About Bastion Bastion enables financial institutions and enterprises to issue regulated stablecoins, generate revenue on reserves, and expand their ecosystems. Bastion's platform combines stablecoin issuance, secure custody, and seamless orchestration for cross-border transfers, on/off-ramps, and stablecoin conversions. With Bastion's platform and APIs, businesses can create and scale their stablecoin network, while optimizing revenue, compliance, and control.We are a startup, so the pace is fast and the specific work will change. We are open to US remote and have an office in New York City.Learn the infrastructure, ship confidentlyRamp on AWS architecture, Terraform patterns, Kubernetes setup, CI/CD pipelines, and observability stackShip a small infrastructure improvement: You understand our core infrastructure patterns and can navigate Terraform, K8s, and AWS resourcesUpdated documentation and/or infrastructure-as-code improvements that help the teamOwn an infrastructure domain and raise the barCI/CD pipelines, observability stack, Kubernetes platform, or AWS security/networkingLead a medium-scope project: implementing a reusable Terraform module, right-sizing service resources, or improving deployment reliabilityStrengthen system reliability with better metrics, alerts, autoscaling policies, and failure recovery mechanismsDrive platform-wide impactLead a platform-wide initiative: single immutable image pipeline, infrastructure standardization, database performance optimization, or security hardeningShape infrastructure direction with design docs, RFC proposals, and mentoring engineering teamsPartner with engineering, security, and compliance teams to make pragmatic tradeoffs on reliability, cost, and regulatory requirementsClear before/after improvements in deployment speed, cost efficiency, or operational stabilityPatterns and tooling that enable engineers to ship faster and saferBuilding reusable Terraform modules that standardize service deployment patterns across dev, sandbox, and prodImplementing single immutable image pipelines with built-in security scanning and promotion workflowsRight-sizing Kubernetes workloads and autoscaling policies to reduce cost while maintaining reliabilityDesigning and implementing database monitoring and performance optimization strategiesHardening AWS infrastructure with security best practices: IAM policies, network segmentation, secrets management, and audit loggingBuilding observability infrastructure that gives engineers fast feedback on system health and performanceLanguages: Go and TypeScript/Node.js; Cloud & Compute: AWS (ECS, EKS, Lambda, EC2), Kubernetes, DockerCI/CD: GitHub Actions, container registries, automated testing and deployment pipelinesData: Postgres (RDS), Redis, Kafka, SnowflakeSecurity: AWS Nitro Enclaves for hardware-backed key isolation, IAM policies, secrets managementBastion provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, and placement.