
Senior Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in New York.
• Become the second engineer on Bastion's security team.
• Report directly to the CTO/CISO and collaborate with the Staff Security Engineer.
• Enhance security engineering, infrastructure and application security, detection and response, and technical GRC programs.
• Develop production Go code, assess design documents, and create reusable security tools and middleware.
• Engage with Bastion's Go platform hosted on Kubernetes (EKS) within AWS and managed via Terraform.
• Acquire knowledge and contribute to the SIEM, security services, DLP program, incident response, and on-call processes.
• Deploy security fixes, guardrails, or detections into production environments.
• Take ownership of security domains such as Kubernetes and cloud hardening, application security in CI, or detection engineering.
• Write and refine detections as code, integrate telemetry sources, and minimize alert noise.
• Develop reusable Go security libraries or middleware and promote their adoption among service teams.
• Evaluate design documents for new product features and architectural modifications.
• Provide control automation and evidence for audits and regulatory initiatives.
• Assist in launching and managing the bug bounty program.
• Lead multi-quarter projects encompassing service-to-service networking, security policy assessments, and granular access.
• Enhance Kubernetes cluster and container security from the build phase through runtime.
• Expand shared security middleware and libraries throughout the codebase.
• Broaden compliance scope through automation efforts.
• Transform tabletop exercises and resilience testing into actionable solutions.
• Shape the security roadmap through cross-functional collaboration.
• Hands-on Senior Security Engineer with the capability to write production code.
• Proficient in working with Go codebases and developing security services in Go.
• Experience with AWS, Kubernetes, EKS, Terraform, SIEM, and security services.
• Ability to provide security insights for engineering design documents.
• Capable of deploying security fixes, guardrails, or detections into production.
• Participation in incident response and security on-call rotations is expected.
• Familiarity with DLP programs and their implementation.
• Capacity to manage a security domain from start to finish.
• Experience with writing and tuning detections as code and integrating telemetry sources.
• Ability to develop reusable security libraries or middleware in Go.
• Competence in reviewing product feature and architecture design documents.
• Deliver control automation and audit evidence for SOC 1, SOC 2, or OCC workstreams.
• Contribute to bug bounty programs and DLP coverage.
• Background in Kubernetes and container security, including image scanning and signing, admission policies, pod security standards, and runtime protection.
• Adaptable to a fast-paced startup environment, making contributions from the first week.
• Legally authorized to work in the United States.
• Willing to undergo a criminal background check.
• Must be at least 18 years old at the time of application.
• A Bachelor's degree or equivalent educational credential is not explicitly required.
• Equity offering.
• Flexible work schedules.
• Unlimited paid vacation & holidays.
• Comprehensive health coverage.
• Life insurance.
• Retirement benefits.
• Paid parental leave.
• Tax-advantaged accounts.
• One Medical.
• Spring Health.
• Exposure to global payment orchestration and stablecoin issuance platform.
EXL
Reli Group
Second Nature
ASRC Federal
Get handpicked remote jobs straight to your inbox weekly.