SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Bastion provides regulated infrastructure for stablecoins, combining custodial wallets, global payment orchestration, and stablecoin issuance. We're seeking a hands-on Senior Security Engineer to join our security team as the second engineer, reporting to our CTO/CISO.
You'll work alongside our Staff Security Engineer to scale our security program across engineering, infrastructure, product and application security, detection and response, and the technical side of GRC (SOC 1, SOC 2, OCC, and MiCA/DORA compliance). The foundation is already in place: SOC 2 Type II report, conditional OCC approval for a national trust charter, a SIEM and detection pipeline, Kubernetes runtime security, and auditable production access.
As a 40-person company, your work will directly protect users and partners. Our platform is almost entirely Go, running on Kubernetes (EKS) in AWS and managed with Terraform. Security services are also written in Go. You must be able to write production code and will spend most of your time writing code, reviewing design docs, and building security tooling and middleware.
First 30 days: Get hands-on with our Go codebase, AWS, Kubernetes, SIEM, and security services. Contribute security feedback to engineering design docs, ship your first security fix or detection to production, learn incident response and on-call procedures, and contribute to our DLP program rollout. You'll ship production code in your first month and join the security on-call rotation.
By 90 days: Own at least one security domain end-to-end (e.g., Kubernetes hardening, application security in CI, or detection engineering). Write and tune detections as code, ship a reusable security library or middleware in Go, be the security reviewer on design docs, deliver control automation for active audits, and help launch our bug bounty program. You'll achieve measurable risk reduction and be recognized as the owner of at least one security domain.
By 180 days: Drive multi-quarter initiatives such as default-deny service-to-service networking or just-in-time access. Expand Kubernetes and container security (image scanning, signing, admission policies, pod security standards, runtime protection). Grow a shared set of security middleware adopted across the codebase. Help expand compliance scope with automation. Turn tabletop exercises into concrete fixes and influence the security roadmap. You'll deliver function-wide improvements and clear business impact.
Challenges include building reusable security building blocks for secure defaults, protecting critical systems in a regulated stablecoin platform, turning OCC and MiCA/DORA requirements into engineered controls, building high-signal detections across cloud/Kubernetes/identity/endpoint/SaaS telemetry, and hardening Kubernetes clusters and container supply chains without slowing deploys.
This role is remote within the US, though the company prefers candidates in NYC or open to relocating. The pace is fast and specific work will change; people who thrive here contribute in their first week and are fully productive by month three.
REQUIREMENTS:
The posting does not explicitly state years of experience or formal education requirements. However, the role requires: production-level Go programming ability; hands-on experience with Kubernetes, AWS, and cloud infrastructure; familiarity with SIEM, detection engineering, and incident response; understanding of security compliance frameworks (SOC 1/2, OCC, MiCA/DORA); and ability to work independently on security domains while contributing to a fast-paced startup environment.