You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Bastion

Senior Security Engineer

  • Remote
  • 6+ years

Salary

$180,000 - 250,000/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

About Bastion

Bastion provides the regulated infrastructure businesses need to hold, move, and issue stablecoins. Our platform combines custodial wallets, global payment orchestration, and stablecoin issuance. Customers can use each product independently or connect them into a single end-to-end flow.

We operate through our own regulated entities, with compliance and risk controls built directly into the platform. We can also support customers operating under their own licenses with the compliance and financial operations required to run their programs.

We're looking for a hands-on Senior Security Engineer to join our security team as its second engineer. You'll work alongside our Staff Security Engineer and report to our CTO/CISO.

The foundation is already in place: a SOC 2 Type II report, conditional approval from the OCC for a national trust charter, a SIEM and detection pipeline, runtime security for Kubernetes, and time-limited, auditable access to production. You'll help scale that program across security engineering, infrastructure, product and application security, detection and response, and the technical side of GRC (SOC 1, SOC 2, OCC, and MiCA/DORA).

As a 40-person company, your work will directly protect our users and partners. You'll build on a strong foundation (we're featured in this AWS case study ). Our platform is almost entirely Go, running on Kubernetes (EKS) in AWS and managed with Terraform, and our security services are written in Go too. You must be able to write production code. Expect to spend most of your time writing code, reviewing design docs, and building security tooling and middleware that engineers can easily drop into any service.

This role can be remote within the US, though we'd prefer someone in NYC or open to relocating.

Work to Be Done

Instead of a list of requirements, we want to give you a directional look into the first 30, 90, and 180 days on the job.

We are a startup, so the pace is fast and the specific work will change. People who thrive here find ways to contribute in their first week and are fully productive by their third month. You need to be okay with that.

If you think this is something you can handle, we'll be excited to speak with you.

First 30 days: Learn and ship from week one

Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services

Contribute security feedback to at least one engineering design doc

Ship your first security fix, guardrail, or detection to production

Learn our incident response and on-call procedures, and join our security rotation

Get up to speed on our DLP program and start contributing to its rollout

Outcomes

Production code shipped in your first month

Join the security on-call rotation, so the team has real coverage

By 90 days: Own initiatives independently

Own at least one security domain end to end, such as Kubernetes and cloud hardening, application security in CI, or detection engineering

Write and tune detections as code, add new telemetry sources, and reduce alert noise

Ship your first reusable security library or middleware in Go (for example authorization, tenant isolation, request signing, or input validation) and get it adopted by at least one service team

Be the security reviewer on design docs for new product features and architecture changes

Deliver control automation and evidence for an active audit or regulatory workstream (SOC 1, SOC 2, OCC)

Help launch and triage our bug bounty program, and grow our DLP coverage and policies

Outcomes

Measurable risk reduction from controls, fixes, or detections you built

Recognized as the owner of at least one security domain

By 180 days: Scale your impact

Drive multi-quarter initiatives such as default-deny service-to-service networking, security policy evaluation, or just-in-time, granular access across more systems

Expand our Kubernetes cluster and container security, including image scanning and signing, admission policies, pod security standards, and runtime protection

Grow a shared set of security middleware and libraries that is adopted across the codebase, so the secure path is the easy path for our Go engineers

Help expand our compliance scope with automation instead of spreadsheets

Turn tabletop exercises and resilience testing into concrete fixes

Join cross-functional planning and influence the security roadmap

Outcomes

Function-wide improvements to how we build and ship secure systems

Clear, measurable business impact from your security work

Some challenges you might tackle

Building reusable security building blocks that make secure defaults easy across our platform

Protecting the critical systems at the core of a regulated stablecoin platform

Turning OCC and MiCA/DORA requirements into controls that are engineered, tested, and continuously evidenced

Building high-signal detections across cloud, Kubernetes, identity, endpoint, and SaaS telemetry

Hardening our Kubernetes clusters and container supply chain, from build to admission to runtime, without slowing deploys

If you think this is something you can handle, we will be excited to speak with you.

Where you’d work

Fully remote

You can work from

  • United States

About the company

Bastion

  • Industry: FinTech

Your chances

We've checked whether it's still hiring and how crowded it is.

  • 20 checks run
  • 0 red flags

Still hiring?

13 checks

No red flags

How crowded?

7 checks

No red flags

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details12 facts · Role, Location, Compensation, Employment, Company
Tech stack
  • Go
  • AWS
  • Kubernetes
  • Terraform
Seniority
Senior
Type
Full-time
Industry
FinTech
Specialty
Security
Region
United States
Show 6 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
6+ years
Tech stack
  • Go
  • AWS
  • Kubernetes
  • Terraform

Location

Work model
Remote
Region
United States
Remote from
  • United States

Compensation

Salary
$180,000 - 250,000 / year
Pay period
Annual

Employment

Type
Full-time

Company

Industry
FinTech

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason