Security Engineer

Bastion

• $110K — $130K *
US-AnywhereRemote in New York City, NY
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in security engineering or a related field
  • Proficient in Go, with the ability to write production code
  • Familiarity with AWS, Kubernetes, and Terraform
  • Experience in security incident response and on-call procedures
  • Knowledge of security compliance frameworks, especially SOC 1, SOC 2, OCC, and MiCA/DORA
  • Understanding of application security practices and principles

Responsibilities

  • Learn and engage with the existing Go codebase and security services
  • Develop and ship security fixes and enhancements to production
  • Own security domains such as Kubernetes hardening or application security
  • Write and tune security detection codes, minimizing alert noise
  • Create reusable security libraries and promote their use across teams
  • Support compliance efforts through automation and security controls
  • Contribute to and help launch a bug bounty program

Benefits

  • Flexible remote work options within the US
  • Collaboration with a skilled security team
  • Opportunity to influence security practices in a growing startup
  • Direct impact on user and partner security
  • Involvement in a fast-paced startup environment with significant learning opportunities
Full Job Description
Overview

We're looking for a hands-on Security Engineer to join our security team as its second engineer. You'll work alongside our Staff Security Engineer and report to our CTO/CISO.

The foundation is already in place: a SOC 2 Type II report, conditional approval from the OCC for a national trust charter, a SIEM and detection pipeline, runtime security for Kubernetes, and time-limited, auditable access to production. You'll help scale that program across security engineering, infrastructure, product and application security, detection and response, and the technical side of GRC (SOC 1, SOC 2, OCC, and MiCA/DORA).

As a 40-person company, your work will directly protect our users and partners. You'll build on a strong foundation (we're featured in this AWS case study). Our platform is almost entirely Go, running on Kubernetes (EKS) in AWS and managed with Terraform, and our security services are written in Go too. You must be able to write production code. Expect to spend most of your time writing code, reviewing design docs, and building security tooling and middleware that engineers can easily drop into any service.

This role can be remote within the US, though we'd prefer someone in NYC or open to relocating.
Work to Be Done

Instead of a list of requirements, we want to give you a directional look into the first 30, 90, and 180 days on the job.

We are a startup, so the pace is fast and the specific work will change. People who thrive here find ways to contribute in their first week and are fully productive by their third month. You need to be okay with that.

If you think this is something you can handle, we'll be excited to speak with you.

First 30 days: Learn and ship from week one
  • Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services
  • Contribute security feedback to at least one engineering design doc
  • Ship your first security fix, guardrail, or detection to production
  • Learn our incident response and on-call procedures, and join our security rotation
  • Get up to speed on our DLP program and start contributing to its rollout
  • Outcomes
    • Production code shipped in your first month
    • Join the security on-call rotation, so the team has real coverage

By 90 days: Own initiatives independently
  • Own at least one security domain end to end, such as Kubernetes and cloud hardening, application security in CI, or detection engineering
  • Write and tune detections as code, add new telemetry sources, and reduce alert noise
  • Ship your first reusable security library or middleware in Go (for example authorization, tenant isolation, request signing, or input validation) and get it adopted by at least one service team
  • Be the security reviewer on design docs for new product features and architecture changes
  • Deliver control automation and evidence for an active audit or regulatory workstream (SOC 1, SOC 2, OCC)
  • Help launch and triage our bug bounty program, and grow our DLP coverage and policies
  • Outcomes
    • Measurable risk reduction from controls, fixes, or detections you built
    • Recognized as the owner of at least one security domain

By 180 days: Scale your impact
  • Drive multi-quarter initiatives such as default-deny service-to-service networking, security policy evaluation, or just-in-time, granular access across more systems
  • Expand our Kubernetes cluster and container security, including image scanning and signing, admission policies, pod security standards, and runtime protection
  • Grow a shared set of security middleware and libraries that is adopted across the codebase, so the secure path is the easy path for our Go engineers
  • Help expand our compliance scope with automation instead of spreadsheets
  • Turn tabletop exercises and resilience testing into concrete fixes
  • Join cross-functional planning and influence the security roadmap
  • Outcomes
    • Function-wide improvements to how we build and ship secure systems
    • Clear, measurable business impact from your security work

Some challenges you might tackle
  • Building reusable security building blocks that make secure defaults easy across our platform
  • Protecting the critical systems at the core of a regulated stablecoin platform
  • Turning OCC and MiCA/DORA requirements into controls that are engineered, tested, and continuously evidenced
  • Building high-signal detections across cloud, Kubernetes, identity, endpoint, and SaaS telemetry
  • Hardening our Kubernetes clusters and container supply chain, from build to admission to runtime, without slowing deploys

If you think this is something you can handle, we will be excited to speak with you.

Similar Jobs

More Jobs at Bastion

  • Security Engineer
    $110K — $130K *
    Remote
    Information Technology
    Remote in New York City, NY
  • Security Engineer
    $120K — $145K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Founding Account Executive
    $110K — $130K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person
  • Product Manager
    $120K — $140K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    Hybrid
  • Product Manager
    $110K — $130K *
    Remote
    Finance & Insurance
    Remote in New York, NY

More Information Technology Jobs

Find similar Security Engineer jobs: