Security Engineer, Business Continuity & Risk

Block, Inc

• $180K — $270K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in third-party risk management and business continuity
  • 4+ years in backend, platform, data, or software engineering
  • Experience owning a production system with on-call responsibilities
  • Proficient in Python, Kotlin, Java, or Go
  • Hands-on experience with LLMs and their applications
  • Familiarity with integration patterns like REST APIs and event-driven architectures
  • Ability to navigate ambiguous technical challenges across teams

Responsibilities

  • Own and operationalize the third-party risk management and business continuity program
  • Define technical approaches for complex, cross-team problems
  • Build and operate data pipelines that aggregate risk and control signals
  • Translate compliance requirements into enforceable policy-as-code
  • Design AI workflows for evidence analysis and control monitoring
  • Automate evidence collection for continuous control monitoring
  • Collaborate with various teams to identify manual processes for automation

Benefits

  • Opportunity to work in a fast-paced, innovative environment
  • Access to cutting-edge technology and tools
  • Collaborative culture with cross-functional teams
  • Focus on professional development and growth
  • Flexible work arrangements to support work-life balance
Full Job Description
The Role

Square Financial Services, Inc. (SFS) is Block's bank. We opened in March 2021 and provide lending and FDIC-insured deposit products to individuals and small businesses on a nationwide basis.

SFS Risk Management is scaling vendor security, third party risk, and business continuity through innovation. Our Risk team designs and promotes the frameworks, standards, and oversight that elevates security considerations among our vendors, simplifies our regulatory obligations, and ensures resilience in our business operations. The team also operates the agent-first platforms that turn those frameworks into running systems.

Most of governance is a data problem. The risk, control, and asset information needed to answer "are we secure and compliant?" is dispersed across dozens of systems: Security Engineers treat that as an engineering problem. You'll build the data pipelines, integrations, and agentic AI workflows that turn manual governance processes into products that run continuously, produce measurable results, and hold up to audit end to end.

You Will
  • Own and operationalize a SFS third-party risk management and business continuity program program.
  • Define the technical approach for ambiguous, cross-team problem spaces. This is an early-stage program, and you will frame problems as often as you solve them.
  • Build and operate the pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from systems of record across Block and SFS, including source control, the service registry, identity, ticketing, and data platforms.
  • Translate standards and compliance requirements into policy-as-code: enforceable, testable rules that run continuously. For example, "every production service has an accountable owner" becomes a versioned, tested check instead of a quarterly spreadsheet.
  • Design agentic AI workflows that pair LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment.
  • Automate evidence collection and continuous control monitoring to replace point-in-time audit preparation.
  • Partner with Security, Procurement, Resilience and Engineering teams to find the manual processes most worth turning into a product.
  • Contribute to technical design discussions, evaluating the security and reliability properties of the platform itself.

You Have
  • Third-party risk management and business continuity experience.
  • 4+ years building production software in backend, platform, data, or software engineering
  • Multi-year ownership of a production system, including on-call, SLOs, and the maintenance work that starts after launch
  • Proficiency with at least one of Python, Kotlin, Java, or Go, and comfort reading unfamiliar codebases
  • Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features) and opinions about where model judgment belongs and where it doesn't. Judgment matters more here than volume
  • Experience with integration patterns: REST APIs, webhooks, authentication flows, event-driven architectures
  • Experience pulling, normalizing, and joining data from multiple imperfect sources, and handling the edge cases gracefully
  • Experience defining technical direction where the problem was ambiguous, and carrying it across team boundaries
  • Attention to detail balanced with pragmatism about risk-based prioritization
  • Curiosity, persistence, and comfort operating with minimal structure in an early-stage program

Nice to have:
  • Working knowledge of a security or compliance framework such as PCI DSS, SOX, SOC 2, ISO 27001, or NIST. Prior GRC experience is not required; we can teach the governance side
  • Production-scale LLM or agentic systems experience

You Know

Ideal candidates will have familiarity with some of the technologies in our environment:
  • Languages & Frameworks: Python, Java, Kotlin, Go
  • AI: LLM APIs (we build on Claude), agent frameworks and tool-use patterns such as Model Context Protocol, eval harnesses
  • APIs & Data: HTTP, JSON, gRPC, Protocol Buffers, SQL, Snowflake
  • Infrastructure: AWS, GCP, Kubernetes, Terraform, CI/CD (Buildkite), event-driven architecture

Similar Jobs

More Jobs at Block, Inc

More Information Technology Jobs

Find similar Security Engineer, Business Continuity & Risk jobs: