Skip to content

Open nowPosted 7 days ago

Senior Security Engineer

Bastion9 open roles

Pay
$180,000 – $250,000 a year
Where
US Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security EngineerBastion · US Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Bastion's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Bastion postings stay open a median of 17 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 7 days ago

Bastion median: 17 days open

The posting

ABOUT BASTION

Bastion provides the regulated infrastructure businesses need to hold, move, and issue stablecoins. Our platform combines custodial wallets, global payment orchestration, and stablecoin issuance. Customers can use each product independently or connect them into a single end-to-end flow.

We operate through our own regulated entities, with compliance and risk controls built directly into the platform. We can also support customers operating under their own licenses with the compliance and financial operations required to run their programs.

OVERVIEW

We're looking for a hands-on Senior Security Engineer to join our security team as its second engineer. You'll work alongside our Staff Security Engineer and report to our CTO/CISO.

The foundation is already in place: a SOC 2 Type II report, conditional approval from the OCC for a national trust charter, a SIEM and detection pipeline, runtime security for Kubernetes, and time-limited, auditable access to production. You'll help scale that program across security engineering, infrastructure, product and application security, detection and response, and the technical side of GRC (SOC 1, SOC 2, OCC, and MiCA/DORA).

As a 40-person company, your work will directly protect our users and partners. You'll build on a strong foundation (we're featured in this AWS case study https://aws.amazon.com/startups/learn/transforming-payments-how-startups-are-pioneering-stablecoin-infrastructure-on-aws?lang=en-US#overview). Our platform is almost entirely Go, running on Kubernetes (EKS) in AWS and managed with Terraform, and our security services are written in Go too. You must be able to write production code. Expect to spend most of your time writing code, reviewing design docs, and building security tooling and middleware that engineers can easily drop into any service.

This role can be remote within the US, though we'd prefer someone in NYC or open to relocating.

WORK TO BE DONE

Instead of a list of requirements, we want to give you a directional look into the first 30, 90, and 180 days on the job.

We are a startup, so the pace is fast and the specific work will change. People who thrive here find ways to contribute in their first week and are fully productive by their third month. You need to be okay with that.

If you think this is something you can handle, we'll be excited to speak with you.

First 30 days: Learn and ship from week one

- Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services

- Contribute security feedback to at least one engineering design doc

- Ship your first security fix, guardrail, or detection to production

- Learn our incident response and on-call procedures, and join our security rotation

- Get up to speed on our DLP program and start contributing to its rollout

  • Outcomes
  • Production code shipped in your first month
  • Join the security on-call rotation, so the team has real coverage

By 90 days: Own initiatives independently

- Own at least one security domain end to end, such as Kubernetes and cloud hardening, application security in CI, or detection engineering

- Write and tune detections as code, add new telemetry sources, and reduce alert noise

- Ship your first reusable security library or middleware in Go (for example authorization, tenant isolation, request signing, or input validation) and get it adopted by at least one service team

- Be the security reviewer on design docs for new product features and architecture changes

- Deliver control automation and evidence for an active audit or regulatory workstream (SOC 1, SOC 2, OCC)

- Help launch and triage our bug bounty program, and grow our DLP coverage and policies

  • Outcomes
  • Measurable risk reduction from controls, fixes, or detections you built
  • Recognized as the owner of at least one security domain

By 180 days: Scale your impact

- Drive multi-quarter initiatives such as default-deny service-to-service networking, security policy evaluation, or just-in-time, granular access across more systems

- Expand our Kubernetes cluster and container security, including image scanning and signing, admission policies, pod security standards, and runtime protection

- Grow a shared set of security middleware and libraries that is adopted across the codebase, so the secure path is the easy path for our Go engineers

- Help expand our compliance scope with automation instead of spreadsheets

- Turn tabletop exercises and resilience testing into concrete fixes

- Join cross-functional planning and influence the security roadmap

  • Outcomes
  • Function-wide improvements to how we build and ship secure systems
  • Clear, measurable business impact from your security work

Some challenges you might tackle

- Building reusable security building blocks that make secure defaults easy across our platform

- Protecting the critical systems at the core of a regulated stablecoin platform

- Turning OCC and MiCA/DORA requirements into controls that are engineered, tested, and continuously evidenced

- Building high-signal detections across cloud, Kubernetes, identity, endpoint, and SaaS telemetry

- Hardening our Kubernetes clusters and container supply chain, from build to admission to runtime, without slowing deploys

If you think this is something you can handle, we will be excited to speak with you.

Bastion provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, and placement. Bastion participates in E-Verify to authorize eligibility of employment in the United States.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Bastion's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Bastion's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Bastion's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.