SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Bastion provides regulated infrastructure for stablecoins, combining custodial wallets, global payment orchestration, and stablecoin issuance. We're seeking a hands-on Security Engineer to join our security team as the second engineer, reporting to our CTO/CISO.
You'll work alongside our Staff Security Engineer to scale our security program across security engineering, infrastructure, product and application security, detection and response, and the technical side of GRC (SOC 1, SOC 2, OCC, and MiCA/DORA compliance). The foundation is already in place: SOC 2 Type II report, conditional OCC approval for national trust charter, SIEM and detection pipeline, Kubernetes runtime security, and auditable production access.
As a 40-person company, your work will directly protect users and partners. Our platform is primarily Go-based, running on Kubernetes (EKS) in AWS and managed with Terraform. Security services are also written in Go. You must be able to write production code and will spend most of your time writing code, reviewing design docs, and building security tooling and middleware for engineers to integrate into services.
First 30 days: Get hands-on with our Go codebase, AWS, Kubernetes, SIEM, and security services. Contribute security feedback to engineering design docs, ship your first security fix or detection to production, learn incident response and on-call procedures, and contribute to DLP program rollout. You'll ship production code in your first month and join the security on-call rotation.
By 90 days: Own at least one security domain end-to-end (e.g., Kubernetes hardening, application security in CI, detection engineering). Write and tune detections as code, ship a reusable Go security library adopted by service teams, review design docs for new features, deliver control automation for active audits, and help launch our bug bounty program. Achieve measurable risk reduction and become recognized as a domain owner.
By 180 days: Drive multi-quarter initiatives like default-deny service-to-service networking and just-in-time access. Expand Kubernetes and container security (image scanning, signing, admission policies, runtime protection). Grow shared security middleware adopted across the codebase. Expand compliance scope with automation. Turn resilience testing into concrete fixes and influence the security roadmap. Deliver function-wide improvements and measurable business impact.
Challenges include building reusable security building blocks for secure defaults, protecting critical regulated stablecoin systems, turning OCC and MiCA/DORA requirements into engineered controls, building high-signal detections across cloud/Kubernetes/identity/endpoint/SaaS telemetry, and hardening Kubernetes clusters and container supply chain without slowing deploys.
REQUIREMENTS:
The posting does not explicitly state years of experience or formal certifications required. However, the role requires: production-level Go programming ability; hands-on experience with Kubernetes, AWS, and Terraform; familiarity with SIEM, detection engineering, and security operations; understanding of compliance frameworks (SOC 1/2, OCC, MiCA/DORA); and ability to work at startup pace with ambiguity. You should be comfortable shipping code in week one and becoming fully productive by month three.