Senior Security Engineer, Platform Security

Block

San Francisco (CA)

On-site

USD 185,200 - 326,800

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Block is seeking a Senior Platform Security Engineer to enhance our cloud security strategy. This role involves architecting security guardrails and developing automation for security issue management. You will leverage your expertise in AWS and GCP while collaborating across teams.

The ideal candidate will have over 5 years of relevant experience, especially with Infrastructure-as-Code and IAM policies. Join Block in our mission to build tools for an open economy.

Qualifications

  • 5+ years of experience as a software or security engineer.
  • 4+ years of experience securing infrastructure running on AWS and/or GCP at scale.
  • Deep experience with Infrastructure-as-Code and Terraform.
  • Strong understanding of IAM policies and roles.

Responsibilities

  • Architect and evolve cloud security guardrails.
  • Build automation to discover, measure, and contextualize security issues.
  • Own the cloud security exception lifecycle.
  • Partner with platform teams to eliminate cloud security risks.
  • Develop risk-based prioritization using data pipelines.

Skills

Cloud security engineering
Infrastructure as Code
AWS security
GCP security
IAM policies

Tools

Terraform
CSPM tools
GitHub Copilot

Job description

Block builds simple, powerful tools that make progress towards an economy that’s truly open to all.

The Platform Security team is responsible for securing Block's cloud, compute, and network infrastructure across multiple business units, including Square, Cash, and Afterpay. We discover, track, and enable the business to remediate the most critical security risks across Block's cloud ecosystems (AWS and GCP). We drive the creation of cloud security policy and best practices, measure and aggregate deviations from these policies, and develop capabilities to estimate security risk based on cloud signals and business context. This work drives Block's cloud security strategy and is the lens through which Block measures progress of our cloud security posture over time.

We believe that the secure option should be the easiest option for our users. We’re looking for a strong Senior Platform Security Engineer with a deep understanding of securing cloud infrastructure and services at scale to help us execute on this vision.

You Will
  • Architect and evolve cloud security guardrails. Design and implement SCPs, GCP org policies, and IAM controls that shape how Block uses cloud infrastructure for years to come.
  • Build automation to discover, measure, and contextualize security issues. Develop integrations with CSPM/DSPM tools and internal platforms to surface and prioritize findings.
  • Own the cloud security exception lifecycle. Build and maintain the tooling and processes that allow teams to request, review, and track security exceptions at scale.
  • Partner with platform teams to deliver solutions that permanently eliminate entire categories of cloud security risk.
  • Deliver key cloud security assurance functions. Balance the need to remediate critical misconfigurations and sensitive data exposures with being responsible stewards of our developers' time.
  • Develop risk‑based prioritization. Build data pipelines and dashboards that aggregate security signals and help leadership understand posture trends.
  • Respond to and triage cloud security alerts. Support on‑call rotations, investigate findings, and help engineers resolve issues quickly.
  • Produce quality software that stands the test of time and scales across Block's multi‑cloud footprint.
  • Think, build and iterate in an AI‑augmented environment.
You Have
  • 5+ years of experience as a software or security engineer.
  • 4+ years of experience securing infrastructure running on AWS and/or GCP at scale.
  • Deep experience with Infrastructure‑as‑Code. Terraform (including securing Terraform pipelines), SCPs, GCP org policies, and understanding of best practices and pitfalls when deploying guardrails at organizational scale.
  • Experience with cloud security posture management (CSPM) tools such as Wiz, and familiarity with DSPM concepts (sensitive data discovery, classification, and remediation).
  • Strong understanding of IAM. AWS IAM policies, roles, SCPs, permission boundaries; GCP IAM, service accounts, and org‑level constraints.
  • Experience maturing the cloud security posture of large, complex, multi‑account/multi‑project environments.
  • Demonstrated ability to successfully deliver complex, multi‑faced projects from concept to launch.
  • Demonstrated fluency with AI‑assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot, or similar agentic coding tools) in real production work.
Bonus If You Have
  • Experience with Kubernetes security (pod security policies, network policies) in environments like EKS or GKE.
  • Familiarity with BI and data exploration tools like Looker and Snowflake for building security metrics and dashboards.
  • Experience building or operating security exception/risk acceptance workflows at scale.
  • Familiarity with cloud networking and network segmentation strategies.
  • Ability to work well cross‑functionally and communicate with audiences who may not have a security or engineering background.
  • Experience supporting multi‑business‑unit organizations with varying compliance and regulatory requirements.

Block is an equal opportunity employer evaluating all employees and job applicants without regard to identity or any legally protected class. We will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and “fair chance” ordinances. We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible.

Want to learn more about what we’re doing to build a workplace that is fair and square? Check out our I+D page.

Pay ranges: Zone A: $217,800—$326,800 USD. Zone B: $207,000—$310,400 USD. Zone C: $196,100—$294,100 USD. Zone D: $185,200—$277,800 USD.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer
Principal Security Engineer

Block • Austin (TX)

On-site
USD 319,000 - 479,000
Remote work
Flexible time off
Medical insurance
+1
Principal Security Engineer
Principal Security Engineer

Block • San Francisco (CA)

On-site
USD 150,000 - 200,000
Principal Security Engineer
Principal Security Engineer

Block • Seattle (WA)

On-site
USD 180,000 - 240,000
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Block • San Francisco (CA)

On-site
USD 160,700 - 283,600
Healthcare coverage
Health Savings Account
Retirement Plans
+5
Principal Security Engineer Bay Area, CA, US
Principal Security Engineer Bay Area, CA, US

Block, Inc. • San Francisco (CA)

On-site
USD 150,000 - 200,000
Principal Security Engineer
Principal Security Engineer

Block • New York (NY)

On-site
USD 319,000 - 479,000
Principal Security Engineer - Secure by Design (Remote)
Principal Security Engineer - Secure by Design (Remote)

Block • Austin (TX)

On-site
USD 319,000 - 479,000
Remote work
Flexible time off
Medical insurance
+1
Senior Software Engineer, Product Platform
Senior Software Engineer, Product Platform

Block • New York (NY)

On-site
USD 120,000 - 150,000
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Block • New York (NY)

On-site
USD 170,000 - 284,000
Healthcare coverage
Retirement plans
Employee Stock Purchase Program
+1
Senior Software Engineer, Product Platform
Senior Software Engineer, Product Platform

Block • San Francisco (CA)

On-site
USD 120,000 - 150,000