As an Internal Audit IT Manager, you'll join the Internal Audit team and own a portfolio of complex IT and security audits across Coinbase's global cloud infrastructure, security operations, and crypto-native products. This team delivers independent, third-line assurance over technology, information security, and IT governance, helping Coinbase protect customers and maintain trust at scale. .
You'll shape audit coverage, ensure that findings from complex audit work are communicated appropriately to executive and Board-level audiences, and lead team members to build a best-in-class IT audit function.
- Own and coordinate a portfolio of IT and security audits covering cloud infrastructure (AWS, GCP), application security, identity and access management, vendor/third-party risk, and blockchain-related products including wallets and cold storage.
- Shape the execution of the multi-year IT and security audit roadmap, coordinating coverage with co-sourced partners and aligning with enterprise risk initiatives.
- Synthesize complex audit findings into high-impact reports and presentations for executive leadership, the Chief Audit Executive, and the Audit Committee, ensuring conclusions are rigorous and actionable.
- Drive remediation strategy for IT and security findings, challenging management on risk-based solutions, validating corrective actions, and escalating thematic concerns to senior leadership.
- Partner with senior technology and security leadership across Engineering, Security, and IT to deliver independent advisory value while maintaining third-line independence and objectivity.
- Evaluate and develop audit talent, mentoring team members, assessing candidates, and contributing to the growth and modernization of the Internal Audit function.
- 8+ years of experience in IT internal audit, information security audit, or first-line technology/security operations, with demonstrated experience managing audit teams, processes, and co-sourced engagements.
- Hands-on audit experience with cloud platforms (AWS, GCP), including IAM policies, security configurations, encryption, logging, and network architecture.
- Relevant professional certifications (e.g., CISA, CISSP, CIA, or CISM) required; working knowledge of frameworks such as NIST CSF, COBIT, SOC 2, and ITIL.
- Proven ability to manage multiple concurrent audits and initiatives across time zones (EMEA, APAC), presenting findings and recommendations to executive and Board-level audiences.
- Experience in crypto, blockchain infrastructure, or financial services audit environments.