Responsibilities
Support and lead our security programs, both internal and with 3rd party vendors.
Lead incident response simulations and continuous vulnerability remediation efforts, optimizing our observability and alerting frameworks.
Support the design and maintenance of resilient, scalable cloud infrastructure, ensuring security is baked into the foundation.
Work closely with company leadership to ensure adoption of security best practices.
Work closely with R&D teams to help them shift security testing left into the early phases of development.
Monitor, detect, and respond to security alerts and infrastructure anomalies, optimizing our logging, tracing, and alerting frameworks.
Conduct regular reviews of security tools and infrastructure such as endpoint security, malware detection, firewall logs, and the like.
Collaborate with our CISO to implement and automate controls supporting fintech/insurtech compliance and data privacy standards (PII protection, SOC2).
Requirements
4+ years experience working in an Incident Response/Cyber Security Operations Center (in-house or outsourced) creating, escalating, and managing security incidents and creating incident reports or 4+ years in either a SecOps or DevSecOps role.
Proficient in at least one scripting language (Python, Bash, or Node.js) to build security guardrails and automate manual processes.
3+ years working with security tools including SIEM, Analytics & Intelligence, Intrusion Detection, Malware Detection, Data Loss Protection, and Identity & Access Management.
Experience managing low to high-risk cybersecurity events, alerts, and incidents with event monitoring, analysis, and escalation.
A builder’s mindset: You aren't just identifying vulnerabilities; you are designing the automated fixes, guardrails, and processes that prevent them from recurring.
We're looking for a Security Operations (SecOps) specialist to take ownership of our security infrastructure and operations as we scale. In this hands-on, high-impact role, you’ll play a crucial role in managing the infrastructure, services and service providers that help keep Faye secure from outside attacks and insider threats, along with managing our information compliance programs.