← Back to results

Security Engineer, Business Continuity & Risk

Own and operationalize a third-party risk management and business continuity program at Block.

Location
Bay Area, CA, United States
Compensation
$162k–$270k/yr
Level
mid
Type
full time

Posted by employer 2 days ago

First seen on Joblaze 2 days ago

Last verified on the company career page 19 hours ago

What you'll build

  • Own and operationalize a third-party risk management program
  • Build and operate data pipelines and integrations
  • Translate standards and compliance requirements into policy-as-code
  • Automate evidence collection and continuous control monitoring
  • Partner with Security, Procurement, Resilience and Engineering teams

Must have

  • Third-party risk management and business continuity experience
  • 4+ years building production software
  • Proficiency with at least one of Python, Kotlin, Java, or Go
  • Hands-on experience building with LLMs
  • Experience with integration patterns

Nice to have

  • Working knowledge of a security or compliance framework
  • Production-scale LLM or agentic systems experience

AI in the day-to-day

Design agentic AI workflows that pair LLM reasoning with deterministic, auditable decision layers.

Requirements

Experience
4+ years

Not disclosed in this posting: work arrangement, visa sponsorship.

Benefits

Retirement Savings Plans Remote Work Flexible Time Off Health Insurance

Joblaze summary

In this role, the Security Engineer focuses on developing and managing third-party risk and business continuity programs, ensuring that security frameworks are effectively integrated into operational processes. Key skills include proficiency in backend programming languages like Python or Java, as well as experience with data integration and AI workflows. This position is suited for candidates with at least four years of software engineering experience, particularly those comfortable navigating ambiguous challenges in an early-stage environment. The team emphasizes collaboration across various departments to enhance security measures and streamline compliance.

Joblaze insights

  • Listed 2 days ago — first seen on Joblaze October 2, 2026. Last confirmed on Block's careers page October 3, 2026.
  • Salary band is in line with the typical range for Security roles (median ~$170,000).
  • Starts above 79% of 52 comparable mid security roles in United States that list Python we track (median $130,000 across 21 companies). See Python salary trends
  • Python appears in 42.7% of 199 comparable mid security roles in United States; Snowflake appears in 0.5% of 199 comparable mid security roles in United States.

Quick facts

What's the salary range?
Block lists $162,000–$270,000 for this role.
How much experience is required?
At least 4 years of relevant experience for this Security Engineer, Business Continuity & Risk role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, CI/CD, GCP, Go, Java, Kotlin.
What seniority level is this role?
Block targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Security Engineer, Business Continuity & Risk role at Block.

From the original posting

Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams — People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more — provide support and guidance at the corporate level. They work across business groups and around the globe, spanning time zones and disciplines to develop inclusive People policies, forecast finances, give legal counsel, safeguard systems, nurture new initiatives, and more. Every challenge creates possibilities, and we need different perspectives to see them all. Bring yours to Block.

The Role

Square Financial Services, Inc. (SFS) is Block’s bank. We opened in March 2021 and provide lending and FDIC-insured deposit products to individuals and small businesses on a nationwide basis.

SFS Risk Management is scaling vendor security, third party risk, and business continuity through innovation. Our Risk team designs and promotes the frameworks, standards, and oversight that elevates security considerations among our vendors, simplifies our regulatory obligations, and ensures resilience in our business operations. The team also operates the agent-first platforms that turn those frameworks into running systems.

Most of governance is a data problem. The risk, control, and asset information needed to answer "are we secure and compliant?" is dispersed across dozens of systems: Security Engineers treat that as an engineering problem. You'll build the data pipelines, integrations, and agentic AI workflows that turn manual governance processes into products that run continuously, produce measurable results, and hold up to audit end to end.

You Will

  • Own and operationalize a SFS third-party risk management and business continuity program program.
  • Define the technical approach for ambiguous, cross-team problem spaces. This is an early-stage program, and you will frame problems as often as you solve them.
  • Build and operate the pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from systems of record across Block and SFS, including source control, the service registry, identity, ticketing, and data platforms.
  • Translate standards and compliance requirements into policy-as-code: enforceable, testable rules that run continuously. For example, "every production service has an accountable owner" becomes a versioned, tested check instead of a quarterly spreadsheet.
  • Design agentic AI workflows that pair LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment.
  • Automate evidence collection and continuous control monitoring to replace point-in-time audit preparation.
  • Partner with Security, Procurement, Resilience and Engineering teams to find the manual processes most worth turning into a product.
  • Contribute to technical design discussions, evaluating the security and reliability properties of the platform itself.

You Have

  • Third-party risk management and business continuity experience.
  • 4+ years building production software in backend, platform, data, or software engineering
  • Multi-year ownership of a production system, including on-call, SLOs, and the maintenance work that starts after launch
  • Proficiency with at least one of Python, Kotlin, Java, or Go, and comfort reading unfamiliar codebases
  • Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features) and opinions about where model judgment belongs and where it doesn't. Judgment matters more here than volume
  • Experience with integration patterns: REST APIs, webhooks, authentication flows, event-driven architectures
  • Experience pulling, normalizing, and joining data from multiple imperfect sources, and handling the edge cases gracefully
  • Experience defining technical direction where the problem was ambiguous, and carrying it across team boundaries
  • Attention to detail balanced with pragmatism about risk-based prioritization
  • Curiosity, persistence, and comfort operating with minimal structure in an early-stage program

Nice to have:

  • Working knowledge of a security or compliance framework such as PCI DSS, SOX, SOC 2, ISO 27001, or NIST. Prior GRC experience is not required; we can teach the governance side
  • Production-scale LLM or agentic systems experience

You Know

Ideal candidates will have familiarity with some of the technologies in our environment:

  • Languages & Frameworks: Python, Java, Kotlin, Go
  • AI: LLM APIs (we build on Claude), agent frameworks and tool-use patterns such as Model Context Protocol, eval harnesses
  • APIs & Data: HTTP, JSON, gRPC, Protocol Buffers, SQL, Snowflake
  • Infrastructure: AWS, GCP, Kubernetes, Terraform, CI/CD (Buildkite), event-driven architecture

We’re working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is an equal opportunity employer evaluating all employees and job applicants without regard to identity or any legally protected class. We will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and “fair chance” ordinances.

We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible. Want to learn more about what we’re doing to build a workplace that is fair and square? Check out our I+D page.

While there is no specific deadline to apply for this role, U.S. roles are typically open for an average of 55 days before being filled by a successful candidate. Please refer to the date listed at the top of this job page for when this role was first posted.

Block takes a market-based approach to pay, and pay may vary depending on your location. U.S. locations are categorized into one of four zones based on a cost of labor index for that geographic area. The successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. These ranges may be modified in the future.

To find a location’s zone designation, please refer to this resource. If a location of interest is not listed, please speak with a recruiter for additional information.

Zone A:
$180,000—$270,000 USD
Zone B:
$171,000—$256,600 USD
Zone C:
$162,000—$243,000 USD
Zone D:
$153,000—$229,600 USD

Application Guidelines

Privacy Policy

Standard company text repeated across Block's postings is omitted here.

Similar positions

Block
Principal Security Engineer
Block · Bay Area, CA, United States of America
Block
Senior Security Engineer, Platform Security
Block · Bay Area, CA, United States of America
Block
Software Engineer, Program Engineering
Block · Bay Area, CA, United States
Block
Senior GRC Engineer
Block · Bay Area, CA, United States of America
Block
Finance & Strategy Manager
Block · New York, NY, United States of America