure, crypto custody, or wallet systems (hot/cold storage).
- Background in a high-growth or rapidly scaling environment with complex, evolving technology stacks.
- Experience with GRC platforms (Workiva, Archer, AuditBoard) or building custom audit automation tooling.
- Familiarity with DORA, MiCA, or crypto-specific regulatory frameworks.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/coinbase/jobs/7755116