Description
Who we are
Faye is the fastest-growing travel protection company in the U.S., and the highest-rated by travelers who use it trip after trip.
We’ve raised $100M to build the autonomous platform for traveler care: insurance, travel care, real-time information, and finance in one place, powered by AI and a team that moves fast.
We’re there for travelers throughout their entire journey, from the moment they book to the moment they’re back home.
The bar is a 6-star experience, 24/7: near-instant payouts, an award-winning app and real support when travel goes sideways. It’s hard to pull off. That’s the point.
Come build what’s next with us.
What we're looking for
We're looking for a Security Operations (SecOps) specialist to take ownership of our security infrastructure and operations as we scale. In this hands-on, high-impact role, you’ll play a crucial role in managing the infrastructure, services and service providers that help keep Faye secure from outside attacks and insider threats, along with managing our information compliance programs.
Responsibilities
- Support and lead our security programs, both internal and with 3rd party vendors.
- Lead incident response simulations and continuous vulnerability remediation efforts, optimizing our observability and alerting frameworks.
- Support the design and maintenance of resilient, scalable cloud infrastructure, ensuring security is baked into the foundation.
- Work closely with company leadership to ensure adoption of security best practices.
- Work closely with R&D teams to help them shift security testing left into the early phases of development.
- Monitor, detect, and respond to security alerts and infrastructure anomalies, optimizing our logging, tracing, and alerting frameworks.
- Conduct regular reviews of security tools and infrastructure such as endpoint security, malware detection, firewall logs, and the like.
- Collaborate with our CISO to implement and automate controls supporting fintech/insurtech compliance and data privacy standards (PII protection, SOC2).
Requirements
- 4+ years experience working in an Incident Response/Cyber Security Operations Center (in-house or outsourced) creating, escalating, and managing security incidents and creating incident reports or 4+ years in either a SecOps or DevSecOps role.
- Proficient in at least one scripting language (Python, Bash, or Node.js) to build security guardrails and automate manual processes.
- 3+ years working with security tools including SIEM, Analytics & Intelligence, Intrusion Detection, Malware Detection, Data Loss Protection, and Identity & Access Management.
- Experience managing low to high-risk cybersecurity events, alerts, and incidents with event monitoring, analysis, and escalation.
- A builder’s mindset: You aren't just identifying vulnerabilities; you are designing the automated fixes, guardrails, and processes that prevent them from recurring.