CronJobs

security jobs

Staff Security Engineer - Bot & Traffic Defence

Faire · San Francisco, CA

hybridstaff$231,000–$318,000Posted Oct 5, 2026KotlinTypeScriptPythonJavaAWSGCPTerraformKubernetes

Apply on the employer site

About this role

**Staff Security Engineer - Bot & Traffic Defence** **About Faire** Faire is a technology wholesale platform built on the belief that the future is local. Independent retailers around the globe collectively represent a multi-hundred-billion-dollar wholesale market that has historically been fragmented and offline. At Faire, we use tech, data, and machine learning to connect entrepreneurs worldwide—helping local businesses discover and sell products from around the world. **About this role** Faire’s Engineering organization owns the software that makes the marketplace work. The **Bot & Traffic Defence** function owns how Faire holds up against automated traffic—scraping, credential abuse, and application-layer DDoS—from the edge through detection and scoring. As a **Staff Security Engineer, Bot & Traffic Defence**, you’ll be the first dedicated owner of this domain. You’ll set the technical direction, build the controls and signals that support it, and establish an ownership model across Security, Platform, service teams, and Anti-Abuse. **You’ll collaborate with us to:** - Own the technical strategy and roadmap for bot, scraping, and application-layer DDoS defense end to end (edge controls → detection and scoring), revising the strategy when evidence contradicts it. - Author and tune edge security controls as code (WAF rules, rate limiting policies, challenge mechanisms) against real adversaries. - Build higher-confidence bot and trust signals so Faire can enforce more aggressively without turning legitimate logged-out buyers away. - Design and operate distributed layer 7 rate limiting, deciding on keying, counter state, and enforcement location in the stack. - Make incident response for bot and DDoS events a solved problem: clear paging paths, runbooks a non-specialist can execute at 3am, and observability that answers whether humans are actually being affected. - Lead post-incident reviews on recurring classes of bot incidents to surface systemic causes. - Build tooling, secure defaults, and playbooks so service-owning teams can protect their endpoints correctly without you being in every decision. - Land a durable ownership model across Security, Platform, service teams, and Anti-Abuse, with named owners for every attack vector. - Make Faire’s bot posture legible to leadership, including a defensible view of residual risk. **We’re excited about you because you have:** - Hands-on operational ownership of a CDN/edge security platform (Cloudflare, Akamai, Fastly, or AWS CloudFront/WAF/Shield) in production against real adversaries, managed as code. - Experience defending high-traffic consumer sites against scraping and application-layer DDoS, including adapting when attackers shift vectors. - Practical understanding of bot detection signals and failure modes (TLS/HTTP fingerprinting like JA3/JA4, behavioral signals, mobile attestation such as App Attest/Play Integrity, and challenges), including precision/recall trade-offs. - Experience designing distributed layer 7 rate limiting (per-IP, per-ASN, per-session, per-fingerprint), including evasion patterns and holding counter state across a fleet. - Quantitative rigor in detection work (precision/recall measurement, false-positive tolerance with the business, data-driven threshold changes). - Preference for solving traffic and abuse problems with code and building internal tooling that on-call engineers rely on mid-incident. - Comfort writing/reviewing code in an OOP language (Kotlin

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord