Remote Jobs RockRemote Jobs Rock

Manager, GRC

๐Ÿ•’ 2 days ago
Technology RiskIT ControlsIT AuditCybersecurity Risk

๐Ÿ“œ Description

  • Lead second line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business.
  • Partner with engineering and technology teams to evaluate domain posture and identify where additional controls, remediation, or governance improvements are needed.
  • Review and challenge the design of new and existing risks and their corresponding controls to ensure mitigations are scalable and effective.
  • Drive coordination across risk, controls, policy, audit, and assurance teams to translate incidents and audit findings into actionable improvements.
  • Facilitate risk treatment decisions and validate execution of mitigation plans with subject matter experts and risk owners.
  • Build, grow, and coach a team of technology and security analysts, fostering a culture of agility and continuous performance feedback.

๐Ÿ› ๏ธ Requirements

  • 8+ years in technology risk, IT controls, IT audit, cybersecurity risk, or compliance, with hands-on experience delivering full-stack GRC services.
  • Deep understanding of technical design and governance principles across domains such as infrastructure resiliency, SDLC, change management, or incident response.
  • Hands-on experience evaluating risks and control design, identifying weaknesses, and partnering with stakeholders to improve risk outcomes.
  • Proven track record managing and mentoring analysts, growing their capabilities and careers.

โœจ Benefits

  • (medical
  • Dental
  • Vision
Full job description

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, itโ€™s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called โ€œsurges.โ€ learn more about working at Coinbase.

We're hiring a Manager, GRC to join our Technology Risk & Controls team within Security and lead second line of defense advisory coverage across critical technology and security domains. This team evaluates risk posture, improves control design, and helps engineering, infrastructure, and security leaders make better, risk-informed decisions. You'll both manage a team and directly own advisory coverage for domains that may include disaster recovery and resiliency, SDLC, artificial intelligence, identity and access management, and supply chain - building trusted partnerships that ensure Coinbase addresses its most critical risks in its most critical functions.

What you'll do:

  • Lead second line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business.
  • Partner with engineering and technology teams to evaluate domain posture and identify where additional controls, remediation, or governance improvements are needed.
  • Review and challenge the design of new and existing risks and their corresponding controls to ensure our mitigations are scalable, effective, and aligned to business, risk, and regulatory expectations.
  • Drive coordination across risk, controls, policy, audit, and assurance teams to translate incidents, audit findings, and regulatory expectations into actionable improvements that strengthen the technology control environment.
  • Intake, triage, and calculate inherent and residual risk with subject matter experts and risk owners, facilitating risk treatment decisions and validating execution of mitigation plans.
  • Enable leadership decision-making by communicating quantitative and qualitative risk tradeoffs and connecting risks, controls, policies, incidents, and findings into clear narratives that support prioritization and reporting.
  • Build, grow, and coach a team of technology and security analysts and senior analysts, fostering a culture of agility, innovation, and continuous performance feedback.

Required Skills and Experience:

  • 8+ years in technology risk, IT controls, IT audit, cybersecurity risk, or compliance, with hands-on experience delivering full-stack GRC services (risk management, control design, continuous monitoring, governance documentation) - not a controls-only or risk-only background.
  • Deep understanding of technical design and governance principles across one or more domains such as infrastructure resiliency, SDLC, change management, or incident response, with demonstrated ability to challenge status quo and drive improvement.
  • Hands-on experience evaluating risks and control design, identifying weaknesses, and partnering with stakeholders to improve risk outcomes and control maturity.
  • Proven track record managing and mentoring analysts, growing their capabilities and careers while holding teams accountable to deliverables and timelines.
  • Track record of influencing cross-functional stakeholders, navigating ambiguity, and translating complex risk and compliance concepts into clear functional requirements for both technical and non-technical audiences.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Position ID: P78170

#LI-Remote

Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)).

Annual base salary range (excluding equity and bonus):
$193,970-$228,200 USD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.
Stripe

Regional Security Manager, Americas

Stripe๐Ÿ‘ฅ 10,000+ employees๐Ÿข Technology, Information And Internet๐Ÿค B2B
๐Ÿ•’ 22 days ago

As Regional Security Manager Americas, you will lead and enhance physical security operations across North America and parts of Latin America, ensuring a safe environment for employees and visitors.

๐Ÿ“ ๐Ÿ‡บ๐Ÿ‡ธ San Francisco - Hybrid๐Ÿ’ฐ $172.6k - $258.8k / year๐Ÿ’ผ Full-Time๐ŸŽน Mid-level๐Ÿ“‹ Manager๐Ÿ“ข ๐Ÿ‡ช๐Ÿ‡ธ Spanish Required
Physical SecurityRisk ManagementIncident ResponseVendor Management
Abnormalsecurity

FedRamp Compliance Analyst

Abnormalsecurity๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Computer & Network Security
๐Ÿ•’ 5 days ago

Own and drive federal security and compliance workstreams, ensuring effective implementation and monitoring of FedRAMP High/Class D security requirements.

FedrampNIST SP 800-53Security ComplianceGRC
Zero-Hash

Technology & Cyber Risk Manager

Zero-Hash๐Ÿ‘ฅ 201 - 500 employees๐Ÿข Financial Services
๐Ÿ•’ 12 days ago

As a Technology & Cyber Risk Manager, you will lead the second-line technology and cyber risk function, assessing and challenging controls to protect zerohash's infrastructure and platforms.

Technology Risk ManagementCyber Risk ManagementInformation SecurityRisk Assessment
Binance

Open Source Intelligence Specialist

Binance๐Ÿ‘ฅ 5001 - 10,000 employees๐Ÿข Internet
๐Ÿ•’ 12 days ago

As an Open Source Intelligence Specialist, you will investigate corporate entities, conduct OSINT research, and assess risks to enhance the company's risk framework.

๐Ÿ“ ๐Ÿ‡ฆ๐Ÿ‡ช United Arab Emirates - Remote๐Ÿ’ผ Full-Time๐ŸŽน Mid-level๐ŸŽฒ Other๐Ÿ“ข ๐Ÿ‡ฌ๐Ÿ‡ง English Required๐Ÿ“ข ๐Ÿ‡จ๐Ÿ‡ณ Chinese Required
Open-source Intelligence (osint)Corporate Due DiligenceRisk AssessmentResearch Skills
OpenAI

Technical Threat Investigator, Threat Intel Engineering

OpenAI๐Ÿ‘ฅ 10,000+ employees๐Ÿข Research Services
๐Ÿ“… Apr 30

As a Technical Threat Investigator at OpenAI, you will help protect the company from sophisticated adversaries targeting OpenAI and the broader ecosystem, as well as those attempting to misuse our models in support of cyber operations.

Threat IntelligenceIncident ResponseOffensive SecurityAdversary Behavior

Trusted by Remote Workers