- Company Name
- Block MB
- Job Title
- Security Engineer - Governance, Risk & Compliance
- Job Description
-
**Job Title:** Security Engineer – Governance, Risk & Compliance
**Role Summary:**
Design, develop, and maintain automated, code‑driven compliance solutions that embed security controls into cloud infrastructure and CI/CD pipelines. Collaborate with cross‑functional teams to operationalize governance, reduce manual audit effort, and provide real‑time risk visibility.
**Expectations:**
- Deliver scalable automation for evidence collection, control monitoring, and compliance reporting.
- Implement infrastructure‑as‑code guardrails and policy‑as‑code across cloud environments.
- Support and lead audit processes (SOC 2, PCI, SOX) with minimal manual intervention.
- Continuously improve compliance effectiveness through dashboards, analytics, and risk trend analysis.
**Key Responsibilities:**
- Build and maintain automation scripts/tools (Python, Go, TypeScript) for compliance evidence and reporting.
- Create and enforce cloud‑native guardrails using Terraform and policy‑as‑code frameworks.
- Integrate compliance validation into CI/CD pipelines and cloud platforms (primarily GCP).
- Develop dashboards and analytical reports to track control effectiveness and risk metrics.
- Partner with security, engineering, and product teams to embed compliance requirements early in design and deployment.
- Lead audit preparation and execution, automating evidence generation for SOC 2, PCI, SOX, ISO, NIST, etc.
- Evaluate and integrate security tooling (e.g., Splunk, Datadog, vulnerability scanners) to enhance monitoring.
**Required Skills:**
- Strong programming experience in Python, Go, or TypeScript; API integration expertise.
- Proficiency with cloud platforms (GCP, AWS, or Azure) and Infrastructure‑as‑Code tools, especially Terraform.
- Hands‑on experience designing or operating compliance programs (SOC 2, ISO, PCI, SOX, NIST) in cloud environments.
- Familiarity with modern security monitoring tools (Splunk, Datadog, vulnerability scanners).
- Problem‑solving orientation focused on building automated solutions over manual workarounds.
- Ability to collaborate effectively across security, engineering, and product teams.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field (or equivalent practical experience).
- Relevant certifications are preferred (e.g., CISSP, CISM, CISA, Cloud Security Alliance CCSK, GCP/AWS/Azure security certifications).