Job Closed

This listing is no longer active.

Coinbase logo
Coinbase

A digital currency exchange, Coinbase is used by consumers, merchants, and traders to buy and sell cryptocurrencies, such as Bitcoin, Ethereum, and Litecoin. Founded in 2012 "to cr

Senior Offensive Security Engineer (IOT / Network Pentesting)

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 4,700Since 2012

Location

United States

Posted

57 days ago

Salary

$186.1K - $218.9K / year

Seniority

Senior

Bachelor Degree9 yrs expEnglishIotNetwork ProtocolsPenetration Testing Tools

Job Description

Senior Offensive Security Engineer (IOT / Network Pentesting)

Coinbase

Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system. To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems. Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. The Application Security org at Coinbase is hiring for a Senior Offensive Security Engineer, Offensive Security. We are seeking a highly skilled and experienced Penetration Tester with a proven track record of assessing and securing the digital security of physical spaces. The ideal candidate will possess a strong technical background, active, current, or recently expired security clearance, and demonstrated experience working with executives at large companies. What you’ll be doing (ie. job duties): To be completed by all business teams except Eng. - Assess the digital security of physical spaces (e.g., labs, offices), including expertise in IOT/IOT automation and prosumer networking gear. - Conduct comprehensive penetration tests on networked devices, including hardware, firmware, and integrations. - Identify and exploit vulnerabilities in ecosystems, providing detailed reports and recommendations for remediation. - Collaborate with security and development teams to integrate security best practices throughout the device lifecycle. - Stay current with the latest security threats, vulnerabilities, and industry best practices for securing physical spaces. - Present findings and recommendations to technical and non-technical stakeholders, including executive leadership. What we look for in you (ie. job requirements): - Active, current, or recently expired security clearance. - 2+ years of experience working with C-Suite at S&P 500 organizations. - Proven penetration testing expertise across the full threat spectrum, from common criminal actors up to highly sophisticated, resource-rich Advanced Persistent Threats (APTs) and nation-state actors. - Proven expertise in penetration testing the full digital security of physical spaces, including building management systems (BMS), physical access control systems (PACS), IoT/home automation devices, wireless protocols (LoRaWAN, Bluetooth, Zigbee, etc) and networked security infrastructure (e.g., IP cameras and alarms). - Extensive experience working with executives at large, complex organizations. - Strong understanding of networking protocols and architectures, security frameworks, and building security best practices. - Proficiency in various penetration testing tools and methodologies. - Excellent communication and report-writing skills. - Ability to travel occasionally, based on business needs. Nice to haves: - Participation in computer security competitions (CTFs), Bug Bounty programs, open source security research, CVE analysis - Experience in Web3 security, network security and/or cloud security. - Experience with developing and implementing security tooling to support penetration testing and AI penetration testing activities. - Experience pentesting AI systems and LLMs. Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)). Annual base salary range (excluding equity and bonus): $186,065—$218,900 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal OpportunityCoinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here). Global Data Privacy Notice for Job Candidates and ApplicantsDepending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here. AI DisclosureFor select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com

Benefits

  • 401(K), 401(K) matching, Childcare benefits, Company equity, Company-sponsored outings, Continuing education stipend, Dental insurance, Employee stock purchase plan, Family medical leave, Flexible Spending Account (FSA), Free daily meals, Generous parental leave, Health insurance, Job training & conferences, Life insurance, Paid volunteer time, Paid holidays, Paid sick days, Performance bonus, Promote from within, Lunch and learns, Relocation assistance, Remote work program, Free snacks and drinks, Team based strategic planning, OKR operational model, Vision insurance, Wellness programs, Mental health benefits, Home-office stipend for remote employees, Employee awards, Pay transparency, Personal development training, Flexible time off, Bereavement leave benefits, Company-wide vacation

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 11-50H1B No Sponsor

• Perform vulnerability testing and reporting • Perform various cybersecurity functions • Support the organization’s cybersecurity, compliance, and consulting practice in delivering various IS027K, HITRUST, HIPAA, and NIST Compliant governance and security services. • Assist in performing Risk Assessments to ensure compliance with IS027K, HITRUST, PCI DSS, HIPAA, and NIST. • Assist in writing and updating IS027K, HITRUST, PCI DSS, HIPAA, and NIST Compliant Policies and Procedures. • Interpretation of industry or regulatory requirements and apply them to business operations • Create or choose an approach or procedure from a variety of complex options for addressing a work task. • Interface with clients, analysts, and project managers to clarify requirements and documentation. • Review literature and documentation and compares such to current practices relevant to the solution of assigned projects. • Work with various Quality Assurance standards to review detailed documents, policies, procedures, and related materials. • Assist other team members with their assignments as required. • Orchestrate the planning of various reports, preparation of audit and compliance programs, performing testing procedures, drafting respective reports for presentation, and assessing management action plans. • Develop status and analysis reports and presentations for regular review. • Create other highly detailed documentation for internal and external use.

Utah
Full TimeRemoteTeam 11-50H1B No Sponsor

• Provide The Center for Food Safety and Applied Nutrition (CFSAN) IT System Lifecycle Development and Management Support Services on behalf of the Food and Drug Association (FDA). • The FDA is seeking Small Business (SB) sources to determine the availability and capability of small business manufacturers or small businesses capable of IT System Lifecycle Development and Management Support Services. • The Single Award Blanket Purchase Agreement (BPA) will be awarded by the FDA contracting manager. • The Center for Food Safety and Applied Nutrition (CFSAN) is the branch of the United States Food and Drug Administration that regulates food, dietary supplements, cosmetics, drugs, biologics, medical devices, and radiological products. • The scope of this contract is to provide the full range of technical and management services necessary to develop, maintain, and enhance CFSAN systems.

Maryland
GC AI logo

Software Engineer, Security & Platform

GC AI

GC AI is the legal AI platform built for in-house teams that solves the workflows in-house lawyers and legal professionals face every day. With powerful tools like Easy Prompt and Exact Quote, you can be the legal hero your team needs with faster and more accurate drafting, reviewing, researching, and redlining. GC AI is built for in-house legal work, gets to know you and your company over time, uses 5 large language models under the hood, and is private, secure and compliant. GC AI is SOC 2 Type II certified, built with enterprise-grade security, and never uses your confidential data for training. Founded by a three-time General Counsel and former Morrison & Foerster litigator, GC AI is trusted by over 500 legal teams worldwide, including Webflow, CDW, Vercel, Liquid Death, Kenneth Cole, Eventbrite, SurveyMonkey, Tipalti, and other high-growth global brands. See the difference that becoming an AI-powered lawyer can make. Try it free or get a demo at gc.ai.

Full TimeRemoteTeam 11-50Since 2023

GC AI is the fastest-growing and most trusted legal AI platform for in-house legal teams. We're building the future of legal work, and we're doing it fast. You'll join at a pivotal moment—when decisions matter, impact is immediate, and the runway to shape your career is wide open. We’re a high-performing team where you'll have real ownership and influence from day one. More than 1,300 companies use GC AI to drive their business forward, including 150+ public companies, 25+ unicorns, and brands such as News Corp, Miro, Bass Pro Shops, Snyk, Skims, Liquid Death, Vercel, Zscaler, and TIME. We've 10x'd revenue in 12 months, raised a $60 million Series B ($555 million valuation), and are growing faster than ever. We are backed by incredible investors, including Scale Venture Partners, Northzone, Sound Ventures, and Guillermo Rauch, CEO of Vercel. If you thrive when the stakes are high and the path isn't paved, you'll love it here. Our six guiding principles are: 1% better every day, customer obsession, ship today, find a way, care deeply, and own it completely. Come shape the future of legal work with us. Location We are hiring for this role to be based in the United States or Canada. This is a remote role unless you fall within the following parameters. If you live within approximately 50 miles of our San Mateo, CA or Provo, UT office, the position follows a hybrid schedule with in-office days on Mondays, Wednesdays, and Fridays. About The Role Help harden, simplify, and operationalize a TypeScript-based production system used by security-conscious, legal/regulatory, and enterprise customers. This is not a feature-churn role – though you may contribute directly to product experiences. The core need centers on security, auditability, infrastructure correctness, and customer trust, with occasional forward-deployed and sales-adjacent work when deep technical context is required. A major component of this role will be to collaborate to form and evangelize engineering direction and culture with respect to security needs. If you’re comfortable owning security surfaces end-to-end—code, cloud, and customer conversations—this role will suit you. We’re an AI-forward environment and (responsibly) use AI tools like Cursor and Claude Code for our work. What You'll Do - Help unify logging, security events and other auditability functionality within our platform. - Work with legal and sales to help communicate security posture, functionality, and compliance. - Work with DevOps and other engineering functions to promote and maintain strong security positions, clear auditability, tight network boundaries, and alignment with security, compliance, and customer needs. What You Bring - Strong experience with TypeScript across backend and frontend. - Production experience with Google Cloud Platform (IAM, service accounts, project isolation). - Experience with infrastructure as code (Terraform, Pulumi, or similar). - Practical experience designing or implementing: - Audit logs and SIEM experience - Access controls / complex roles, organizations, and permissioning - Security-relevant telemetry - Ability to reason about real risk vs. checklist compliance. Nice to Have - Experience acting as a technical lead either on a team or a vertical, strong soft skills. - Familiarity with security questionnaires, vendor risk reviews, SOC 2, and audits. - Prior work in regulated or compliance-heavy environments. - Comfort working directly with customers or sales in technical contexts. A Note On Pace We’re building something new in a once-in-a-generation shift in technology and the legal industry, so we move at a relentless pace. We expect urgency, ownership, and good judgment even when things aren’t perfectly clear. If you need structure and consensus to do your best work, this isn’t the right place for you. If you thrive in ambiguity and growth, work with intensity, and want real responsibility, keep reading. We’re excited to meet you. Compensation GC AI's compensation package includes a competitive base salary benchmarked against real-time market data, as well as meaningful equity and excellent benefits for all full-time roles. Our US-based compensation range for this role is $165,000 – $350,000. This range spans four levels, from mid-level to Principal. Final compensation will vary based on leveling, market conditions, geographic location, and candidate qualifications, including relevant knowledge, skills, and experience assessed during the interview process. These compensation bands are just the starting point. After someone joins and proves they’re an exceptional performer, we adjust quickly to ensure their compensation aligns with their impact. Equal Opportunity Employment GC AI is an equal opportunity employer that supports workplace diversity and does not discriminate on the basis of race, color, religion, gender identity/expression, national origin, age, military service eligibility, veteran status, sexual orientation, marital status, physical or mental disability, or any other protected class. GC AI is committed to working with and providing reasonable accommodation to applicants with physical and mental disabilities. #LI-GCAI Fraud Notice to GC AI Applicants To protect yourself against phishing and recruitment fraud, please note that GC AI only accepts job applications through our official careers page at https://gc.ai/careers and through sponsored jobs on LinkedIn. All legitimate communication from our team regarding job opportunities will come from a GC AI team member with a @gc.ai or @getgc.ai email address. GC AI will never: - Refer you to external websites to apply - Conduct interviews over email, chat platforms, or messaging apps - Ask you to provide payment or purchase equipment - Request personal or financial information such as your mailing address, social security number, credit card numbers, or banking information during the application process Examples of fraudulent email addresses: - info.gcai.careers.com@gmail.com - info.gc.aicareers.online.com@gmail.com - Any email address ending in @gmail.com, @yahoo.com, or other free email services If you are contacted by someone claiming to be from GC AI via an unofficial channel or from a suspicious email address, please do not share any information. Mark the communication as "phishing" or "spam" and do not respond.

California
$165K - $350K / year
GC AI logo

Software Engineer, Security & Platform

GC AI

GC AI is the legal AI platform built for in-house teams that solves the workflows in-house lawyers and legal professionals face every day. With powerful tools like Easy Prompt and Exact Quote, you can be the legal hero your team needs with faster and more accurate drafting, reviewing, researching, and redlining. GC AI is built for in-house legal work, gets to know you and your company over time, uses 5 large language models under the hood, and is private, secure and compliant. GC AI is SOC 2 Type II certified, built with enterprise-grade security, and never uses your confidential data for training. Founded by a three-time General Counsel and former Morrison & Foerster litigator, GC AI is trusted by over 500 legal teams worldwide, including Webflow, CDW, Vercel, Liquid Death, Kenneth Cole, Eventbrite, SurveyMonkey, Tipalti, and other high-growth global brands. See the difference that becoming an AI-powered lawyer can make. Try it free or get a demo at gc.ai.

Full TimeRemoteTeam 11-50Since 2023

GC AI is the fastest-growing and most trusted legal AI platform for in-house legal teams. We're building the future of legal work, and we're doing it fast. You'll join at a pivotal moment—when decisions matter, impact is immediate, and the runway to shape your career is wide open. We’re a high-performing team where you'll have real ownership and influence from day one. More than 1,300 companies use GC AI to drive their business forward, including 150+ public companies, 25+ unicorns, and brands such as News Corp, Miro, Bass Pro Shops, Snyk, Skims, Liquid Death, Vercel, Zscaler, and TIME. We've 10x'd revenue in 12 months, raised a $60 million Series B ($555 million valuation), and are growing faster than ever. We are backed by incredible investors, including Scale Venture Partners, Northzone, Sound Ventures, and Guillermo Rauch, CEO of Vercel. If you thrive when the stakes are high and the path isn't paved, you'll love it here. Our six guiding principles are: 1% better every day, customer obsession, ship today, find a way, care deeply, and own it completely. Come shape the future of legal work with us. Location We are hiring for this role to be based in the United States or Canada. This is a remote role unless you fall within the following parameters. If you live within approximately 50 miles of our San Mateo, CA or Provo, UT office, the position follows a hybrid schedule with in-office days on Mondays, Wednesdays, and Fridays. About The Role Help harden, simplify, and operationalize a TypeScript-based production system used by security-conscious, legal/regulatory, and enterprise customers. This is not a feature-churn role – though you may contribute directly to product experiences. The core need centers on security, auditability, infrastructure correctness, and customer trust, with occasional forward-deployed and sales-adjacent work when deep technical context is required. A major component of this role will be to collaborate to form and evangelize engineering direction and culture with respect to security needs. If you’re comfortable owning security surfaces end-to-end—code, cloud, and customer conversations—this role will suit you. We’re an AI-forward environment and (responsibly) use AI tools like Cursor and Claude Code for our work. What You'll Do - Help unify logging, security events and other auditability functionality within our platform. - Work with legal and sales to help communicate security posture, functionality, and compliance. - Work with DevOps and other engineering functions to promote and maintain strong security positions, clear auditability, tight network boundaries, and alignment with security, compliance, and customer needs. What You Bring - Strong experience with TypeScript across backend and frontend. - Production experience with Google Cloud Platform (IAM, service accounts, project isolation). - Experience with infrastructure as code (Terraform, Pulumi, or similar). - Practical experience designing or implementing: - Audit logs and SIEM experience - Access controls / complex roles, organizations, and permissioning - Security-relevant telemetry - Ability to reason about real risk vs. checklist compliance. Nice to Have - Experience acting as a technical lead either on a team or a vertical, strong soft skills. - Familiarity with security questionnaires, vendor risk reviews, SOC 2, and audits. - Prior work in regulated or compliance-heavy environments. - Comfort working directly with customers or sales in technical contexts. A Note On Pace We’re building something new in a once-in-a-generation shift in technology and the legal industry, so we move at a relentless pace. We expect urgency, ownership, and good judgment even when things aren’t perfectly clear. If you need structure and consensus to do your best work, this isn’t the right place for you. If you thrive in ambiguity and growth, work with intensity, and want real responsibility, keep reading. We’re excited to meet you. Compensation GC AI's compensation package includes a competitive base salary benchmarked against real-time market data, as well as meaningful equity and excellent benefits for all full-time roles. Our US-based compensation range for this role is $165,000 – $350,000. This range spans four levels, from mid-level to Principal. Final compensation will vary based on leveling, market conditions, geographic location, and candidate qualifications, including relevant knowledge, skills, and experience assessed during the interview process. These compensation bands are just the starting point. After someone joins and proves they’re an exceptional performer, we adjust quickly to ensure their compensation aligns with their impact. Equal Opportunity Employment GC AI is an equal opportunity employer that supports workplace diversity and does not discriminate on the basis of race, color, religion, gender identity/expression, national origin, age, military service eligibility, veteran status, sexual orientation, marital status, physical or mental disability, or any other protected class. GC AI is committed to working with and providing reasonable accommodation to applicants with physical and mental disabilities. #LI-GCAI Fraud Notice to GC AI Applicants To protect yourself against phishing and recruitment fraud, please note that GC AI only accepts job applications through our official careers page at https://gc.ai/careers and through sponsored jobs on LinkedIn. All legitimate communication from our team regarding job opportunities will come from a GC AI team member with a @gc.ai or @getgc.ai email address. GC AI will never: - Refer you to external websites to apply - Conduct interviews over email, chat platforms, or messaging apps - Ask you to provide payment or purchase equipment - Request personal or financial information such as your mailing address, social security number, credit card numbers, or banking information during the application process Examples of fraudulent email addresses: - info.gcai.careers.com@gmail.com - info.gc.aicareers.online.com@gmail.com - Any email address ending in @gmail.com, @yahoo.com, or other free email services If you are contacted by someone claiming to be from GC AI via an unofficial channel or from a suspicious email address, please do not share any information. Mark the communication as "phishing" or "spam" and do not respond.

California
$165K - $350K / year