Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Offensive Security Manager, Offensive Security image - Rise Careers
Job details

Offensive Security Manager, Offensive Security

Ready to be pushed beyond what you think you’re capable of?

At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.

To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems.

Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be.

The Application Security org at Coinbase is looking to hire a Pentest Manager to lead a team of Security Engineers responsible for managing Coinbase’s public bug bounty program and performing pentests of new products and features. In this role, you will work closely with both tech and non-tech stakeholders across the company to ensure the pentesting needs of the business are met on time. You’ll also own the Bug Bounty program charter, ensuring we continue to leverage talent worldwide to uplevel the security of Coinbase’s apps and services.

What you’ll be doing (ie. job duties):

  • Develop and execute on a vision what pentesting, bug bounty and red teaming at Coinbase should look like over the years ahead.
  • Develop and track metrics and OKRs to track pentesting work, bug bounty engagements, new security capability development, etc.
  • Lead internal and external pentesting as a service.
  • Own DAST and MAST as an internal security service offering.
  • Lead a team of Security Engineers focusing on performing tightly-scoped, new product launch pentests, regulatory and compliance-driven pentests, and managing Coinbase’s public bug bounty program.
  • Work with engineers and engineering leaders across the company to prioritize, implement and deploy fixes for known vulnerabilities.
  • Partner with Legal and GRCP to ensure we continue to meet regulatory and compliance-related pentesting requirements.
  • Provide on-call and product incident support.

What we look for in you (ie. job requirements):

  • A Bachelor’s or Master’s degree in Computer Science, Computer Engineering or a related field.
  • 3+ years of management experience, preferably managing a security team of 5 or more full time employees.
  • 3+ years of leading internal and external pentest engagements, actively participating in bug bounty programs, or performing security reviews.
  • Expertise in Web2, Web3 and Network security.
  • Experience in responsible vuln disclosure.
  • Ability to navigate through ambiguity and deliver results fast.
  • A growth mindset, able to quickly iterate on stakeholder feedback and lead change to meet the evolving needs of the business.
  • Ability to partner effectively with cross-functional stakeholders across various teams within a large organization.
  • Passion for the work that you do and ability to be hands-on when needed – participating in on-call rotations, leading incidents, performing pentests, validating bug bounty reports, verifying vuln fixes, etc.

Nice to haves:

  • You’ve owned a successful Bug Bounty and/or a Pentest program at a FinTech or a TradFi company.
  • You have experience automating manual processes using Go, Python, Ruby, etc.
  • You’ve identified and reported 0-day vulnerabilities in software used by millions of users around the world.

Job #: P69495

Pay Transparency Notice: The target annual salary for this position can range as detailed below. Full time offers from Coinbase also include target bonus + target equity + benefits (including medical, dental, and vision).

Pay Range:
$217,900$217,900 CAD

Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.

Commitment to Equal Opportunity

Coinbase is committed to diversity in its workforce and is proud to be an Equal Opportunity Employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law.  For US applicants, you may view the Know Your Rights notice here.  Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. 

Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information.  For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here).

Global Data Privacy Notice for Job Candidates and Applicants

Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here.    

 

Coinbase Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Coinbase DE&I Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Coinbase
Coinbase CEO photo
Brian Armstrong
Approve of CEO

Average salary estimate

$217900 / YEARLY (est.)
min
max
$217900K
$217900K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Offensive Security Manager, Offensive Security, Coinbase

Are you ready to stretch your limits and truly make an impact? As the Offensive Security Manager at Coinbase, a leader in the crypto space, your expertise will empower our mission to revolutionize the global financial system. In this remote role, supported by a team of high-caliber professionals, you'll lead critical efforts in fortifying our security measures. The ideal candidate will be driven by a passion for our transformative vision and the belief that technology can reshape finance for the better. You'll manage a dynamic team of Security Engineers, oversee our public bug bounty program, and ensure that our pentesting initiatives align with both business needs and regulatory requirements. We’re looking for someone who thrives under pressure and relishes the challenge of tackling our toughest security problems. Your responsibilities will include establishing a forward-looking vision for pentesting and red teaming, working collaboratively with various stakeholders to prioritize and implement security improvements, and developing key metrics to monitor our progress. If you’re someone who embraces feedback and is eager to grow, you’ll fit right in at Coinbase. We celebrate a culture where innovation and excellence are key, and we expect the same from you. Confidence in your skills, a proactive approach to problem-solving, and the ability to lead a team effectively will be essential in this role. Whether you’re managing DAST, MAST, or liaising with legal teams, your contributions will directly enhance the security of our applications and services. If you’re excited about the opportunity to create a lasting impact and work alongside passionate individuals, this is the perfect place for you.

Frequently Asked Questions (FAQs) for Offensive Security Manager, Offensive Security Role at Coinbase
What are the main responsibilities of an Offensive Security Manager at Coinbase?

As an Offensive Security Manager at Coinbase, you'll be responsible for leading a team of Security Engineers and overseeing the public bug bounty program. Your role will involve developing a vision for pentesting and red teaming, executing internal and external penttesting, and collaborating with various departments to implement security measures. Additionally, you'll manage metrics to track the effectiveness of security initiatives, ensuring compliance with regulatory requirements.

Join Rise to see the full answer
What qualifications do I need to become an Offensive Security Manager at Coinbase?

To qualify for the Offensive Security Manager position at Coinbase, candidates should have a Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field, along with at least 3 years of management experience in a security-related setting. Experience with pentest engagements, a strong understanding of Web2 and Web3 security practices, and a demonstrated ability to work effectively with cross-functional teams are also essential.

Join Rise to see the full answer
What skills are essential for the Offensive Security Manager role at Coinbase?

Essential skills for the Offensive Security Manager role at Coinbase include expertise in pentesting, bug bounty management, and vulnerability disclosure practices. A growth mindset, ability to navigate ambiguity, and strong communication skills are crucial for collaborating with diverse teams. You should also be hands-on, ready to take part in on-call rotations or incident response when needed.

Join Rise to see the full answer
What is the work culture like for an Offensive Security Manager at Coinbase?

The work culture for an Offensive Security Manager at Coinbase is intense and focused on excellence. The company values individuals who are passionate about their mission and eager to embrace challenges. Collaborating with talented colleagues, engaging in continuous learning, and tackling complex problems are central to the culture at Coinbase. If you have a strong desire to make an impact and thrive in a dynamic environment, you’ll find a great fit here.

Join Rise to see the full answer
What kind of career growth can an Offensive Security Manager expect at Coinbase?

At Coinbase, an Offensive Security Manager can expect significant opportunities for career growth. By leading innovative security initiatives and collaborating with brilliant minds from various fields, you'll expand your technical acumen and leadership skills. Coinbase encourages professional development and actively seeks to promote a growth-oriented environment where ideas are welcomed and valued.

Join Rise to see the full answer
Common Interview Questions for Offensive Security Manager, Offensive Security
Can you explain your experience in leading pentest engagements?

When answering this question, focus on specific examples from your previous roles where you successfully led pentest engagements. Describe your approach to planning, executing, and reporting on those tests, including how you collaborated with other teams to remediate the issues discovered.

Join Rise to see the full answer
How do you prioritize security tasks within your team?

To answer this question effectively, discuss your methodology for assessing risks and aligning priorities with company goals. You might mention frameworks or tools you use to identify critical areas of security that need immediate attention and how you communicate these priorities to your team.

Join Rise to see the full answer
What strategies do you employ to improve a bug bounty program?

In your response, highlight your approach to analyzing feedback from bounty hunters, tracking the success of previous programs, and incentivizing participation. Discuss any techniques you've implemented to ensure higher quality submissions and engagement from the security research community.

Join Rise to see the full answer
How do you build a strong security culture within a tech organization?

Explain your principles for fostering a culture where security is a shared responsibility. You can reference cross-training initiatives, regular communication about vulnerabilities, and how you motivate other teams to prioritize security in their processes.

Join Rise to see the full answer
Describe an incident where you had to make a quick decision to handle a security vulnerability.

Use a specific example to illustrate your decision-making process during a security incident. Detail the situation, your immediate response, and the outcomes. Emphasize your ability to stay calm under pressure and make informed decisions rapidly.

Join Rise to see the full answer
What is your experience with regulatory compliance in security?

Provide examples of your experience with relevant regulations related to security, such as GDPR or PCI-DSS compliance. Discuss how you have ensured your team's processes align with these regulations and any challenges you faced in doing so.

Join Rise to see the full answer
How do you stay current with the latest security trends and technologies?

Share the resources, networks, or communities you engage with to stay updated on security advancements. Mention any courses, certifications, or conferences you've attended that have contributed to your knowledge.

Join Rise to see the full answer
What role do communication skills play in your position as a security manager?

Explain the importance of effective communication in your job, particularly in conveying complex security information to non-technical stakeholders. Provide examples of how strong communication has enhanced collaboration and problem-solving in your past roles.

Join Rise to see the full answer
Can you give an example of how you used metrics to measure your team's performance?

Demonstrate your understanding of key performance metrics. Discuss which metrics you tracked (like the number of vulnerabilities discovered or fixed) and how they influenced your team's activities and priorities.

Join Rise to see the full answer
What approaches do you use to promote teamwork in a remote environment?

Discuss specific strategies you've implemented to enhance collaboration among remote team members, such as virtual meetings, team-building activities, and establishing clear communication channels to foster a sense of camaraderie and trust.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Collaboration over Competition
Growth & Learning
Mission Driven
Transparent & Candid
Photo of the Rise User
Posted 9 days ago
Inclusive & Diverse
Collaboration over Competition
Growth & Learning
Mission Driven
Transparent & Candid
Photo of the Rise User
Posted 14 days ago
Photo of the Rise User
Cognizant Remote US, Dallas County, TX; Texas, Dallas, TX
Posted 5 days ago

Join Cognizant as a Senior Manager Mulesoft Technical Architect to lead the design and implementation of complex Mulesoft solutions.

Photo of the Rise User
Posted 13 hours ago

SilverEdge Government Solutions is on the lookout for a Senior Network Engineer to enhance network performance and reliability in support of critical government initiatives.

Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Grammarly Remote Hybrid in the United States or Canada
Posted 2 days ago

Join Grammarly as a Solutions Architect to drive innovative custom solutions for enterprise customers in a hybrid work environment.

Photo of the Rise User
ServiceNow Remote The Fairway 6th Floor, Survey No 10/1, 11/2 and 12/2B, Challaghatta Next to Embassy Golf Links, Domlur, Bangalore, Karnataka, India
Posted 10 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
Photo of the Rise User
Posted 7 hours ago

Kaseware, Inc. is looking for a skilled Configuration Management Manager to enhance their information systems' security and efficiency in a remote setting.

Coinbase is an American publicly traded company operating a cryptocurrency exchange platform. They are a distributed company and all employees operate via remote work.

851 jobs
MATCH
Calculating your matching score...
BADGES
Badge Family FriendlyBadge Future MakerBadge Global CitizenBadge InnovatorBadge Work&Life Balance
CULTURE VALUES
Inclusive & Diverse
Collaboration over Competition
Growth & Learning
Mission Driven
Transparent & Candid
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 4, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
S
8 people applied to SOC Intern at SHEIN
Photo of the Rise User
Someone from OH, Beachwood just viewed Legal Counsel (Intellectual Property) at Mars
o
Someone from OH, Columbus just viewed Marketing and Communications Specialist at osu
Photo of the Rise User
Someone from OH, Cincinnati just viewed Data Analyst at Apple
Photo of the Rise User
Someone from OH, Dublin just viewed Manager-Financial Systems at American Express
Photo of the Rise User
Someone from OH, Akron just viewed Financial Analyst (Project Controls Analyst) at Nava
Photo of the Rise User
Someone from OH, Fairfield just viewed Finance Rotation Analyst at Huntington National Bank
A
Someone from OH, Canton just viewed Remote Sales- NO COLD CALLING at AO Globe Life
Photo of the Rise User
Someone from OH, Athens just viewed Digital Customer Experience Improvment (UX) at Advansys
Photo of the Rise User
Someone from OH, Akron just viewed Mobile Business Analyst at E.L.F. BEAUTY
Photo of the Rise User
Someone from OH, Lisbon just viewed Associate Cybersecurity Analyst - IAM at Visa
Photo of the Rise User
Someone from OH, Cincinnati just viewed Associate Buyer - Hardgoods at Huckberry
Photo of the Rise User
Someone from OH, Cleveland just viewed Inside Sales Representative at Elvtr
Photo of the Rise User
Someone from OH, Dayton just viewed Risk Operations Specialist at Imprint
A
Someone from OH, Cleveland just viewed Traffic Control Flagger at AWP Safety
Photo of the Rise User
Someone from OH, Sylvania just viewed Talent Sourcer at CEQUENS
Photo of the Rise User
Someone from OH, Sylvania just viewed Talent Sourcer (6 month contract) at Jerry
T
6 people applied to Intern-Tech at TDS Telecom
A
Someone from OH, Cleveland just viewed Junior Communications Specialist at Alphabe Insight Inc
Photo of the Rise User
Someone from OH, Columbus just viewed Telecom Coordinator at The Cheesecake Factory
Photo of the Rise User
Someone from OH, Cincinnati just viewed Staff Data Engineer at Visa
Photo of the Rise User
Someone from OH, Mason just viewed R&D Mechanical Engineer at Traeger Wood Pellet Grills
Photo of the Rise User
37 people applied to Security Analyst Jr at DEUNA