Hybrid Manager, Technology Risk

Posted last month

Apply now

About the role

  • Enable risk informed business outcomes: Enable teams and leadership to make risk-based decisions by clearly communicating quantitative and qualitative tradeoffs.
  • Manage risks throughout the risk lifecycle: Intake, triage, analyze, and calculate (inherent/residual) risk in collaboration with subject matter experts and risk owners. Facilitate agreement and documentation of risk treatment decisions; pressure testing treatment decisions and validating execution of mitigation plans across stakeholders as required. Participate in continuous monitoring or risk treatment.
  • Maintain source of truth risk register: Quality control of data, tooling support, and implementing automation/process improvements to establish a baseline and iteratively improve risk management data and tooling.
  • Iterating on program elements: Analysis of multiple variables to inform improvements to threat models/risk scoring methodologies.
  • Reporting on risk posture: Support synchronous and asynchronous reporting on findings, metrics, and recommend mitigations to business leadership. This includes ad hoc and scheduled meetings with leadership and business risk owners.
  • Communications and training: Support develop, execution, and maintenance of communication and training plans to roll out the technology risk program across the organization. Maintain team runbooks, team intra-web pages, and risk register metrics dashboards.
  • Build, grow, and coach a team of technology and security risk analysts; foster a culture of agility and innovation, and provide ongoing performance feedback.
  • Enterprise risk alignment: Work in lockstep with Enterprise Risk Management to escalate risks through the enterprise risk register and report relevant metrics to senior leadership as determined necessary.
  • Global Engagement: Collaborate with stakeholders to help scale the program’s risk framework across Coinbase entities, products, and geographies/markets. Regularly collaborate with GRC teams, Legal and Compliance for risks, assessments, and reporting to meet regulatory requirements.
  • Support audit and regulatory inspections: Support data compilation to respond to US and international audit/regulator inquiries.
  • Maintain an industry pulse: Maintain awareness of international regulation, emerging threats, forecasts, policies, and benchmarks

Requirements

  • 8+ years of experience working in a 1 or 2 LoD risk management function and/or Governance, Risk, and Compliance organization.
  • Risk domain knowledge and best practices: Familiarity with standards and frameworks e.g. ISO 27001/5, NIST CSF, COBIT, ITIL, DORA, FAIR risk quant methodology to measure controls/risks, monitor controls/risks, and validating/racking/evidencing remediation.
  • Technology risk domain knowledge: Ability to dig into technical risk solutions and to work on technical quantitative risk assessments across information technology domains such as asset management, resilience, systems development lifecycle, and infrastructure.
  • Comfortable working with project management tooling (e.g. Jira, Archer) and quant and qualitative data analytics tooling.
  • Clear/concise communicator and writer; experience drafting/operationalizing project plans across stakeholders, holding teams accountable, and documenting deliverables to varying levels of junior and senior stakeholder audiences. Ability to translate controls/risk standards out of compliance speak and into functional requirements and across varying levels of technical stakeholders.
  • Managing high performing teams: Demonstrable experience managing and mentoring analysts to grow and mature their capabilities and careers.
  • Regulatory familiarity: Working knowledge of major regulatory/legal frameworks (US/international) driving requirements across technology organizations.
  • Navigating ambiguity and complexity: Ability to manage a queue against strategic priorities and shows expertise in being able to handle multiple assessments at a time. You are comfortable operating on an unpaved road and dealing with ambiguity.
  • Drive for continuous learning: You are willing to learn and apply processes unique to the challenges at Coinbase. You have a willingness to embrace a steep learning curve and stretch opportunities to learn new skills.
  • Excellent organization and project management skills in a fast-moving and demanding environment

Benefits

  • bonus eligibility
  • equity eligibility
  • benefits (including medical, dental, vision, and 401(k))

Job title

Manager, Technology Risk

Job type

Experience level

SeniorLead

Salary

$193,970 - $228,200 per year

Degree requirement

No Education Requirement

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job