Senior GRC Engineer

Block
Bay Area, CA, United States of America / US - CA - Bay Area - Remote2026-09-01

About the job

Block Information Security is an engineering-driven team focused on scaling security through innovation. Our Security Governance team designs and promotes the frameworks and standards that safeguard customer data, elevate security considerations across the company, and simplify regulatory and compliance obligations. The team also operates the agent-first platform that turns those frameworks into running systems.

Most of governance is a data problem. The risk, control, and asset information needed to answer "are we secure and compliant?" is dispersed across dozens of systems: source control, service registries, identity providers, data warehouses, ticketing, CI/CD. GRC Engineers treat that as an engineering problem. You'll build the data pipelines, integrations, and agentic AI workflows that turn manual governance processes into products that run continuously, produce measurable results, and hold up to audit end to end.

Responsibilities

Build and operate the pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from systems of record across Block, including source control, the service registry, identity, ticketing, data platforms, and CI/CD

Translate security standards and compliance requirements into policy-as-code: enforceable, testable rules that run continuously

Design agentic AI workflows that pair LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment

Build the evals, benchmarks, and calibration harnesses that keep automated governance honest

Automate evidence collection and continuous control monitoring to replace point-in-time audit preparation

Define the technical approach for ambiguous, cross-team problem spaces

Qualifications

Minimum

7+ years building production software in backend, platform, data, or security engineering

Multi-year ownership of a production system, including on-call, SLOs, and the maintenance work that starts after launch

Proficiency with at least one of Python, Kotlin, Java, or Go, and comfort reading unfamiliar codebases

Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features) and opinions about where model judgment belongs and where it doesn't

Experience with integration patterns: REST APIs, webhooks, authentication flows, event-driven architectures

Experience pulling, normalizing, and joining data from multiple imperfect sources, and handling the edge cases gracefully

Experience defining technical direction where the problem was ambiguous, and carrying it across team boundaries

Attention to detail balanced with pragmatism about risk-based prioritization

Preferred

Working knowledge of a security or compliance framework such as PCI DSS, SOX, SOC 2, ISO 27001, or NIST

Production-scale LLM or agentic systems experience