Security Engineer, Business Continuity & Risk
Block (Square) · Bay Area, CA, United States of America
About this role
## Security Engineer, Business Continuity & Risk ### About the team Square Financial Services, Inc. (SFS) is Block’s bank, providing lending and FDIC-insured deposit products to individuals and small businesses nationwide. SFS Risk Management is scaling vendor security, third-party risk, and business continuity through innovation—designing and promoting frameworks, standards, and oversight that elevate security considerations among vendors, simplify regulatory obligations, and ensure resilience in business operations. ### The role Governance is a data problem. You’ll build data pipelines, integrations, and agentic AI workflows that turn manual governance processes into continuously running products—producing measurable results and holding up to audit end to end. ### You will - Own and operationalize a SFS third-party risk management and business continuity program. - Define the technical approach for ambiguous, cross-team problem spaces (early-stage program; you’ll frame problems as often as you solve them). - Build and operate pipelines/integrations that aggregate, normalize, and join risk, control, and asset signals from systems of record across Block and SFS (e.g., source control, service registry, identity, ticketing, data platforms). - Translate standards and compliance requirements into **policy-as-code** (enforceable, testable rules that run continuously). - Design agentic AI workflows that combine LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment. - Automate evidence collection and continuous control monitoring to replace point-in-time audit preparation. - Partner with Security, Procurement, Resilience, and Engineering teams to identify the most valuable manual processes to productize. - Contribute to technical design discussions, evaluating security and reliability properties of the platform itself. ### You have - Third-party risk management and business continuity experience. - 4+ years building production software in backend, platform, data, or software engineering. - Multi-year ownership of a production system (including on-call, SLOs, and post-launch maintenance). - Proficiency with at least one of: Python, Kotlin, Java, or Go (and comfort reading unfamiliar codebases). - Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features) and strong opinions on where model judgment belongs. - Integration experience: REST APIs, webhooks, authentication flows, event-driven architectures. - Experience pulling, normalizing, and joining data from multiple imperfect sources, handling edge cases. - Ability to define technical direction when the problem is ambiguous and carry it across team boundaries. - Attention to detail with pragmatic, risk-based prioritization. - Curiosity, persistence, and comfort operating with minimal structure in an early-stage program. ### Nice to have - Knowledge of security/compliance frameworks such as PCI DSS, SOX, SOC 2, ISO 27001, or NIST (GRC experience not required). - Production-scale LLM or agentic systems experience. ### You know (examples of the environment) - **Languages/Frameworks:** Python, Java, Kotlin, Go - **AI:** LLM APIs (built on Claude), agent frameworks, tool-use patterns (e.g., Model Context Protocol), eval harnesses - **APIs/Data:** HTTP, JSON, gRPC, Protocol Buffers, SQL, Snowflake - **Infrastructure:** AWS, GCP, Kubernetes, Terraform, CI/CD (Buildkite), event-drive
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.