Senior Security Engineer, Platform Security

Block Block · Fintech · CA · Remote · 10404 Engineering - Information Security

Senior Platform Security Engineer responsible for securing Block's cloud, compute, and network infrastructure across multiple business units. The role involves architecting and evolving cloud security guardrails, building automation for security issue discovery and measurement, owning the cloud security exception lifecycle, and partnering with platform teams to eliminate security risks. The role also includes developing risk-based prioritization, responding to alerts, and producing quality software in an AI-augmented environment.

What you'd actually do

  1. Architect and evolve cloud security guardrails. Design and implement SCPs, GCP org policies, and IAM controls that shape how Block uses cloud infrastructure for years to come.
  2. Build automation to discover, measure, and contextualize security issues. Develop integrations with CSPM/DSPM tools and internal platforms to surface and prioritize findings.
  3. Own the cloud security exception lifecycle. Build and maintain the tooling and processes that allow teams to request, review, and track security exceptions at scale
  4. Partner with platform teams to deliver solutions that permanently eliminate entire categories of cloud security risk.
  5. Deliver key cloud security assurance functions. Balance the need to remediate critical misconfigurations and sensitive data exposures with being responsible stewards of our developers' time.

Skills

Required

  • 5+ years of experience as a software or security engineer
  • 4+ years of experience securing infrastructure running on AWS and/or GCP at scale
  • Deep experience with Infrastructure-as-Code (Terraform, SCPs, GCP org policies)
  • Experience with cloud security posture management (CSPM) tools (e.g., Wiz)
  • Familiarity with DSPM concepts
  • Strong understanding of IAM (AWS IAM policies, roles, SCPs, permission boundaries; GCP IAM, service accounts, org-level constraints)
  • Experience maturing cloud security posture in large, complex environments
  • Demonstrated ability to deliver complex projects
  • Demonstrated fluency with AI-assisted development tools

Nice to have

  • Experience with Kubernetes security (pod security policies, network policies) in environments like EKS or GKE
  • Familiarity with BI and data exploration tools like Looker and Snowflake
  • Experience building or operating security exception/risk acceptance workflows at scale
  • Familiarity with cloud networking and network segmentation strategies
  • Ability to work well cross-functionally and communicate with diverse audiences
  • Experience supporting multi-business-unit organizations with varying compliance and regulatory requirements

What the JD emphasized

  • securing cloud infrastructure and services at scale
  • Deep experience with Infrastructure-as-Code
  • Experience with cloud security posture management (CSPM) tools
  • Strong understanding of IAM
  • maturing the cloud security posture of large, complex, multi-account/multi-project environments
  • Demonstrated ability to successfully deliver complex, multi-faceted projects from concept to launch
  • Demonstrated fluency with AI-assisted development tools