About the company
Coinbase is one of the most trusted cryptocurrency exchanges today. It secures cash on FDIC-secured accounts, lets you securely connect and trade crypto via your bank account, and blocks suspicious accounts to ensure user safety
Job Summary
What you’ll be doing (ie. job duties):
📍Develop and execute on a vision what pentesting, bug bounty and red teaming at Coinbase should look like over the years ahead. 📍Develop and track metrics and OKRs to track pentesting work, bug bounty engagements, new security capability development, etc. 📍Lead internal and external pentesting as a service. 📍Own DAST and MAST as an internal security service offering. 📍Lead a team of Security Engineers focusing on performing tightly-scoped, new product launch pentests, regulatory and compliance-driven pentests, and managing Coinbase’s public bug bounty program. 📍Work with engineers and engineering leaders across the company to prioritize, implement and deploy fixes for known vulnerabilities. 📍Partner with Legal and GRCP to ensure we continue to meet regulatory and compliance-related pentesting requirements. 📍Provide on-call and product incident support.
What we look for in you (ie. job requirements):
📍A Bachelor’s or Master’s degree in Computer Science, Computer Engineering or a related field. 📍3+ years of management experience, preferably managing a security team of 5 or more full time employees. 📍3+ years of leading internal and external pentest engagements, actively participating in bug bounty programs, or performing security reviews. 📍Expertise in Web2, Web3 and Network security. 📍Experience in responsible vuln disclosure. 📍Ability to navigate through ambiguity and deliver results fast. 📍A growth mindset, able to quickly iterate on stakeholder feedback and lead change to meet the evolving needs of the business. 📍Ability to partner effectively with cross-functional stakeholders across various teams within a large organization. 📍Passion for the work that you do and ability to be hands-on when needed – participating in on-call rotations, leading incidents, performing pentests, validating bug bounty reports, verifying vuln fixes, etc.
The crypto industry is evolving rapidly, offering new opportunities in blockchain, web3, and remote crypto roles — don’t miss your chance to be part of it.