Block Logo

Block

Senior Security Engineer, Offensive Security

Posted Yesterday
Remote
Hybrid
7 Locations
Senior level
Remote
Hybrid
7 Locations
Senior level
Join Block's Offensive Security Team as a Senior Security Engineer, where you will lead security initiatives, conduct penetration tests, and communicate findings to cross-functional teams. Your role includes mentoring, managing multiple projects, and improving security designs to safeguard systems and uphold customer trust.
The summary above was generated by AI

Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups and around the globe, spanning time zones and disciplines to develop inclusive People policies, forecast finances, give legal counsel, safeguard systems, nurture new initiatives, and more. Every challenge creates possibilities, and we need different perspectives to see them all. Bring yours to Block.
The Role
Protect the Future of Finance:
Join Block's Offensive Security Team as a Senior Security Engineer, driving impactful security initiatives across teams and organizational boundaries. You'll identify critical areas to improve, applying your expertise to safeguard our systems and uphold customer trust. Your work will shape our security posture, keep us ahead of emerging threats, and secure the financial systems of tomorrow.
About the team:
Offensive Security & Design team emulates attackers to find vulnerabilities throughout Block, and inform remediation. We surface issues and offer technical expertise, without mandating deadlines. We don't throw security problems over the wall. We understand the struggle of our engineers and provide contextual guidance for a diverse, complex and cutting edge tech stack that enables the business. We don't work in isolation, engineering and security teams at Block are your partners. We collaborate with our partners at every opportunity we can find and place the needs of our partners at the highest priority.
Your Mission:
You'll immerse yourself in our tech stack to gain an understanding of our infrastructure, applications and services, including their security boundaries.
You Will

  • Identify and lead critical security initiatives.
  • Conduct penetration tests, source code reviews, threat models, and design reviews to identify and mitigate security risks. Create exploits that demonstrate impact.
  • Commit small PRs to directly fix security issues, rather than waiting for teams to address them.
  • Identify gaps in existing designs and improve them to ensure security is integrated from the ground up.
  • Communicate critical security findings to cross-functional teams, providing context, applicable remediation steps, and hands-on guidance throughout the resolution process.
  • Lift skills and expertise of your teammates
  • Be an excellent source of insights and wisdom on security topics.
  • Support incident response efforts and reproduce bug bounty reports to ensure analysis resolutions.
  • Guide the direction of the team to ensure team's success.


You Have

  • 10+ years experience in penetration testing, threat modeling and security engineering.
  • Expertise in appsec and cloudsec and are proficient in infrastructure as code, CI/CD and supply chain security.
  • The ability to work independently, managing multiple projects with ease and navigating technically complex apps and services.
  • Experience mentoring others on the team
  • [Even Better]
  • Expertise in modern secure design patterns
  • Knowledge about cryptocurrencies, wallets and storage.
  • Understanding of GenAI security topics
  • Conference presentations on AppSec/OffSec topics
  • Published CVEs / responsibly disclosed bugs


What You'll Get

  • The opportunity to make a real impact on the security of our applications and the financial industry as a whole.
  • A collaborative and dynamic work environment with an exceptional team of security engineers.
  • Freedom to do security research that has the potential to have a deep impact on Block.
  • An environment where conference presentations are highly encouraged.


We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is an equal opportunity employer evaluating all employees and job applicants without regard to identity or any legally protected class. We also consider qualified applicants with criminal histories for employment on our team, and always assess candidates on an individualized basis.We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible. Want to learn more about what we're doing to build a workplace that is fair and square? Check out our I+D page .Block will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and "fair chance" ordinances.
Block takes a market-based approach to pay, and pay may vary depending on your location. U.S. locations are categorized into one of four zones based on a cost of labor index for that geographic area. The successful candidate's starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. These ranges may be modified in the future.
To find a location's zone designation, please refer to this resource . If a location of interest is not listed, please speak with a recruiter for additional information.
Zone A:
$217,800 - $326,800 USD
Zone B:
$207,000 - $310,400 USD
Zone C:
$196,100 - $294,100 USD
Zone D:
$185,200 - $277,800 USD
Every benefit we offer is designed with one goal: empowering you to do the best work of your career while building the life you want. Remote work, medical insurance, flexible time off, retirement savings plans, and modern family planning are just some of our offering. Check out our other benefits at Block.
Block, Inc. (NYSE: XYZ) builds technology to increase access to the global economy. Each of our brands unlocks different aspects of the economy for more people. Square makes commerce and financial services accessible to sellers. Cash App is the easy way to spend, send, and store money. Afterpay is transforming the way customers manage their spending over time. TIDAL is a music platform that empowers artists to thrive as entrepreneurs. Bitkey is a simple self-custody wallet built for bitcoin. Proto is a suite of bitcoin mining products and services. Together, we're helping build a financial system that is open to everyone.

Top Skills

Appsec
Cloudsec
Penetration Testing
Threat Modeling

Similar Jobs at Block

21 Hours Ago
Remote
Hybrid
7 Locations
Senior level
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
As an Insider Risk Security Engineer, you will detect, analyze, and mitigate internal threats by developing and maintaining advanced security tools and incident response strategies. Collaborating with various teams, you will implement security policies, perform assessments, and refine risk mitigation measures to safeguard the company's assets and data.
Top Skills: BashPowershellPython
7 Days Ago
Remote
Hybrid
7 Locations
Senior level
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
The role involves enhancing security for Block's analytics and AI data platforms through software development and collaboration with data platform teams. Responsibilities include identifying security gaps, documenting risks, and implementing resilient software changes.
Top Skills: Machine LearningSecurity Software Engineering
2 Hours Ago
Remote
Hybrid
7 Locations
Expert/Leader
Expert/Leader
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
As a Staff Android Engineer on the Order Hub team, you will lead the design and implementation of features for the Order Manager product, collaborate with various teams to enhance order management, mentor junior engineers, and ensure engineering excellence in a dynamic work environment.
Top Skills: JavaKotlin

What you need to know about the Vancouver Tech Scene

Raincouver, Vancity, The Big Smoke — Vancouver is known by many names, and in recent years, it has gained a reputation as a growing hub for both tech and sustainability. Renowned for its natural beauty, the city has become a magnet for professionals eager to create environmental solutions, and with an emphasis on clean technology, renewable energy and environmental innovation, it's attracted companies across various industries, all working toward a shared goal: advancing clean technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account