Senior Manager, Internal Audit IT
Lead Coinbase's global IT and security audit program, owning the multi-year roadmap and delivering complex audits across cloud, infrastructure, and cybersecurity. Manage a global team and partner with engineering and security leadership.
About the job
What you'll do
- Own the end-to-end delivery of complex, cross-functional IT and security audits covering cloud infrastructure, security operations, identity and access management, data protection, vendor/third-party risk, and key products and services.
- Lead and develop a high-performing global team of internal auditors and co-sourced resources, setting goals, coaching talent, managing performance, and building succession pipelines across regions.
- Drive integrated assurance across the three lines of defense by partnering with first and second line risk, compliance, security, and technology teams to rationalize testing and maximize control coverage.
- Shape executive-level reporting on technology and security control effectiveness, distilling key themes, emerging risks, and root causes into clear materials for senior management, the Head of Internal Audit, and the Audit Committee.
- Partner with technology and security leadership across Engineering, Security, Infrastructure, and Product to provide independent challenge on major initiatives (e.g., cloud migrations, new product launches, architecture changes) without compromising third-line independence.
- Build continuous improvement into the audit function by driving adoption of data analytics, automation, and generative AI to modernize IT and security audit execution, including continuous monitoring and automated evidence retrieval.
Required Skills & Experience
- 12+ years of experience in internal audit with deep focus on IT and information security, or in first-line / second-line technology/security roles with significant controls and audit exposure.
- Demonstrated success leading global, cross-functional IT audit portfolios spanning cloud, infrastructure, cybersecurity, and third-party risk across multiple regulatory jurisdictions (US, EMEA, APAC).
- Deep technical knowledge of cloud-based technology stacks, software development lifecycles, cloud security configurations, and enterprise IT operations risks and controls.
- Relevant professional certifications (e.g., CISA, CISSP, CIA, CPA) and working fluency with frameworks such as NIST, COBIT, and ITIL.
- Proven leadership experience building, mentoring, and managing global audit teams, including co-sourced resources and indirect reports across time zones.
- Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.
Skills
Cisa, Cissp, Cia, CPA, Nist, Cobit, Itil, Cloud Infrastructure, Cybersecurity, Identity And Access Management
Similar jobs
Own external connectivity, backbone capacity planning, and carrier negotiations for multi-GW AI training networks across data center campuses. Requires scaled carrier/long-haul experience, dark fiber procurement, and capacity planning.
Leads site-level environmental, health, and safety strategy for a rapidly scaling robotics portfolio, covering risk prevention, compliance, incident management, and contractor safety across complex operations. Requires 15+ years of progressive EHS leadership experience and strong OSHA/Cal-OSHA expertise.
Leads the architecture, extensibility, integration, and AI strategy for Databricks’ SAP S/4HANA finance platform. Requires 10+ years in SAP technical roles, architecture or technical leadership experience, and delivery of a full S/4HANA program with BTP extensions.
Lead infrastructure sustainability and emerging energy technology strategy for OpenAI's AI data centers. Evaluate and deploy scalable low-carbon solutions balancing reliability, cost, carbon, and regulatory needs; requires 15+ years in energy tech or clean power.
Lead AV Engineer owning multi-site audiovisual standards, infrastructure, event production, and the Zoom-to-Google Meet migration. The role requires 8+ years of AV engineering experience, deep control/audio/video expertise, and strong live-event and vendor leadership.