Back to Jobs
Bastion
Engineering & Architecture 18h ago

Security Engineer

Bastion
New York CityNew York City
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

CybersecurityKubernetesTerraformGoAWS

Want to know if you're a match for this job?

Calculate My Match Score

About Bastion: Bastion provides regulated infrastructure for stablecoin operations, including custodial wallets, global payment orchestration, and stablecoin issuance. Their platform combines independent product usage or end-to-end flows, with compliance and risk controls embedded directly into the system. They support customers with their own licenses via compliance and financial operations.

Overview

We are seeking a hands-on Security Engineer to join our security team as its second engineer. You will collaborate with our Staff Security Engineer and report to our CTO/CISO.

The foundation is already established: SOC 2 Type II report, conditional approval from the OCC for a national trust charter, a SIEM and detection pipeline, runtime security for Kubernetes, and time-limited, auditable access to production. Your role will involve scaling security engineering across infrastructure, product and application security, detection and response, and the technical aspects of GRC (SOC 1, SOC 2, OCC, and MiCA/DORA).

As a 40-person startup, your work will directly protect our users and partners. You will build on a strong foundation, highlighted in an AWS case study. Our platform is almost entirely written in Go, runs on Kubernetes (EKS) in AWS, and is managed with Terraform. Security services are also written in Go. You must be capable of writing production-grade code. Expect to spend most of your time writing code, reviewing design documents, and building security tooling and middleware that engineers can easily integrate into any service.

This role can be remote within the US, though we prefer candidates in NYC or open to relocation.

Work to Be Done

Instead of a list of requirements, we provide a directional look into the first 30, 90, and 180 days on the job.

We are a startup, so the pace is fast, and the specific work will evolve. Successful candidates will find ways to contribute from their first week and be fully productive by their third month. You need to be comfortable with this dynamic.

First 30 days: Learn and ship from week one

  • Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services
  • Contribute security feedback to at least one engineering design document
  • Ship your first security fix, guardrail, or detection to production
  • Learn our incident response and on-call procedures, and join the security rotation
  • Get up to speed on our Data Loss Prevention (DLP) program and start contributing to its rollout
  • Outcomes:
    • Production code shipped in your first month
    • Join the security on-call rotation, ensuring real coverage for the team

By 90 days: Own initiatives independently

  • Own at least one security domain end-to-end, such as Kubernetes and cloud hardening, application security in CI, or detection engineering
  • Write and tune detections as code, add new telemetry sources, and reduce alert noise
  • Ship your first reusable security library or middleware in Go (e.g., authorization, tenant isolation, request signing, or input validation) and get it adopted by at least one service team
  • Be the security reviewer on design documents for new product features and architecture changes
  • Deliver control automation and evidence for an active audit or regulatory workstream (SOC 1, SOC 2, OCC)
  • Help launch and triage our bug bounty program, and grow our DLP coverage and policies
  • Outcomes:
    • Measurable risk reduction from controls, fixes, or detections you built
    • Recognized as the owner of at least one security domain

By 180 days: Scale your impact

  • Drive multi-quarter initiatives such as default-deny service-to-service networking, security policy evaluation, or just-in-time, granular access across more systems
  • Expand our Kubernetes cluster and container security, including image scanning and signing, admission policies, pod security standards, and runtime protection
  • Grow a shared set of security middleware and libraries that is adopted across the codebase, making the secure path the easy path for our Go engineers
  • Help expand our compliance scope with automation instead of spreadsheets
  • Turn tabletop exercises and resilience testing into concrete fixes
  • Join cross-functional planning and influence the security roadmap
  • Outcomes:
    • Function-wide improvements to how we build and ship secure systems
    • Clear, measurable business impact from your security work

Some challenges you might tackle:

  • Building reusable security building blocks that make secure defaults easy across our platform
  • Protecting the critical systems at the core of a regulated stablecoin platform
  • Turning OCC and MiCA/DORA requirements into controls that are engineered, tested, and continuously evidenced
  • Building high-signal detections across cloud, Kubernetes, identity, endpoint, and SaaS telemetry
  • Hardening our Kubernetes clusters and container supply chain, from build to admission to runtime, without slowing deployments

How would you rate this job post?

See what other professionals think about this role.

banner

Bastion (operating at bastion.com) is a financial institution building regulated stablecoin infrastructure for modern money movement. Founded in 2023 by Nassim Eddequiouaq and headquartered in Campbell, Bastion blends the best of web2 and web3 technologies to broaden opportunities for organizations and their customers. Under the hood, Bastion's platform securely issues, custodies, moves, and converts digital assets, under its licenses or its customers' own. This allows global enterprises to leverage trusted stablecoin infrastructure for modern money movement. Backed by $39.6M in funding from Coinbase and Andreessen Horowitz.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Security Engineer at Bastion | HireSkys