Systems & Security Engineer

Fairly Inc.

Portland (OR)

Hybrid

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Collaborative environment
Impactful role in growth

Job summary

Fairly Inc. is seeking a generalist security and IT operations role to maintain and expand our security, compliance, and IT foundation. You will own SOC 2 and PCI-DSS programs, manage identity and endpoint administration, and partner with the CTO on audits and tooling.

This role emphasizes automation, incident response, and building runbooks and internal tools. You will work across Google Workspace, JumpCloud, Auth0, AWS, and our SIEM, applying a builder mentality to make the company run more

Qualifications

  • Hands-on experience administering a cloud-native IT stack.
  • Familiarity with SOC 2/PCI-DSS and ISO 27001 practices.
  • Experience using AI coding assistants and agents.
  • Proficiency reading/writing code and shipping automation.

Responsibilities

  • Maintain SOC 2 and PCI-DSS compliance programs and audits.
  • Own identity, endpoint management, and SSO integrations.
  • Handle escalations, on-call issues, and break/fix tasks.
  • Develop automations to reduce recurring incidents.
  • Analyze operational problems and build data-driven solutions.

Skills

Cloud IT administration
Compliance frameworks familiarity
AI tooling experience
Coding ability (TypeScript/Python)
AWS & IaC
On-call & break/fix mindset
Curiosity & scope expansion
Written communication
Datadog familiarity

Tools

Drata
Datadog
JumpCloud
Google Workspace
AWS CDK

Job description

At Fairly we're revolutionizing vacation rental care: Making life better for property owners, caretakers, and guests alike.
.

About the role

Fairly runs a lean engineering team, and over the last few years we've built out a security, compliance, and IT foundation that is now mature: SOC 2 and PCI-DSS programs running on Drata, a SIEM on Datadog, unified identity and device management on JumpCloud and Google Workspace, and automated vulnerability management across our AWS/CDK stack. These programs are well built and well run. Your job is to carry these forward and to expand what this role can do for the company. We're looking for someone who will keep those programs strong and who is curious and driven enough to grow the role beyond them, making the company work better: digging into operational problems, building automations for what they find, handling escalations from customer support before they reach engineers, and taking a share of on-call and break/fix work.

This is a role for a generalist with a builder mentality: solid in security and IT fundamentals, and eager to keep expanding in breadth. If you're the person on every team who ends up understanding how everything connects and quietly making it better, this is probably for you.

What you'll own
Security & compliance program
  • Keep SOC 2 and PCI-DSS in continuous good standing on Drata: monitor and remediate flagged controls, keep policies current, collect and organize evidence for auditors.
  • Run the recurring compliance calendar: annual risk assessment, DR/BCP tabletop exercises, quarterly ASV scans, annual penetration test coordination and remediation tracking, PCI SAQ, and banking partner coordination.
  • Provide technical evidence and answers during audit and pentest cycles, working alongside our CTO who is the auditor and vendor point of contact and the named PCI role.
  • Own and improve the security tooling: SIEM detections, custom rule creation when necessary and log volume, dependency and secret scanning, security awareness training assignment, AWS and GitHub org guardrails.
IT, identity, and endpoint administration
  • Own day-to-day identity administration across Google Workspace, JumpCloud, and Auth0: provisioning and deprovisioning, role grants, SaaS access requests, password and MFA resets.
  • Own endpoint management: MDM and EDR configuration and compliance, device enrollment, and the security posture of our laptop fleet.
  • Run the employee hardware lifecycle: procurement, imaging, shipping and receiving for hires and departures, inventory tracking.
  • Field employee questions and either act to resolve issues or know where to redirect requests.
  • Manage our SaaS and vendor footprint: license reviews, renewals, and vendor security reviews.
Escalation, on-call, and break/fix support
  • Be the technical escalation point for customer support: when a case needs someone who can read logs, query data, trace a workflow, or fix a record, it comes to you before it reaches product or engineering.
  • Take a share of on-call coverage and handle break/fix bugs and small production fixes.
  • Turn recurring escalations into runbooks, tooling, or fixes so they stop recurring.
Analysis and building
  • Investigate operational problems as an analyst: pull data, find the pattern, write up what's actually going on and what to do about it.
  • Build automations for the problems you see, whether that's a Claude skill, a GitHub Action, a scheduled job, an internal tool, or a small service.
  • Contribute to internal AI and agentic tooling that helps ops, support, and engineering move faster.
What you'll bring
  • Hands-on experience administering a cloud-native IT stack: Google Workspace, an identity provider (JumpCloud, Okta, or similar), MDM/EDR, and SSO/SAML/OIDC integrations.
  • Working familiarity with a compliance framework in practice (SOC 2, PCI-DSS, ISO 27001, or similar), ideally on a platform like Drata or Vanta, and comfort talking to auditors.
  • Experience using AI coding assistants and agents as a daily part of your work, and interest in pushing how far they can go.
  • Enough engineering to be dangerous: you can read and write code (TypeScript, Python, or similar), work in git, query SQL, read logs and traces, and ship a working automation on your own.
  • Comfort with AWS and infrastructure-as-code at the level of understanding what's deployed and why, and making careful changes.
  • A support instinct: patience with people, urgency with problems, and the judgment to know when something needs an engineer versus when you can handle it.
  • Curiosity that doesn't stop at the edge of your job description, and a track record of expanding your scope wherever you've been.
  • Strong written communication. Much of this job is explaining what happened and what to do next.
  • Familiarity with Datadog, or the drive to get deep in it quickly.
Nice to have
  • Prior exposure to PCI-DSS specifically, or to running a small company's security program end to end.
  • Familiarity with Auth0, Intercom, Linear, or Snowflake.
  • A history of being the "systems person" at a small company: the one who figured out how everything connects and made it better.
How we work
  • Small team, high trust, high ownership. You'll have real authority over your areas and direct access to the CTO.
  • AI-native: we use Claude and agentic tooling heavily across engineering and operations, and we'd expect you to as well.
  • The work has a rhythm: compliance windows are intense, and the stretches between them are where you'll have room to build.
What we offer
  • Collaborative, innovative work environment
  • Opportunity to make significant impact on company growth
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT & Security Operations Manager
IT & Security Operations Manager

Clearstory Technologies, Inc. • Walnut Creek (CA)

On-site
USD 80,000 - 120,000
Competitive salary and equity ownership
Comprehensive health, dental, and vision coverage
401(k) plan
+3
Head of Security (Cloud, Corporate & Physical)
Head of Security (Cloud, Corporate & Physical)

StudyFetch Inc. • Beverly Hills (CA)

On-site
USD 180,000 - 240,000
Employer-paid Medical, Dental, and Vis
401(k) with employer matching
Daily team dinner provided in-office
Cloud Security Engineer
Cloud Security Engineer

YGO GmbH • United States

Remote
USD 140,000 - 190,000
IT & Security Operations Manager
IT & Security Operations Manager

Clearstory • Walnut Creek (CA)

Hybrid
USD 90,000 - 120,000
Competitive salary
Health, dental, and vision coverage
401(k) plan
+2
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
Senior Security Engineer
Senior Security Engineer

Entegrata • Indianapolis (IN)

Hybrid
USD 120,000 - 180,000
Medical insurance
401k plan with match
Unlimited paid time off
+1
Founding IT Engineer
Founding IT Engineer

Cogent-Security • San Francisco (CA)

On-site
USD 140,000 - 190,000
Founding IT Engineer
Founding IT Engineer

Cogent • San Francisco (CA)

On-site
USD 140,000 - 210,000
Staff DevSecOps Engineer
Staff DevSecOps Engineer

Red Ventures • United States

Hybrid
USD 180,000 - 240,000
Hybrid Schedule
Flexible PTO
Mentorship Culture
+2
Senior IT & Corporate Engineering
Senior IT & Corporate Engineering

Flex • San Francisco (CA), Miami (FL), New York (NY)

Hybrid
USD 145,000 - 200,000