Staff Security Engineer, InfraSec

Coinbase
Remote - USAPosted 24 February 2026

Job Description

<div class="content-intro"><p>Ready to be pushed beyond what you think you’re capable of?</p> <p>At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.</p> <p>To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems.</p> <p>Our <a href="https://www.coinbase.com/mission">work culture</a> is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be.</p> <p>While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.</p></div><p>Coinbase Infrastructure Security (InfraSec) is at the forefront of protecting the foundation of Coinbase’s infrastructure and platform services. This role partners closely with engineering teams to design, implement, and automate cutting-edge security solutions across complex cloud and containerized environments. Leveraging deep expertise in technologies like Kubernetes and AWS, this position serves as a trusted advisor to cross-functional teams and senior leaders, driving strategic decisions that balance security, scalability, and business enablement.</p> <p><strong>What you’ll be doing (ie. job duties):</strong></p> <ul> <li>Designing, implementing, and maintaining security controls across multi-cloud environments (AWS, GCP, etc.), Kubernetes clusters, and containerized workloads (Docker).</li> <li>Developing secure-by-default patterns for infrastructure-as-code (Terraform) and container orchestration platforms.</li> <li>Writing code in Go to automate security processes, enforce guardrails, and integrate security solutions.</li> <li>Conducting security reviews of cloud architecture, data platforms (e.g., Snowflake, Databricks), and routing configurations to identify vulnerabilities and recommend improvements.</li> <li>Partnering with engineering teams to embed security into the design and deployment of platform services.</li> <li>Collaborating with cross-functional teams to align security initiatives with business goals, balancing security, risk, and enablement.</li> <li>Evaluating security needs during mergers and acquisitions (MA) and ensuring acquired companies are integrated into secure paved road frameworks.</li> <li>Influencing senior leaders and stakeholders on technical decisions, risk management strategies, and tradeoffs to drive secure and scalable outcomes.</li> <li>Driving continuous improvement of security policies, threat detection mechanisms, and incident response automations.</li> </ul> <p><strong>What we look for in you (ie. job requirements):</strong></p> <ul> <li>At least 7 years of experience in infrastructure security, with strong expertise in both AWS and Kubernetes, and deep SME-level knowledge in at least one.</li> <li>Proficiency in writing Go for automation and guardrails, and deploying infrastructure with Terraform.</li> <li>Expertise across modern cloud and containerized platform technologies, including securing data platforms (e.g., Snowflake, Databricks) and cloud edge security.</li> <li>Proven ability to partner with engineering, product, and business teams to align security initiatives with broader company goals ... (truncated, view full listing at source)