Jobs / United States / Coinbase
Manager, GRC
Coinbase · 🇺🇸 Remote - USA · Remote
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 119 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 44 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Coinbase paid sponsored hires in similar roles6 certified filings for “Senior Manager, Tech Risk” (Information Technology Project Managers) in CA: $152k–$219k, median $207k. Most were filed at wage level III (50%) — 3 lottery entries, ≈46% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Coinbase
The US Department of Labor certified 119 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 44 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Coinbase →
About the role
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . We're hiring a Manager, GRC to join our Technology Risk & Controls team within Security and lead second line of defense advisory coverage across critical technology and security domains. This team evaluates risk posture, improves control design, and helps engineering, infrastructure, and security leaders make better, risk-informed decisions. You'll both manage a team and directly own advisory coverage for domains that may include disaster recovery and resiliency, SDLC, artificial intelligence, identity and access management, and supply chain - building trusted partnerships that ensure Coinbase addresses its most critical risks in its most critical functions. What you'll do: • Lead second line advisory coverage for key technology and security domains, assessing risk exposure, control effectiveness, policy alignment, and emerging issues across the business. • Partner with engineering and technology teams to evaluate domain posture and identify where additional controls, remediation, or governance improvements are needed. • Review and challenge the design of new and existing risks and their corresponding controls to ensure our mitigations are scalable, effective, and aligned to business, risk, and regulatory expectations. • Drive coordination across risk, controls, policy, audit, and assurance teams to translate incidents, audit findings, and regulatory expectations into actionable improvements that strengthen the technology control environment. • Intake, triage, and calculate inherent and residual risk with subject matter experts and risk owners, facilitating risk treatment decisions and validating execution of mitigation plans. • Enable leadership decision-making by communicating quantitative and qualitative risk tradeoffs and connecting risks, controls, policies, incidents, and findings into clear narratives that support prioritization and reporting. • Build, grow, and coach a team of technology and security analysts and senior analysts, fostering a culture of agility, innovation, and continuous performance feedback. Required Skills and Experience: • 8+ years in technology risk, IT controls, IT audit, cybersecurity risk, or compliance, with hands-on experience delivering full-stack GRC services (risk management, control design, continuous monitoring, governance documentation) - not a controls-only or risk-only background. • Deep understanding of technical design and governance principles across one or more domains such as infrastructure resiliency, SDLC, change management, or incident response, with demonstrated ability to challenge status quo and drive improvement. • Hands-on experience evaluating risks and control design, identifying weaknesses, and partnering with stakeholders to improve risk outcomes and control maturity. • Proven track record managing and mentoring analysts, growing their capabilities and careers while holding teams accountable to deliverables and timelines. • Track record of influencing cross-functional stakeholders, navigating ambiguity, and translating complex risk and compliance concepts into clear functional requirements for both technical and non-technical audiences. • Utilizes generative AI responsi