Jobs and Careers
CO

Security Analyst, CSIRT

Coinbase
Remote - USA, United StatesRemotefull_timeVerifiedPosted 26 Apr 2025
💰 $170,000/yr($144,500/yr$170,000/yr)

About the role

Ready to be pushed beyond what you think you’re capable of?

At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.

To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems.

Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be.

Security Operations Team

Security is a primary competency at Coinbase, and the Security Operations team keeps a watchful eye over every aspect of it. Every day, we go to battle against some of the most sophisticated attackers in the world to protect billions of dollars worth of digital assets and ensure that our customers and employees can enjoy a safe, trusted experience. As Coinbase scales globally, our team is scaling along with it, using a blend of tooling, automation, and strategic team growth to ensure that we’re well-equipped to protect the next billion users of crypto.

 

What you’ll be doing:

The Security Operations group is a multi-functional organization that includes our CSIRT, Trust & Safety, Insider Threat, and Threat Intelligence. While no two days will end up looking the same, generally-speaking you’ll be responsible for the following things:

  • You’ll serve as the first line of response when a security alert needs to be triaged, and lead the incident response/ management as needed
  • You’ll also refine our alerting rules to improve our signal/noise ratio, because no one wants to be a button-pusher or SOC monkey
  • If something happens twice, you’ll write a runbook for it. If it happens three times, you’ll figure out a way to automate that runbook
  • You’ll partner with Trust & Safety and Threat Intelligence on some of our attacker investigations to build TTP profiles
  • You’ll have a clear communication strategy and be able to assist with Coinbase emerging Web3 launches around the lines of Incident Response and Threat Detection
  • You’ll be part of a light on-call rotation with counterparts in multiple time zones
  • You’ll lead a culture of excellence by mentoring peers and share knowledge
  • You’ll collaborate with cross functional teams like engineering, product development, compliance to ensure timely Incident Response

 

What we look for in you:

Some security teams have strict requirements about certifications, degrees, years of experience, and things like that. Not us! We’re more interested in the unique perspectives and expertise you’ll bring to the team, rather than the acronyms on your resume. However, you’ll be much more likely to be successful in this role if these bullet points seem like a good description of you:

  • You’ve been doing practical security things (incident response, phishkit/malware analysis, investigating account compromises, etc) for a while now, probably in the realm of 3+ years
  • You have got a knack for identifying threats and measuring coverage / visibility across a vast amount of log sources - Multicloud, SaaS, Container Environment
  • You are good in understanding and analyzing multitude of artifacts across network and host level
  • You consider “Automation as a Force Multiplier”, you prefer spending time in building automation so you don’t have to do manual work tasks
  • You don’t just reflexively open up a Jupyter Notebook during an investigation, you’ve actually got favorite Jupyter Notebooks you’ve built up over the years, because you like backing up your conclusions with data, and you like automating things
  • You frequently get praise from your peers and coworkers about your communication skills, both written and verbal
  • Your high degree of empathy means that your coworkers trust you to help solve their security problems, because you never come across as judgmental or condescending
  • Pressure doesn’t get to you, even in high intensity situations or environments

 

Nice to haves:

  • You would bring a diverse perspective to the team: for example,  maybe you took an unconventional route to get into your current security car

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Coinbase

View company profile →