As an Internal Audit IT Associate Manager, you'll join the Internal Audit team and lead the execution of IT and security audits across Coinbase's global cloud infrastructure, security operations, and crypto-native products. This team delivers independent, third-line assurance over technology, information security, and IT governance, helping Coinbase protect customers and maintain trust at scale.
You'll own audits end-to-end, from planning through reporting, mentor junior team members supporting your engagements, and translate complex technical findings into clear, actionable insights for senior leadership.
- Own end-to-end execution of IT and security audits covering cloud infrastructure (AWS, GCP), application security, identity and access management, vendor/third-party risk, and blockchain-related products including wallets and cold storage.
- Lead audit planning, fieldwork, and stakeholder management, synthesizing findings into evidence-based reports and presentations for senior leadership and the Audit Committee.
- Direct and develop junior audit team members supporting your engagements, providing day-to-day guidance, reviewing workpapers, and coaching on technical and professional growth.
- Drive continuous monitoring and validation of remediated audit findings, tracking management responses and flagging delays or emerging risk themes.
- Partner with Engineering, Security, and IT leadership to identify control improvements and risk mitigation opportunities while preserving third-line independence and objectivity.
- Build and maintain a current understanding of IT, security, and financial services regulatory requirements to assess their impact on Coinbase's control environment.
- 6+ years of experience in IT internal audit, information security audit, or first-line technology/security operations, with at least 1 year managing audit processes and staff.
- Hands-on audit experience with cloud platforms (AWS, GCP), including IAM policies, security configurations, encryption, logging, and network architecture.
- Working knowledge of audit and security frameworks such as NIST CSF, COBIT, SOC 2, or ITIL, with relevant certifications (CISA, CISSP, CIA, or CISM) preferred.
- Proven ability to lead multiple concurrent audits across time zones and communicate technical findings clearly to both technical and non-technical stakeholders.
- Familiarity with crypto, blockchain infrastructure, or financial services audit environments.