About BastionBastion builds regulated financial infrastructure for modern businesses. Bastion's full stack product suite covers stablecoin issuance, custodial wallet infrastructure, and global asset conversion rails, with the flexibility to deploy individual capabilities or combine them end-to-end.Bastion's regulated foundation underpins a compliance-first approach to risk management, ensuring the integrity and security of all financial activity within its systems. Bastion holds the appropriate licenses for its own operations, but can also act as a service provider, offering compliance and financial operations support under our customers’ licenses.Work to Be DoneInstead of a list of requirements, we want to give you a directional look into the first 30, 90, and 180 days on the job.We are a startup, so the pace is fast and the specific work will change. You need to be okay with that.If you think this is something you can handle, we will be excited to speak with you.We are open to US remote and have an office in New York City.First 30 days: Learn the infrastructure, ship confidentlyRamp on AWS architecture, Terraform patterns, Kubernetes setup, CI/CD pipelines, and observability stackShip a small infrastructure improvement: Terraform module refactor, monitoring enhancement, or CI/CD optimizationAdd runbooks, alerts, or documentation for the infrastructure areas you touchOutcomesMultiple safe infrastructure changes deployed with verificationYou understand our core infrastructure patterns and can navigate Terraform, K8s, and AWS resourcesUpdated documentation and/or infrastructure-as-code improvements that help the teamBy 90 days: Own an infrastructure domain and raise the barTake ownership of an infrastructure area: CI/CD pipelines, observability stack, Kubernetes platform, or AWS security/networkingLead a medium-scope project: implementing a reusable Terraform module, right-sizing service resources, or improving deployment reliabilityStrengthen system reliability with better metrics, alerts, autoscaling policies, and failure recovery mechanismsOutcomesA delivered infrastructure improvement that enhances reliability, reduces cost, or improves developer velocityYou're a go-to person for your infrastructure domainBy 180 days: Drive platform-wide impactLead a platform-wide initiative: single immutable image pipeline, infrastructure standardization, database performance optimization, or security hardeningShape infrastructure direction with design docs, RFC proposals, and mentoring engineering teamsPartner with engineering, security, and compliance teams to make pragmatic tradeoffs on reliability, cost, and regulatory requirementsOutcomesA multi-sprint infrastructure delivery that improves system-wide reliability, security, or developer experienceClear before/after improvements in deployment speed, cost efficiency, or operational stabilityPatterns and tooling that enable engineers to ship faster and saferSome problems you might work onBuilding reusable Terraform modules that standardize service deployment patterns across dev, sandbox, and prodImplementing single immutable image pipelines with built-in security scanning and promotion workflowsRight-sizing Kubernetes workloads and autoscaling policies to reduce cost while maintaining reliabilityDesigning and implementing database monitoring and performance optimization strategiesHardening AWS infrastructure with security best practices: IAM policies, network segmentation, secrets management, and audit loggingBuilding observability infrastructure that gives engineers fast feedback on system health and performanceImproving CI/CD reliability and speed through better caching, parallelization, and failure handlingOur typical stackLanguages: Go and TypeScript/Node.js; some services in Rust as neededInfrastructure-as-Code: TerraformCloud & Compute: AWS (ECS, EKS, Lambda, EC2), Kubernetes, DockerCI/CD: GitHub Actions, container registries, automated testing and deployment pipelinesData: Postgres (RDS), Redis, Kafka, SnowflakeWorkflow Management: TemporalSecurity: AWS Nitro Enclaves for hardware-backed key isolation, IAM policies, secrets managementObservability: Datadog, Grafana, Sentry, CloudWatchIncident Management: Incident.ioActual compensation is unique to each candidate and based on a variety of factors such as skill set, experience, and specific work location. Salary is one part of Bastion’s total compensation and benefits package.We are proud to present to all employees a generous equity offering and additional benefits including:Flexible work schedulesUnlimited paid vacation & holidaysSeveral holistic and balanced life benefits such as: comprehensive health coverage, life insurance, retirement benefits, paid parental leave, tax-advantaged accounts, One Medical, Spring health, and more.