> Markdown version of [/jobs/ext/2709572-block-information-security](https://www.wearedevelopers.com/jobs/ext/2709572-block-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Block Information Security - **Company:** Block, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $217,800.0 - $326,800.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, User Authentication, Spreadsheets, Continuous Integration, Customer Data Management, Data Normalization, Data Warehousing, Protocol Buffers, Hypertext Transfer Protocols (HTTP), JSON, Python (Programming Language), PCI Data Security Standards, SQL Databases, Google Cloud, Large Language Models, Snowflake, Multi-Agent Systems, Backend, Kotlin, Event Driven Architecture, Kubernetes, Data Management, Restful APIs, Terraform, Grpc, Webhooks, Software Version Control, Data Pipelines, Golang, Programming Languages - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-grc-engineer-block-9842926 ## About the Role * 7+ years building production software in backend, platform, data, or security engineering * Multi-year ownership of a production system, including on-call, SLOs, and the maintenance work that starts after launch * Proficiency with at least one of Python, Kotlin, Java, or Go, and comfort reading unfamiliar codebases * Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features) and opinions about where model judgment belongs and where it doesn't. Judgment matters more here than volume * Experience with integration patterns: REST APIs, webhooks, authentication flows, event-driven architectures * Experience pulling, normalizing, and joining data from multiple imperfect sources, and handling the edge cases gracefully * Experience defining technical direction where the problem was ambiguous, and carrying it across team boundaries * Attention to detail balanced with pragmatism about risk-based prioritization Nice to have (optional): * Working knowledge of a security or compliance framework such as PCI DSS, SOX, SOC 2, ISO 27001, or NIST. Prior GRC experience is not required; we can teach the governance side * Production-scale LLM or agentic systems experience ## Description Block Information Security is an engineering-driven team focused on scaling security through innovation. Our Security Governance team designs and promotes the frameworks and standards that safeguard customer data, elevate security considerations across the company, and simplify regulatory and compliance obligations. The team also operates the agent-first platform that turns those frameworks into running systems. Most of governance is a data problem. The risk, control, and asset information needed to answer "are we secure and compliant?" is dispersed across dozens of systems: source control, service registries, identity providers, data warehouses, ticketing, CI/CD. GRC Engineers treat that as an engineering problem. You'll build the data pipelines, integrations, and agentic AI workflows that turn manual governance processes into products that run continuously, produce measurable results, and hold up to audit end to end. You Will * Build and operate the pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from systems of record across Block, including source control, the service registry, identity, ticketing, data platforms, and CI/CD * Translate security standards and compliance requirements into policy-as-code: enforceable, testable rules that run continuously. For example, "every production service has an accountable owner" becomes a versioned, tested check instead of a quarterly spreadsheet * Design agentic AI workflows that pair LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment * Build the evals, benchmarks, and calibration harnesses that keep automated governance honest * Automate evidence collection and continuous control monitoring to replace point-in-time audit preparation * Define the technical approach for ambiguous, cross-team problem spaces. This is an early-stage program, and you will frame problems as often as you solve them * Partner with Security Governance Partners, Compliance, and Engineering teams to find the manual processes most worth turning into product * Help govern Block's own AI systems: the same platform that automates governance also assesses the autonomy and safety of Block's agents * Contribute to technical design discussions, evaluating the security and reliability properties of the platform itself, * AI: LLM APIs (we build on Claude), agent frameworks and tool-use patterns such as Model Context Protocol, eval harnesses * APIs & Data: HTTP, JSON, gRPC, Protocol Buffers, SQL, Snowflake * Infrastructure: AWS, GCP, Kubernetes, Terraform, CI/CD (Buildkite), event-driven architecture We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is an equal opportunity employer evaluating all employees and job applicants without regard to identity or any legally protected class. We will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and "fair chance" ordinances., We may use automated AI tools to evaluate job applications for efficiency and consistency. These tools comply with local regulations, including bias audits, and we handle all personal data in accordance with state and local privacy laws. ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Boosting OpenSearch Performance: gRPC Search in Action](https://www.wearedevelopers.com/videos/1964-boosting-opensearch-performance-grpc-search-in-action) - [Boosting OpenSearch Performance: gRPC Search in Action](https://www.wearedevelopers.com/videos/1935-boosting-opensearch-performance-grpc-search-in-action) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [From Hype to Code: Real Blockchain Use Cases for Developers](https://www.wearedevelopers.com/magazine/620-from-hype-to-code-real-blockchain-use-cases-for-developers) - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering)