Yeah, it is probably about as secure as is reasonably needed. You should also have daily and maybe total limits, do statistical anti fraud (useful in general, but more so on low trust channels)
You might be more willing to allow large repeat transactions vs large transactions to a new payee.
I haven't tried it yet, but you definitely want the voice call to include both as much transaction info as possible and a "press 0 to talk to security" etc.
Unclear which telephony provider you use, but if you are more partnered with carriers, you can see more data, which may help reduce fraud. If you turn out to have a bunch of users in Nigeria, I'd set up peering directly with the Nigerian mobile carriers. This is probably years down the line.
I'd personally be willing to risk 10-20 BTC to this level of security, but not 500. Of course, my Bitcoin holdings are 2-3 BTC right now.
The big risk is the link between Coinbase and your outsourced telephony provider. Worst case, if someone is defrauded out of 5 BTC, he can eat it, or you can eat it -- it's not material to you. However, if I can somehow compromise the entire thing and take 10% out of every enabled-for-sms account, that might be material to Coinbase. I'd make sure the entire path is secure, and do as much verification in-house as possible, and probably put aggregate limits on the whole thing.
To be clear, I like the idea here, and think it is a great thing to deploy, it just makes me scared because it is a huge step down from the rest of coinbase's security. Since it is opt-in maybe it doesn't matter as much.