Is SHA-256 safe for proof-of-work?

As far as I know SHA-2 was not designed to be used as a proof-of-work algorithm. Could we find a way to generate a block easily without doing a trillion trillion hashes?