Manager of GRC
Coinbase
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreAbout the role
Join Coinbase as a Manager of GRC, where you will lead second line of defense advisory coverage across critical technology and security domains. You will manage a team and directly own advisory coverage for domains such as disaster recovery, SDLC, artificial intelligence, identity and access management, and supply chain. Your role will involve assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business, as well as driving coordination across risk, controls, policy, audit, and assurance teams. You will also build, grow, and coach a team of technology and security analysts, fostering a culture of agility, innovation, and continuous performance feedback. Key missions: Lead second line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business.. Partner with engineering and technology teams to evaluate domain posture and identify where additional controls, remediation, or governance improvements are needed.. Build, grow, and coach a team of technology and security analysts and senior analysts, fostering a culture of agility, innovation, and continuous performance feedback. Profile: - Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality - Proven track record managing and mentoring analysts, growing their capabilities and careers while holding teams accountable to deliverables and timelines - 8+ years in technology risk, IT controls, IT audit, cybersecurity risk, or compliance, with hands-on experience delivering full-stack GRC services (risk management, control design, continuous monitoring, governance documentation) - not a controls-only or risk-only background - Track record of influencing cross-functional stakeholders, navigating ambiguity, and translating complex risk and compliance concepts into clear functional requirements for both technical and non-technical audiences - Hands-on experience evaluating risks and control design, identifying weaknesses, and partnering with stakeholders to improve risk outcomes and control maturity - Deep understanding of technical design and governance principles across one or more domains such as infrastructure resiliency, SDLC, change management, or incident response, with demonstrated ability to challenge status quo and drive improvement
Scraped 9/26/2026