Security Compliance Analyst

July 12

Apply Now
Logo of Coinbase

Coinbase

We're building an open financial system for the world.

Digital Currency • Software • Payment Processing • Bitcoin • Technology

1001 - 5000

💰 $21.4M Post-IPO Equity on 2022-11

Description

• Partner with SecCom security partners to index on CB security control objectives and index all affiliated control implementations to define related control monitoring objectives, by control and control implementation target • Identify various control implementation owners and partner with the aforementioned DRI’s to assess each implementation for expected operating thresholds to produce meaningful monitoring objectives which would indicate both a control implementation’s design and operating effectiveness • Partner with control implementation owners to generate control monitoring design documentation • Partner with data engineers to drive development of control monitors • Assist with development of process and training content to enable control owners to self-execute much of the above • Lead and perform security control gap assessments against industry standards and security regulatory requirements to evaluate control design and operating effectiveness • Define, draft and communicate potential security control improvement opportunities and paths to address based on requirements and industry experience • Support regulatory examinations across both U.S. and international regulatory regimes in partnership with Security and other GRC functions by reviewing and evaluating requests, coordinating with XFN stakeholders to collect and QA artifacts, and track outcomes of regulatory examinations performed • Partner with Security Risk and Security Policy functions to ensure that security controls are reflected properly in our Security Risk Review, Security Policy requirements, and other governance processes • Support Security Compliance, Information Security, and Engineering stakeholders in identifying and executing on continuous control monitoring opportunities • Work closely with control owners and internal and external auditors on control operation and related documentation • Communicate progress, escalations, and issue resolutions to management and team stakeholders • Create procedural documentation, including training materials that support how we support control owners in risk to control analysis, control narratives, and how we operate as a Security Compliance team in the form of runbooks for new processes.

Requirements

• 4+ years of security, IT compliance (internal or external audit) or equivalent experience • Hands-on experience with implementing, reviewing or auditing security frameworks such as SOC 2, NIST, ISO • Prior experience at a Big 4 or consulting experience in Cybersecurity • Prior experience working closely with auditors and/or external regulators • Experience with compliance initiatives from start to finish • Experience sourcing, interpreting, and reporting on data via data visualization tools • Outstanding written and spoken communication skills • Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with light supervision • Ability to multitask, prioritize work, and meet deadlines in a fast-paced environment • Focus on precision and accuracy, and the drive to clarify ambiguity

Benefits

• target bonus + target equity + benefits (including medical, dental, vision and 401(k))

Apply Now
Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@remoterocketship.com