Security Compliance Analyst, Coinbase

$131.3-154.5k

+ Target bonus + Target equity

Mid and Senior level
Remote in US
Coinbase

The world’s leading exchange for digital currencies

Open for applications

Coinbase

The world’s leading exchange for digital currencies

1001+ employees

FintechB2CB2BCryptocurrencySaaS

Open for applications

$131.3-154.5k

+ Target bonus + Target equity

Mid and Senior level
Remote in US

1001+ employees

FintechB2CB2BCryptocurrencySaaS

Company mission

Their mission is to create an open financial system for the world and to be the leading global brand for helping people convert digital currency into and out of their local currency.

Role

Who you are

  • 4+ years of security, IT compliance (internal or external audit) or equivalent experience
  • Hands-on experience with implementing, reviewing or auditing security frameworks such as SOC 2, NIST, ISO
  • Prior experience at a Big 4 or consulting experience in Cybersecurity
  • Prior experience working closely with auditors and/or external regulators
  • Experience with compliance initiatives from start to finish
  • Experience sourcing, interpreting, and reporting on data via data visualization tools
  • Outstanding written and spoken communication skills
  • Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with light supervision
  • Ability to multitask, prioritize work, and meet deadlines in a fast paced environment
  • Focus on precision and accuracy, and the drive to clarify ambiguity
  • You’ve got positive energy. You’re optimistic about the future and determined to get there
  • You’re never tired of learning. You want to be a pro in bleeding edge tech like DeFi, NFTs, DAOs, and Web 3.0
  • You appreciate direct communication. You’re both an active communicator and an eager listener - because let’s face it, you can’t have one without the other. You’re cool with candid feedback and see every setback as an opportunity to grow
  • You can pivot on the fly. Crypto is constantly evolving, so our priorities do, too. What you worked on last month may not be what you work on today, and that excites you. You’re not looking for a boring job
  • You have a “can do” attitude. Our teams create high-quality work on quick timelines. Owning a problem doesn’t scare you, but rather empowers you to take 100% responsibility for achieving our mission
  • You want to be part of a winning team. We’re stronger together, and you’re a person who embraces being pushed out of your comfort zone

Desirable

  • FinTech, TradFi, consulting, business operations technical program management or other customer-facing disciplines
  • Security certifications e.g. CISA, CISSP, CISM or other relevant certifications
  • Experience mapping common controls across multiple frameworks in a GRC tool
  • Financial services or financial regulatory experience
  • Experience building a risk/controls aligned to a standards framework
  • Demonstrated beginner/intermediate knowledge of crypto/blockchain/web3
  • Strong knowledge of risk/control issues in relation to evolving technology (e.g., mobile, cloud, data lakes, machine learning)
  • Willingness to embrace stretch opportunities to learn new skills and work on net new projects where you have no previous experience

What the job involves

  • The Security Compliance Analyst will sit within the Security Compliance (SecCom) team, one of several sub teams within the larger Security Governance, Risk and Compliance org
  • SecCom builds and operates various programs aimed at documenting, communicating, testing / validating IT controls and related requirements in partnership with 1LOD control owners
  • SecCom facilitates audit initiatives from both internal and external audit partners and reports out on the state of our control environment
  • This role will contribute to the newly chartered ‘Continuous Control Monitoring’ program which is aimed at enabling continuous, automated testing of control operations
  • Partner with SecCom security partners to index on CB security control objectives and index all affiliated control implementations to define related control monitoring objectives, by control and control implementation target
  • Identify various control implementation owners and partner with the aforementioned DRI’s to assess each implementation for expected operating thresholds to produce meaningful monitoring objectives which would indicate both a control implementation’s design and operating effectiveness
  • Partner with control implementation owners to generate control monitoring design documentation
  • Partner with data engineers to drive development of control monitors
  • Assist with development of process and training content to enable control owners to self-execute much of the above
  • Lead and perform security control gap assessments against industry standards and security regulatory requirements to evaluate control design and operating effectiveness,
  • Define, draft and communicate potential security control improvement opportunities and paths to address based on requirements and industry experience,
  • Support regulatory examinations across both U.S. and international regulatory regimes in partnership with Security and other GRC functions by reviewing and evaluating requests, coordinating with XFN stakeholders to collect and QA artifacts, and track outcomes of regulatory examinations performed,
  • Partner with Security Risk and Security Policy functions to ensure that security controls are reflected properly in our Security Risk Review, Security Policy requirements, and other governance processes,
  • Support Security Compliance, Information Security, and Engineering stakeholders in identifying and executing on continuous control monitoring opportunities,
  • Work closely with control owners and internal and external auditors on control operation and related documentation
  • Communicate progress, escalations, and issue resolutions to management and team stakeholders
  • Create procedural documentation, including training materials that support how we support control owners in risk to control analysis, control narratives, and how we operate as a Security Compliance team in the form of runbooks for new processes

Our take

Coinbase allows its users to create their own crypto wallets and start buying or selling cryptocurrencies by connecting with their bank accounts. It also provides a series of merchant payment processing systems and tools that support transactions with many popular websites.

Coinbase has recently made a big push to broaden its services away from consumers and they want to cater services from institutional investors.

Coinbase currently offers one of the largest selection of cryptocurrency assets - over 10,000 but does not allow trading on all of them. The company wisely keeps such offerings to the most stable assets however, the list is always expanding. Coinbase see a much wider adoption of cryptocurrency and tokens in the future, and plan to expand potentially to millions in the future. It speaks volumes to Coinbase's goals of wider global adoption that former UK Finance Minister George Osborne is now an Advisor at the company.

Coinbase's lofty ambitions paid off in it being the first crypto listing on the NASDAQ. The company has weathered several bull and bear runs in the cryptocurrency industry through diversification of its offerings, including wallet-as-a-service technology for crypto platforms, and has acquired healthy coffers of cryptocurrency assets. The aim is to eventually operate independently of the volatility surrounding cryptocurrencies.

Freddie headshot

Freddie

Company Specialist

Insights

Led by a woman
Top investors

Some candidates hear
back within 2 weeks

-24% employee growth in 12 months

Company

Funding (last 2 of 8 rounds)

Oct 2018

$300m

GROWTH EQUITY VC

Oct 2018

$108.1m

SERIES D

Total funding: $633.4m

Company benefits

  • 12 weeks maternity/paternity leave
  • Vision and dental care
  • Commuter benefits
  • Learning and development budget
  • Unlimited paid time off policy
  • Work from home opportunities
  • Health insurance

Company values

  • Clear Communication - Share information efficiently, improving collaboration and productivity. Practice active listening while. Being candid and kind
  • Positive Energy - Be optimistic about the future and determined to get there. Co-create solutions and work together to get there
  • Continuous Learning - We view every situation as an opportunity to learn, We value giving and receiving regular feedback
  • Efficient Execution - We complete high quality work quickly by working smarter, not harder. We prefer automation over manual work
  • Act like an owner: We take 100% responsibility for achieving the mission. We seek to improve all aspects of our company even in ways that are not explicitly part of our job. We run through brick walls.
  • Customer focus: We are deeply focused on solving our customers’ problems with technology, by enabling them to acquire, store and use crypto. We strive to be the easiest to use, most trusted and most secure platform. In every decision we make, we ask, “How does this create more value for our customers?”
  • Repeatable innovation: We are builders, leveraging technology to improve the world, constantly shipping ideas vs just discussing them. We know that companies must continually reinvent themselves to avoid stagnation. We have a high tolerance for failure, investing 10% of our resources in venture bets that are uncomfortably ambitious

Company HQ

Civic Center, New York, NY

Articles

Leadership

Previously founded UniversityTutor.com, also worked as a Software Engineer at AirBnb

Previously held various head positions, including VP at GE Healthcare, Director at Merrill Lynch and CFO at CIT Bank and Oz Management


People progressing

Joined as a Compliance Analyst, promoted to Compliance Partnerships Senior Associate in 15 months. 2 promotions later, she is now a Financial Crimes & Compliance Manager.

Share this job

View 162 more jobs at Coinbase