CronJobs

security jobs

Security Engineer

Bastion · US Remote

remoteunknown$180,000–$250,000Posted Sep 28, 2026GoKubernetesAWSTerraformSIEMDockerEKS

Apply on the employer site

About this role

**Security Engineer — Bastion** **About Bastion** Bastion provides regulated infrastructure businesses need to hold, move, and issue stablecoins. Our platform combines custodial wallets, global payment orchestration, and stablecoin issuance. Customers can use each product independently or connect them into a single end-to-end flow. We operate through our own regulated entities, with compliance and risk controls built directly into the platform. **Overview** We’re looking for a hands-on **Security Engineer** to join our security team as its second engineer. You’ll work alongside our Staff Security Engineer and report to our **CTO/CISO**. We already have a strong foundation, including **SOC 2 Type II**, **OCC conditional approval** for a national trust charter, a **SIEM and detection pipeline**, **Kubernetes runtime security**, and **time-limited, auditable access** to production. This is a **Go + Kubernetes** environment (EKS on AWS, managed with Terraform). You’ll spend most of your time **writing production code**, reviewing design docs, and building security tooling and middleware that engineers can easily adopt. **Location** Remote within the US is possible, though we prefer **NYC** or someone open to relocating. --- ## What you’ll do (first 30 / 90 / 180 days) ### First 30 days - Get hands-on with our **Go codebase**, **AWS + Kubernetes**, **SIEM**, and security services - Contribute security feedback to at least one engineering design doc - Ship your first security fix, guardrail, or detection to production - Learn incident response and on-call procedures; join the security rotation - Get up to speed on our **DLP** program and start contributing to its rollout **Outcomes** - Production code shipped in your first month - Joined the security on-call rotation for real team coverage ### By 90 days - Own at least one security domain end to end (e.g., Kubernetes/cloud hardening, application security in CI, or detection engineering) - Write and tune detections as code, add telemetry sources, and reduce alert noise - Ship a reusable Go security library/middleware (e.g., authorization, tenant isolation, request signing, input validation) adopted by at least one service team - Serve as the security reviewer on design docs for new product features and architecture changes - Deliver control automation and evidence for active audit/regulatory workstreams (SOC 1, SOC 2, OCC) - Help launch and triage our bug bounty program; expand DLP coverage and policies **Outcomes** - Measurable risk reduction from controls, fixes, or detections you built - Recognized as the owner of at least one security domain ### By 180 days - Drive multi-quarter initiatives (e.g., default-deny service-to-service networking, security policy evaluation, just-in-time granular access) - Expand Kubernetes and container security (image scanning/signing, admission policies, pod security standards, runtime protection) - Grow shared security middleware/libraries adopted across the codebase - Expand compliance scope with automation instead of spreadsheets - Turn tabletop exercises and resilience testing into concrete fixes - Join cross-functional planning and influence the security roadmap **Outcomes** - Function-wide improvements to how we build and ship secure systems - Clear, measurable business impact from your security work --- ## Challenges you may tackle - Building reusable security building blocks for secure defaults across the platform - Protecting critical s

Listing freshness

CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord