Coinbase is on a mission to increase economic freedom globally, and they are seeking a Staff Security Engineer to protect the foundation of their infrastructure and platform services. This role involves designing, implementing, and automating security solutions across complex cloud and containerized environments while partnering with engineering teams to embed security into platform services.
Responsibilities:
- Designing, implementing, and maintaining security controls across multi-cloud environments (AWS, GCP, etc.), Kubernetes clusters, and containerized workloads (Docker)
- Developing secure-by-default patterns for infrastructure-as-code (Terraform) and container orchestration platforms
- Writing code in Go to automate security processes, enforce guardrails, and integrate security solutions
- Conducting security reviews of cloud architecture, data platforms (e.g., Snowflake, Databricks), and routing configurations to identify vulnerabilities and recommend improvements
- Partnering with engineering teams to embed security into the design and deployment of platform services
- Collaborating with cross-functional teams to align security initiatives with business goals, balancing security, risk, and enablement
- Evaluating security needs during mergers and acquisitions (M&A) and ensuring acquired companies are integrated into secure paved road frameworks
- Influencing senior leaders and stakeholders on technical decisions, risk management strategies, and tradeoffs to drive secure and scalable outcomes
- Driving continuous improvement of security policies, threat detection mechanisms, and incident response automations
Requirements:
- At least 7 years of experience in infrastructure security, with strong expertise in both AWS and Kubernetes, and deep SME-level knowledge in at least one
- Proficiency in writing Go for automation and guardrails, and deploying infrastructure with Terraform
- Expertise across modern cloud and containerized platform technologies, including securing data platforms (e.g., Snowflake, Databricks) and cloud edge security
- Proven ability to partner with engineering, product, and business teams to align security initiatives with broader company goals
- Experience influencing senior leaders and stakeholders on technical decisions, risk tradeoffs, and enablement strategies
- An execution-focused approach, capable of navigating ambiguity and delivering impactful results
- A commitment to advancing an open financial system that connects the world
- Experience with hybrid cloud and on-prem environments, including platforms like GCP and Vercel, to secure infrastructure in a multi-cloud company alongside AWS and on-prem systems
- Proficiency in crafting Rego rules for Open Policy Agent (OPA) or similar tools to enforce security policies at scale
- Physical networking and datacenter experience, including securing physical infrastructure and managing network hardware in datacenter environments