Description
Who We Are
Faye is the first-ever digital, consumer-centric travel insurance for Americans with a product redefining travel coverage and care, taking it from a forgettable add-on to a must-have advantage that enhances the entire trip experience. Faye's whole-trip protection, coupled with its proprietary technology, enables 24/7 immediate assistance, claims processing and reimbursements anywhere in the world, setting a new standard and over-delivering in an industry synonymous with doing the opposite.
Life at Faye
At Faye, every day is a journey. Whether you're building the next generation of travel products, coding new solutions, or helping travelers navigate the unexpected, your work here has a real impact on real people. Our team is as diverse as the destinations our travelers explore — made up of 62% women, 50% parents, and a few office pets. Since launching in 2022, we've accomplished what others in the travel insurance industry only dream of — and we're just getting started. At Faye, we believe in growing together, having fun along the way, and making every day count.
What we're looking for
We're looking for a Security Operations (SecOps) specialist to take ownership of our security infrastructure and operations as we scale. In this hands-on, high-impact role, you’ll play a crucial role in managing the infrastructure, services and service providers that help keep Faye secure from outside attacks and insider threats, along with managing our information compliance programs.
Responsibilities
- Support and lead our security programs, both internal and with 3rd party vendors.
- Lead incident response simulations and continuous vulnerability remediation efforts, optimizing our observability and alerting frameworks.
- Support the design and maintenance of resilient, scalable cloud infrastructure, ensuring security is baked into the foundation.
- Work closely with company leadership to ensure adoption of security best practices.
- Work closely with R&D teams to help them shift security testing left into the early phases of development.
- Monitor, detect, and respond to security alerts and infrastructure anomalies, optimizing our logging, tracing, and alerting frameworks.
- Conduct regular reviews of security tools and infrastructure such as endpoint security, malware detection, firewall logs, and the like.
- Collaborate with our CISO to implement and automate controls supporting fintech/insurtech compliance and data privacy standards (PII protection, SOC2).
Requirements
- 4+ years experience working in an Incident Response/Cyber Security Operations Center (in-house or outsourced) creating, escalating, and managing security incidents and creating incident reports or 4+ years in either a SecOps or DevSecOps role.
- Proficient in at least one scripting language (Python, Bash, or Node.js) to build security guardrails and automate manual processes.
- 3+ years working with security tools including SIEM, Analytics & Intelligence, Intrusion Detection, Malware Detection, Data Loss Protection, and Identity & Access Management.
- Experience managing low to high-risk cybersecurity events, alerts, and incidents with event monitoring, analysis, and escalation.
- A builder’s mindset: You aren't just identifying vulnerabilities; you are designing the automated fixes, guardrails, and processes that prevent them from recurring.