
Coinbase · Remote - USA
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environ...
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic
freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to
be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for
"good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for
intense in-person working sessions called “surges.” learn more about working at Coinbase.
You'll join the Insider Threat team within Coinbase's Security Operations organization as an Insider Threat Analyst. This team
protects billions of dollars in digital assets and the trust of millions of customers by detecting, investigating, and mitigating
threats from inside the organization. You'll serve as the front line for insider threat detection, triaging alerts, conducting
investigations, and partnering cross-functionally with Security, Legal, HR, and business teams to safeguard Coinbase as it scales
globally.
prioritizing findings and escalating recommendations for investigation and mitigation.
coordination, delivering clear documentation of findings, risk assessment, and recommended next steps.
including abuse and misuse across company systems.
briefs and assessments for leadership and cross-functional stakeholders.
scalable solutions that reduce insider risk across the organization.
discipline, with hands-on use of insider threat technologies (SIEM, UBA, DLP, endpoint detection) and log analysis.
collection, interviewing techniques, and stakeholder coordination.
briefs and assessments consumed by leadership.
sensitive information, and experience with customer service tools or financial analysis.
improvements in workflow efficiency, cost, and quality.
Position ID: P77055
#LI-Remote
Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus
eligibility, and benefits (medical, dental, vision, 401(k)).
employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability,
protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with
applicable federal, state, and local laws.
contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen
reader and view the tutorial.
submitting your application, you agree to Arbitration of Disputes.
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase. You'll join the Insider Threat team within Coinbase's Security Operations organization as a Senior Insider Threat Analyst, helping protect billions of dollars in digital assets and the trust of millions of customers. This team detects, investigates, and mitigates threats from inside the organization using a blend of tooling, automation, and strategic expertise. You'll own complex investigations end to end, shape detection and response processes, and partner cross-functionally with Security, Legal, HR, and business teams to mature Coinbase's insider threat program as it scales globally. What you'll do: * Own complex insider threat investigations end to end, from triage and evidence collection through employee interviews and stakeholder coordination, delivering clear findings, risk assessments, and actionable recommendations to leadership. * Lead detection and analysis efforts by prioritizing alert reviews across insider threat technologies (SIEM, UBA, DLP, endpoint detection), correlating signals, and identifying patterns that inform broader mitigation strategies. * Partner cross-functionally with Security, Legal, HR, and business teams to design, implement, and refine processes that systematically reduce insider risk and close recurring control gaps at scale. * Shape the team's investigative and analytical capabilities by refining alerting logic, developing scalable detection improvements, and mentoring junior analysts on tradecraft, evidence handling, and stakeholder communication. * Strengthen reporting and stakeholder communication by composing decision-ready briefs and assessments for senior leadership, translating complex investigative findings into concise narratives with clear risk context and recommended next steps. Required Skills and Experience: * 5+ years of experience in insider threat, security investigations, counterintelligence, fraud detection, or a closely related discipline, with deep hands-on expertise in insider threat technologies (SIEM, UBA, DLP, endpoint detection) and log analysis. * Track record of independently leading complex, sensitive investigations involving employee matters, including evidence collection, interviewing techniques, and coordination across Legal, HR, and business stakeholders. * Demonstrated ability to identify systemic control gaps and drive scaled improvements to insider threat detection and response processes, including refining alerting logic and recommending automation opportunities. * Proven experience composing investigative briefs, risk assessments, and analytical products consumed by senior leadership, with the ability to translate complex technical and behavioral findings into concise, decision-ready narratives. * Working knowledge of the legal, regulatory, and ethical frameworks governing insider threat programs, with experience applying sound judgment when handling highly sensitive and confidential information. * Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality. Position ID: P77056 #LI-Remote Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)). Annual base salary range (excluding equity and bonus): $167,280—$196,800 USD * Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period. * Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws. * US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation. * Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial. * Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.
About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability. We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity. Role We are looking for an Insider Risk Analyst - SkillBridge Intern to join our Enterprise Security team. This is a remote role, reporting to the Director of Federal Security Operations and Insider Threat. This is a remote role, reporting to the Director of Federal Security Operations and Insider Threat. Our team is a mission-focused group dedicated to defending Zscaler’s global infrastructure, corporate assets, and government data through proactive detection, behavioral analysis, and rapid incident response. This role is unique in its scope, providing exposure to both commercial and federal security environments. What you’ll do (Role Expectations) * Cross-Environment Analysis: Assist in monitoring behavioral telemetry (UEBA) and access logs across both commercial and federal environments to identify potential insider risks and unauthorized data exfiltration * Data Protection: Support the implementation and auditing of Data Loss Prevention (DLP) controls within the Zscaler Zero Trust Exchange to safeguard sensitive corporate and government information * Investigation & Response: Monitor and triage security alerts related to policy violations; participate in the end-to-end lifecycle of insider risk investigations and root-cause analysis for a diverse global footprint * Operational Governance: Maintain specialized dashboards and Standard Operating Procedures (SOPs) that reflect the security requirements of both commercial standards (e.g., SOC2) and federal compliance (e.g., FedRAMP) Who You Are (Success Profile) * You thrive in ambiguity. You're comfortable building the path as you walk it, seeing ambiguity not as a hindrance but as the raw material to build something meaningful.. * You act like an owner. Your passion for the mission fuels your bias for action, and you navigate seamlessly between high-level strategy and hands-on execution.. * You are a problem-solver. You seek out challenges because you are energized by finding solutions, knowing that solving the hard problems delivers the biggest impact.. * You are customer-obsessed. You build deep empathy for the customer—both internal and external—and anchor your decisions in solving their real-world problems.. * You operate with urgency. You have a relentless focus on execution and a bias for action, delivering high-impact results quickly to win for the customer and the team.. What We’re Looking for (Minimum Qualifications) * Experience in Military Intel/CI: Prior experience in Counterintelligence, Insider Risk hubs, or Cyber Defensive Operations * Data Protection Knowledge: Familiarity with data classification, encryption standards, and Data Loss Prevention (DLP) technologies * Must be a current Active Duty United States military member or a member of the United States Guard/Reserve component on active duty orders for at least the last 180 days with 180 days or fewer remaining prior to your date of discharge and located in the United States * Obtain approval from your unit commander * MOU must be approved and submitted before start What Will Make You Stand Out (Preferred Qualifications) * Technical Proficiency: Exposure to SIEM/XDR platforms or User Behavior Analytics (UEBA) tools such as Crowdstrike Falcon, Splunk, or Google SecOps * Methodology: Understanding of behavioral indicators and how to map them to the MITRE ATT&CK or insider risk frameworks * Training/Certs: Completion of specialized training or certifications such as Security+, CySA+, GSEC, or vendor-specific data protection tracks #LI-TJ1 #LI-remote At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure. Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including: * Various health plans * Time off plans for vacation and sick time * Parental leave options * Retirement options * Education reimbursement * In-office perks, and more! Learn more about Zscaler's hybrid working model and benefits here. By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines. Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link. Pay Transparency Zscaler complies with all applicable federal, state, and local pay transparency rules. Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Locations: Lisbon, Portugal ABOUT THE ROLE Cloudflare is a system spanning the globe, on a mission to make the internet safer and more powerful everyday. To help fulfill this mission, we are seeking a talented REACT Analyst / Consultant to join us in growing our Cloudforce One REACT organization. In this role, you will be instrumental in building a proactive and threat intelligence-driven approach to protecting Cloudflare and its customers from sophisticated and evolving threat actors. As a REACT Consultant, you will respond to customer security incidents across on-premises, cloud, and hybrid environments. This position requires an innovative, self-starting, and detail-oriented problem solver with a passion for analyzing, tracking, and triaging malicious activity. You will engage with customers at all levels—including Executive, VP, Director, and engineering levels—serving an integral role alongside forensic analysts, threat researchers, detection engineers, and malware analysts to detect, isolate, and mitigate threats. KEY RESPONSIBILITIES 1. INCIDENT RESPONSE & ACTIVE EDGE MITIGATION * Active Edge Mitigation: Execute immediate defensive maneuvers at the Cloudflare edge to protect customer availability. This includes deploying custom WAF rules, implementing L3/L4 DDoS shunning, and performing real-time traffic filtering to neutralize attacks before they reach the customer's origin. * Support Full IR Lifecycle Management: Support and execute the end-to-end incident response process for clients (investigation, containment, remediation, and recovery). Review technical deliverables and coordinate sessions with customer stakeholders to ensure high-quality service and resolution. * Incident Remediation: Build a strong understanding of targeted attacks to create and execute customized tactical and strategic remediation plans for compromised organizations. 2. DIRECT CUSTOMER CONTAINMENT & THREAT ISOLATION * Ransomware & BEC: Identify and isolate infected hosts, revoke compromised sessions/identities, and stop data exfiltration within the customer's infrastructure. * Insider Threats & Nation-State Attacks: Track unauthorized lateral movement, identify sophisticated persistent backdoors, correlate threat actor activity across the environment, and execute containment to preserve evidence while neutralizing the adversary. 3. FORENSICS, ENGINEERING & AI ANALYSIS * Forensic Evidence & Chain of Custody: Conduct initial evidence preservation (logs, volatile memory, disk images) within customer environments according to forensic standards to support legal, regulatory, or insurance requirements. * Crisis Solution Development: Create and enhance client-facing Crisis & Incident Response solutions based on industry standards (ISO 27001, NIST, CIS). Advance customer cyber readiness by identifying opportunities for process optimization in monitoring, detection, and response. * AI-Leveraged Analysis: Utilize AI-powered security platforms to synthesize massive telemetry sets, automate log summarization, and accelerate the identification of emerging threat patterns during active customer engagements. * Technical Documentation & Reporting: Prepare high-fidelity incident reports, forensic findings, and client communications. Maintain rigorous standards for clarity and accuracy to ensure customer executives and engineers understand both the threat and the resolution. DESIRABLE SKILLS, KNOWLEDGE, AND EXPERIENCE * Education: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent training/practical experience. * Experience: 3+ years of overall experience in cybersecurity, including 2+ years of dedicated Incident Response / Digital Forensics experience, and 1+ years in a customer-facing role. * OS & Cloud Environments: In-depth understanding of Windows operating systems and general knowledge of Unix, Linux, and Mac environments. Familiarity with cloud environments (AWS, Azure, O365, Google Cloud, Cloudflare) and cloud IR methodologies. * Network Forensic Analysis: Strong technical knowledge of common network protocols and design patterns (TCP/IP, HTTPS, FTP, SFTP, SSH, RDP, CIFS/SMB, NFS). Experience with network analysis tools like Bro/Zeek or Suricata, and analyzing associated network logs. * Industry Standards: Solid understanding of MITRE ATT&CK and NIST Cyber Security Frameworks. * Communications: Excellent verbal and written communication skills with a proven ability to establish relationships and clearly explain tasks, guidance, and complex technical findings to executive and technical clients. BONUS POINTS * Proficient in Python or Golang, capable of writing modular code or simple scripts that can be installed on a remote system. * Proficient with Yara and writing rules to detect similar malware samples. * Understanding of source code, hex, binary, regular expressions, data correlation, and analysis (such as network flow and system logs). * Practical malware analysis experience with static, dynamic, and automated techniques, including the ability to reverse engineer various file formats and analyze complex samples. * Reverse engineering experience with APT malware with an understanding of common infection vectors, infrastructure enumeration, malware attribution, and current evasion tactics. * Familiarity with bash command-line executables to conduct static analysis and investigate Indicators of Compromise (IOCs). COMPENSATION ● For Portugal based hires: Estimated annual salary is between €54,000 - €75,000. * The final offer will be inclusive of time exemption, in alignment with the applicable law and collective bargaining agreements. EQUITY This role is eligible to participate in Cloudflare’s equity plan. What Makes Cloudflare Special? We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet. Project Galileo: Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost. Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states. 1.1.1.1: We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers. Sound like something you’d like to be a part of? We’d love to hear from you! Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process. This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license. Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer. Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.