Principal Security Engineer
BlockBay Area2d ago
SecurityEngineeringremotecurated-jd
Job description
Principal Security Engineer at Block.
About the role
You will serve as a technical leader reporting to the CISO, defining the security strategy for software development across the organization. This role involves guiding architectural decisions and fostering a security-first culture to protect core products and infrastructure.
Key facts
What you'll do
- Architect and build software solutions to address high-level security risks like technology fragmentation.
- Create a multi-year technical roadmap for software security.
- Develop shared security infrastructure to reduce data sprawl and overpermissioning across business units including Square, Cash App, and TBD.
- Oversee security for critical systems, such as tokenization platforms, to ensure performance and scalability.
- Direct the security strategy for mobile platforms and product ecosystems.
- Implement security reliability engineering practices to boost system resilience.
- Perform threat modeling and security architecture reviews during the development lifecycle.
- Mentor engineers on system design, technical execution, and security best practices.
Requirements
- 10+ years of experience in production software development and service delivery.
- 5+ years of experience focused on scaling security practices within a modern technology environment.
- Proven technical leadership at a Principal level or equivalent (L8+).
- Mastery of system design and architecture for complex, ambiguous problems.
- Expertise in security vulnerabilities, risk mitigation, and controls in high-volume transaction environments.
- Ability to write production-grade code or scripts for security tooling and automation.
- Strong communication skills to influence executive leadership and engineering teams.
Nice to have
- Experience driving technical initiatives across multiple organizational boundaries.
- Background in fintech, payments, or cryptocurrency and bitcoin.
- Experience building systems that allow security resources to scale sub-linearly with business growth.
Skills & tools
- Software Security Engineering
- Secure SDLC
- Threat Modeling
- System Architecture
- Security Reliability Engineering (SecRelEng)
- Production-level coding/scripting
Practical notes
- Compensation is market-based and determined by skills, experience, and location.
- Candidates may submit up to 9 active applications every 60 days.
- Reapplications for the same role are permitted 90 days after a previous review.
- Automated AI tools may be used during the application evaluation process.
- Benefits include remote work options, medical insurance, flexible time off, and retirement savings.