We're looking for a hands-on Security Engineer to join our security team as its second engineer. You'll work alongside our Staff Security Engineer and report to our CTO/CISO. The foundation is already in place: a SOC 2 Type II report, conditional approval from the OCC for a national trust charter, a SIEM and detection pipeline, runtime security for Kubernetes, and time-limited, auditable access to production. You'll help scale that program across security engineering, infrastructure, product and application security, detection and response, and the technical side of GRC (SOC 1, SOC 2, OCC, and MiCA/DORA).
🏢 About Bastion
Bastion provides the regulated infrastructure businesses need to hold, move, and issue stablecoins. Our platform combines custodial wallets, global payment orchestration, and stablecoin issuance. Customers can use each product independently or connect them into a single end-to-end flow.
We operate through our own regulated entities, with compliance and risk controls built directly into the platform. We can also support customers operating under their own licenses with the compliance and financial operations required to run their programs.
🎯 The Role
As a 40-person company, your work will directly protect our users and partners. You'll build on a strong foundation (we're featured in this AWS case study). Our platform is almost entirely Go, running on Kubernetes (EKS) in AWS and managed with Terraform, and our security services are written in Go too. You must be able to write production code. Expect to spend most of your time writing code, reviewing design docs, and building security tooling and middleware that engineers can easily drop into any service.
✅ Key Responsibilities
Learn and ship from week one: Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services
Contribute security feedback to at least one engineering design doc
Ship your first security fix, guardrail, or detection to production
Learn our incident response and on-call procedures, and join our security rotation
Get up to speed on our DLP program and start contributing to its rollout
Own initiatives independently: Own at least one security domain end to end, such as Kubernetes and cloud hardening, application security in CI, or detection engineering
Write and tune detections as code, add new telemetry sources, and reduce alert noise
Ship your first reusable security library or middleware in Go (for example authorization, tenant isolation, request signing, or input validation) and get it adopted by at least one service team
Be the security reviewer on design docs for new product features and architecture changes
Deliver control automation and evidence for an active audit or regulatory workstream (SOC 1, SOC 2, OCC)
Help launch and triage our bug bounty program, and grow our DLP coverage and policies
Scale your impact: Drive multi-quarter initiatives such as default-deny service-to-service networking, security policy evaluation, or just-in-time, granular access across more systems
Expand our Kubernetes cluster and container security, including image scanning and signing, admission policies, pod security standards, and runtime protection
Grow a shared set of security middleware and libraries that is adopted across the codebase, so the secure path is the easy path for our Go engineers
Help expand our compliance scope with automation instead of spreadsheets
Turn tabletop exercises and resilience testing into concrete fixes
Join cross-functional planning and influence the security roadmap
🎁 Benefits
We are proud to present to all employees a generous equity offering and additional benefits including:
Flexible work schedules
Unlimited paid vacation & holidays
Several holistic and balanced life benefits such as: comprehensive health coverage, life insurance, retirement benefits, paid parental leave, tax-advantaged accounts, One Medical, Spring health, and more.
Please let Bastion know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.