A Risk Manager evaluates risk and recommends and manages strategies to mitigate or offset risks that could result in financial losses for a company or organization. Analyzes current risks and assesses potential new risks. Reviews contracts and insurance policies; prepares risk budgets. Communicates risk policies and procedures to staff at all levels of a company.
at Coinbase in Boise, Idaho, United States Job Description Ready to do the most impactful work of your career?
Athttps:
//www.coinbase.com/careers. We're hiring a Manager, GRC to join our Technology Risk & Controls team within Security and lead second line of defense advisory coverage across critical technology and security domains. This team evaluates risk posture, improves control design, and helps engineering, infrastructure, and security leaders make better, risk-informed decisions. You'll both manage a team and directly own advisory coverage for domains that may include disaster recovery and resiliency, SDLC , artificial intelligence, identity and access management, and supply chain - building trusted partnerships that ensure Coinbase addresses its most critical risks in its most critical functions. What you'll do: Lead second line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business. Partner with engineering and technology teams to evaluate domain posture and identify where additional controls, remediation, or governance improvements are needed. Review and challenge the design of new and existing risks and their corresponding controls to ensure our mitigations are scalable, effective, and aligned to business, risk, and regulatory expectations. Drive coordination across risk, controls, policy, audit, and assurance teams to translate incidents, audit findings, and regulatory expectations into actionable improvements that strengthen the technology control environment. Intake, triage, and calculate inherent and residual risk with subject matter experts and risk owners, facilitating risk treatment decisions and validating execution of mitigation plans. Enable leadership decision-making by communicating quantitative and qualitative risk tradeoffs and connecting risks, controls, policies, incidents, and findings into clear narratives that support prioritization and reporting. Build, grow, and coach a team of technology and security analysts and senior analysts, fostering a culture of agility, innovation, and continuous performance feedback.
Required Skills and Experience:
8+ years in technology risk, IT controls, IT audit, cybersecurity risk, or compliance, with hands-on experience delivering full-stack GRC services (risk management, control design, continuous monitoring, governance documentation) - not a controls-only or risk-only background. Deep understanding of technica To view full details and how to apply, please login or create a Job Seeker account