Coinbase logo
Coinbase

We're building an open financial system for the world.

Blockchain Security Engineer

Security EngineerSecurity EngineerOtherRemoteTeam 1,001-5,000Since 2012H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

142 days ago

Salary

$152K - $179K / year

Job Description

Blockchain Security Engineer

Coinbase

Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system. To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems. Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. At Coinbase, security isn't just a priority. It's the foundation of everything we do. In the fast-evolving world of digital currency, where trust is paramount, security breaches can mean the difference between success and failure. That's why we've made security a cornerstone of our mission, setting the standard for protecting millions of customers and billions of dollars in assets. As a Blockchain Security Engineer on the Decentralized Financial Security Team, you will work closely with engineers, technical product managers and senior leadership on designing secure products from the ground up. You will be responsible for performing secure design reviews, threat modeling, vendor reviews, working with vendors, and secure code reviews for upcoming Coinbase products or features that will be used by millions of customers. You will have an opportunity to work on the latest technology and provide leadership visibility of the current risk posture. You’ll also have an opportunity to pitch, lead and participate in cross-functional initiatives that uplevel the security of all Coinbase products and services. What you’ll be doing (ie. job duties): To be completed by all business teams except Eng. - Perform design reviews, threat modeling and code reviews of upcoming features and products. - Identify top product risk areas and lead risk-reduction initiatives with cross-functional teams. - Improve and/or automate existing processes to increase efficiency, utilizing agentic/AI tooling. - Create monitoring solutions to ensure identified risks remain at acceptable levels for Coinbase. - Participate in the team on-call rotation to support engineering teams through timely design consultations, vulnerability analysis, bug fix verification, etc. - Publish blogs and give talks (internal and external) on newfound vulnerabilities, incident investigations, unique integration risks, and related topics What we look for in you (ie. job requirements): To be completed by all business teams except Eng. - Strong understanding of blockchains (particularly EVM chains) and highly “crypto forward” - Expertise in blockchain technology and foundational knowledge in security principles - 2+ years of threat modeling/design review experience - Strong communication skills with the ability to translate technical security requirements and risks into terms that anyone can understand. - High ownership and drive, including the ability to work independently and unblock yourself. - Experience with using AI/agentic tooling (Claude Code, Cursor, GPT Codex, etc.) - Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human-in-the-loop practices to deliver business-ready outputs and drive measurable improvements in efficiency, cost, and quality. Nice to haves: - MS or PhD in Computer Science or related field. - Experience in at least one of: Snowflake, Databricks, Dune - Experience automating manual processes or carrying out process improvements. - Experience in Blockchain, Exchange, or Decentralized Exchange Security. Job ID: P76318 #LI-Remote Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)). Annual base salary range (excluding equity and bonus): $152,405—$179,300 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal Opportunity Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here). Global Data Privacy Notice for Job Candidates and Applicants Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here. AI Disclosure For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com

Related Categories

Related Job Pages

More Security Engineer Jobs

RunSybil logo

Security Software Engineer

RunSybil

Automated hacker intuition. We’re hiring!

Security Engineer142 days ago
Full TimeRemoteTeam 11-50Since 2023

• Research and develop offensive agentic capabilities that become core Sybil features • Hunt for real vulnerabilities across a range of target environments and translate what you find into repeatable, automated techniques • Build and ship end-to-end customer-facing features: from research spike to production deployment • Design and implement LLM-powered tooling that extends Sybil's reach and depth across attack surfaces • Identify gaps in our offensive coverage and propose technical initiatives to close them, without waiting to be asked • Contribute to technical design discussions, review your teammates' work, and hold a high bar for what we ship • Operate with ownership: you define the problem, build the solution, and see it through

United States
$170K - $210K / year
DeepJudge logo

Information Security

DeepJudge

The Only AI Platform that Knows Everything Your Firm Knows

Security Engineer142 days ago
OtherRemoteTeam 51-200H1B No Sponsor

• Own and continuously elevate our ISMS in accordance with ISO 27001, SOC 2 Type 2, GDPR, and emerging AI governance standards • Manage the full lifecycle of security audits, certifications, and internal controls • Guide enterprise prospects and clients through InfoSec and compliance conversations • Own our security whitepapers and InfoSec collateral • Partner with Legal and Compliance to define security policies • Manage day-to-day compliance operations • Work with Solution Architects and DevOps to translate security requirements into scalable practices • Collaborate with Engineering and business teams

United States
$150K - $200K / year
Job Closed
OtherRemoteTeam 10,001+Since 1961H1B Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Become a part of our caring community and help us put health first. The Senior Engineer, Offensive Security, executes high-fidelity threat actor and control validation campaigns within our BAS program. This role influences functional area strategy through technical expertise, operates with considerable autonomy on moderately complex assignments, and makes recommendations to leadership based on advanced knowledge and experience. The position focuses on Breach and Attack Simulation operations, campaign delivery, and detailed analysis, while also contributing to the overall direction of the program. The Bigger Picture - Join a 100% remote, highly specialized offensive security team. - Access to Hack TheBox Pro Labs, all HTB role-based training paths and certifications, discretionary certification funding, and conference/training budgets. - Collaborate with Red Team, Penetration Testing, and Bug Bounty professionals. - Fridays are dedicated to research and development in emerging offensive security technologies. Mission & Impact - Run high-fidelity threat-actor and control-validation campaigns. - Maintain agent health and convert raw BAS platform test results into actionable findings. - Track findings in the enterprise risk management platform. - Leverage offensive security expertise to determine effective simulation execution. - Design appropriate test cases for specific security countermeasures. - Manage multiple projects simultaneously. - Review the latest products from the Threat Intelligence team. - Chain custom Tactics, Techniques, and Procedures (TTPs) for Threat Simulation. - Develop complementary custom test cases using the platform’s Python API. - Initiate a bi-weekly Security Baseline and collaborate with SIEM Engineering. - Write concise findings for documentation in the enterprise risk management system. - Conduct in-depth analysis of IOC Validation gaps. Campaign Delivery - Build and execute threat-actor and control-validation campaigns using the BAS platform's pre-built threat simulation libraries. - Supplement campaigns with custom test cases developed through the Python API. - Ensure campaigns meet service level agreements, such as a two-week turnaround for prebuilt threat simulations. - Operate with limited guidance on moderately complex campaign development. Tool Operation & Tuning - Maintain agents, payload sets, and scheduling with considerable autonomy. - Automate bi-weekly security baseline runs. - Create synthetic unit tests for changes in countermeasure configurations or architecture. - Apply advanced technical knowledge to resolve complex issues. Data & Reporting - Draft actionable findings for SOC/IR. - Organize risk items within the Findings-Analysis workstream for documentation. - Use independent judgment to analyze and evaluate variable factors. Strategic Collaboration - Collaborate with the CTI team on priority TTPs. - Verify annual coverage and share new test cases with the broader team. - Make recommendations regarding testing approaches based on offensive security expertise. Continuous Improvement - Propose enhancements to security countermeasures. - Address detection or alerting gaps. - Suggest new service-line use cases to the Lead for roadmap consideration. Qualifications - Minimum 3 years of experience in offensive security roles such as Red Team, Penetration Testing, or Bug Bounty programs. - Intermediate to advanced proficiency in Python programming, or equivalent experience with interpreted languages such as PowerShell, Bash, or Ruby. - Independent technical problem-solving and analysis. - Experience with major Cloud Service Providers, including AWS, GCP, and Azure. - Demonstrated ability to work autonomously on complex technical assignments. - Experience utilizing Threat Intelligence to guide offensive security operations. - Experience testing endpoints protected by solutions such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne. - Interest in building and testing large language models (LLMs), machine learning models, AI infrastructure, MCP, prompt engineering, and applying these technologies to offensive security operations. Preferred Qualifications - Minimum 5 years of experience in any of the following areas: - Malware development. - Advanced Red Team operations and threat simulation. - Threat hunting or digital forensics in enterprise environments. - Analyzing and gathering intelligence on threat actors and their TTPs. - Published speaking engagements at industry conferences such as DEF CON, BSIDES, x33fcon, Black Hat, etc. - Relevant industry certifications, including but not limited to: OSCP, OSWE, OSED, OSCE3, CRTP, CRTE, CRTO, CRTL, CPTS, CBBH, CWEE, CAPE, MalDev Academy, OpenSecurityTraining2. - Experience with building and breaking LLMs, machine learning models, AI infrastructure MCP, prompt engineering, and applying these technologies to offensive security operations. Additional Information - WAH requirements: Must have the ability to provide a high speed DSL or cable modem for a home office. - Associates or contractors who live and work from home in the state of California will be provided payment for their internet expense. - A minimum standard speed for optimal performance of 25x10 (25mpbs download x 10mpbs upload) is required. - Satellite and Wireless Internet service is NOT allowed for this role. - A dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information. - Travel: While this is a remote position, occasional travel to Humana's offices for training or meetings may be required. Scheduled Weekly Hours 40 Pay Range The compensation range below reflects a good faith estimate of starting base pay for full time (40 hours per week) employment at the time of posting. The pay range may be higher or lower based on geographic location and individual pay will vary based on demonstrated job related skills, knowledge, experience, education, certifications, etc. $117,600 - $161,700 per year. This job is eligible for a bonus incentive plan based on company and/or individual performance. Description of Benefits - Humana, Inc. offers competitive benefits that support whole-person well-being. - Benefits designed to encourage personal wellness and smart healthcare decisions for you and your family. - Includes medical, dental and vision benefits, 401(k) retirement savings plan, time off (including paid time off, company and personal holidays, volunteer time off, paid parental and caregiver leave), short-term and long-term disability, life insurance, and many other opportunities. Application Deadline 03-17-2026 Equal Opportunity Employer It is the policy of Humana not to discriminate against any employee or applicant for employment because of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or protected veteran status.

United States + 1 moreAll locations: United States | United Arab Emirates
$117.6K - $161.7K / year
Job Closed
Capital One logo

Senior Manager, Customer Trust – Field Security Specialist

Capital One

At Capital One, we think and work like a tech company, using our digital fluency to transform everything about the customer experience. We’re bending data to our will, and turning a stodgy industry on its head. That’s reflected in our ranking as the number one business technology innovator in the U.S. in the 2016 InformationWeek Elite 100.

Security Engineer142 days ago
OtherRemoteTeam 10,001+Since 1994H1B Sponsor

• Act as the security expert for sales and business development efforts • Review, interpret, and respond to customer security-related inquiries • Drive transparency, thought leadership, and strategic engagement • Bridge the gap between technical value and business outcomes • Analyze and respond to cybersecurity sections of RFIs (Requests for Information) and RFPs (Requests for Proposal)

California + 2 moreAll locations: California | New York | Virginia
$209K - $286.2K / year
Job Closed