About this role
The Aladdin Platform Engineering – Engineering Services team builds the platforms, pipelines, and developer tooling that thousands of engineers across BlackRock use every day to design, build, and ship software. Security is engineered into that path rather than inspected at the end of it: the same teams that own build systems, artifact repositories, and deployment pipelines also own the guardrails, evidence, and automated controls that make secure delivery the default.
You will lead the cybersecurity engineering function inside this group, working alongside platform engineering, product management, risk, and the firm’s information security organization to protect a large, cloud-native, AI-enabled, highly regulated financial services firm.
Your role and impact
As Director for Cybersecurity Engineering, you’ll set the technical strategy for how security is built into software delivery and cloud infrastructure at scale. Software supply chain integrity is your first principle: every artifact the firm ships should carry verifiable provenance, and every release should be attested — signed, traceable to its source and build environment, and admissible as evidence without anyone assembling it after the fact. You’ll lead BlackRock toward that future state, moving the organization from periodic inspection of what was built to continuous, cryptographic proof of how it was built, with trust decisions made against attestations rather than assumptions.
You’ll treat DevSecOps as the operating principle that makes this achievable — policy as code, automated enforcement in continuous integration and delivery pipelines, and time-boxed exceptions with audit-ready evidence generated automatically. You’ll extend that same provenance and trust model to AI-assisted development and agentic workflows, where model-generated code, prompt injection, and non-human identities create new classes of exposure and demand policy-driven defense in depth.
Your responsibilities
No matter your role at BlackRock, you’ll be expected to apply sound judgement and critical thinking to solve complex problems, stay curious and adaptable as the business evolves, and take end-to-end ownership of outcomes that matter to clients. The scope of this role also includes the following responsibilities:
- Own the software supply chain security strategy end to end — source integrity, dependency and artifact provenance, software bills of materials, signing, and verifiable build attestation across the firm’s technology estate
- Secure the build and release path itself, hardening build systems, artifact repositories, and deployment pipelines as high-value targets, and enforcing trust decisions at admission based on attested provenance rather than implicit trust
- Define and implement the security model for agentic and AI-assisted workflows — least-privilege identities for agents, bounded model and data access, provenance for machine-generated code, and guardrails that hold as autonomy increases
- Embed automated controls across the delivery lifecycle, including threat modeling, static and dynamic analysis, software composition analysis, and container and infrastructure-as-code scanning, with clear rules for what blocks versus warns
- Partner with information security, risk, and audit to translate regulatory and control requirements into engineered, continuously evidenced guardrails, and report progress, coverage, and residual risk to senior technology and business leaders
- Build, lead, and mentor a team of security engineers, and grow a network of security champions embedded in delivery teams
You have…
- 10+ years in security engineering, platform engineering, or application security, including experience leading teams in a large, regulated enterprise
- Deep, hands-on understanding of software supply chain security — build provenance and attestation, artifact signing and verification, dependency risk, and secure software development lifecycle frameworks
- Strong command of DevSecOps practice, including CI/CD pipeline security, policy as code, and automated control enforcement at scale
- Strong cloud-native security expertise across containers, orchestration, serverless, microservices, and APIs, with fluency in identity, zero trust, and secure architecture patterns
- Practical experience securing AI and machine learning workloads or agentic systems, or a demonstrated ability to reason about emerging AI-related risk in software delivery
- A track record of influencing engineering organizations without owning them — building adoption of guardrails developers actually want to use — with excellent communication skills across executive, regulatory, and engineering audiences
- Bachelor’s degree in a related technical field or equivalent practical experience; industry certifications such as CISSP, CCSP.
Our benefits
To help you stay energized, engaged and inspired, we offer a wide range of benefits including a strong retirement plan, tuition reimbursement, comprehensive healthcare, support for working parents and Flexible Time Off (FTO) so you can relax, recharge and be there for the people you care about.
Our hybrid work model
BlackRock’s hybrid work model is designed to enable a culture of collaboration and apprenticeship that enriches the experience of our employees, while supporting flexibility for all. Employees are currently required to work at least 4 days in the office per week, with the flexibility to work from home 1 day a week. Some business groups may require more time in the office due to their roles and responsibilities. We remain focused on increasing the impactful moments that arise when we work together in person – aligned with our commitment to performance and innovation. As a new joiner, you can count on this hybrid model to accelerate your learning and onboarding experience here at BlackRock.
Guidance on AI use for candidates
At BlackRock, AI has long been part of how we work – enhancing decision-making, improving operations, and helping us deliver better outcomes for clients. We encourage candidates to use AI thoughtfully to learn, prepare, and work more effectively; but during our interview process, we want to focus on getting to know you through your own experiences, thinking, and judgment. To support you, we’ve provided guidance on when and how to use AI during our hiring process so you can approach each step with confidence and showcase your best self.
About BlackRock
At BlackRock, we are all connected by one mission: to help more and more people experience financial well-being. Our clients, and the people they serve, are saving for retirement, paying for their children’s educations, buying homes and starting businesses. Their investments also help to strengthen the global economy: support businesses small and large; finance infrastructure projects that connect and power cities; and facilitate innovations that drive progress.
This mission would not be possible without our smartest investment – the one we make in our employees. It’s why we’re dedicated to creating an environment where our colleagues feel welcomed, valued and supported with networks, benefits and development opportunities to help them thrive.
To learn more about BlackRock, please visit Careers.BlackRock.com. We also encourage you to get to know us on LinkedIn, Instagram, YouTube, X, and TikTok.
BlackRock is proud to be an equal opportunity workplace. We are committed to equal employment opportunity to all applicants and existing employees, and we evaluate qualified applicants without regard to race, creed, color, national origin, sex (including pregnancy and gender identity/expression), sexual orientation, age, ancestry, physical or mental disability, marital status, political affiliation, religion, citizenship status, genetic information, veteran status, or any other basis protected under applicable federal, state, or local law. View the EEOC’s Know Your Rights poster and its supplement and the pay transparency statement.
BlackRock is committed to full inclusion of all qualified individuals and to providing reasonable accommodations or job modifications for individuals with disabilities. If reasonable accommodation/adjustments are needed throughout the employment process, please email [email protected]. All requests are treated in line with our privacy policy.
BlackRock will consider for employment qualified applicants with arrest or conviction records in a manner consistent with the requirements of the law, including any applicable fair chance law.Skills Required
- 10+ years in security engineering, platform engineering, or application security, including leadership in a large, regulated enterprise
- Deep hands-on understanding of software supply chain security including provenance, attestation, artifact signing, dependency risk, and SBOMs
- Strong command of DevSecOps practices including CI/CD pipeline security, policy-as-code, and automated control enforcement at scale
- Cloud-native security expertise across containers, orchestration, serverless, microservices, APIs, identity, and zero trust
- Practical experience securing AI/ML workloads or agentic systems, or demonstrated ability to reason about emerging AI-related risks
- Experience embedding automated controls across the delivery lifecycle (threat modeling, static/dynamic analysis, SCA, container and IaC scanning)
- Proven ability to influence engineering organizations and drive adoption of security guardrails without direct ownership
- Bachelor's degree in a related technical field or equivalent practical experience
- Industry certifications such as CISSP or CCSP
BlackRock Compensation & Benefits Highlights
-
Retirement Support — A 401(k)/Retirement Savings Plan with a stated company match formula (subject to plan caps) alongside an Employee Stock Purchase Plan is prominently featured. Feedback suggests these elements make the financial-wellness offering a notable strength among large employers.
-
Parental & Family Support — Paid parental leave of at least 16 weeks for primary caregivers, plus adoption support, fertility benefits, and child/elder back‑up care, is highlighted across materials. Offerings are substantial, with specifics varying by location.
-
Leave & Time Off Breadth — Flexible Time Off for many U.S. salaried roles, paired with sick and bereavement leave, provides generous time‑away options. Wellness resources such as free access to Calm and an Employee Assistance Program further support rest and recovery.
BlackRock Insights
What We Do
As the world’s largest asset manager, BlackRock partners with investors around the globe to help them (and those on whose behalf they invest) plan for life’s most important goals – like retirement, home ownership and their children’s education. Our clients range from governments, foundations and other large institutions to those investing on behalf of individuals, including firefighters, nurses, teachers and factory workers. BlackRock was founded with the idea of creating a better asset management firm — one that was purpose-driven, focused on clients and risk management, and propelled by data and technology. Our breakthrough Aladdin® platform is BlackRock’s technological backbone, helping investors see and manage their whole portfolios in one place – from constructing investments to monitoring risk and executing trades. Used by hundreds of external institutions around the world, Aladdin combines powerful analytics and a common language to help investment teams make faster, more informed decisions across public and private markets. It’s a key part of our business and one of the reasons we’re trusted to manage more assets than any other investment manager today. At BlackRock, we challenge conventions and raise the bar for what’s possible. We harness technology to unlock new solutions, simplify complexity, and deliver investment strategies that meet people where they are. Whether it’s retirement planning, wealth building or navigating market shifts, we’re here to help clients invest more easily, more affordably and with more choice as we chart a path toward financial well-being together. Learn more: Careers.BlackRock.com
Why Work With Us
Without our people, technology is irrelevant. When we combine the power of people with the power of technology, we amplify our ability to create better outcomes for our employees, clients, shareholders and society alike.
Gallery
BlackRock Teams
BlackRock Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
BlackRock has 25,000 employees across more than 100 offices in over 40 countries around the world.






