Faire

Staff Security Engineer - Bot & Traffic Defence

Faire
Apply
4 hours ago
Toronto, CanadaStaff+

Responsibilities

  • Own the technical strategy and roadmap for bot, scraping, and application-layer DDoS defense from edge controls through detection and scoring.
  • Author and tune WAF rules, rate-limiting policies, and challenge mechanisms as code against evolving adversaries.
  • Build bot and trust signals that enable stronger enforcement while minimizing impact on legitimate buyers.
  • Design and operate distributed Layer 7 rate limiting, including keying, counter state, and enforcement placement.
  • Establish incident-response procedures, paging paths, runbooks, and observability for bot and DDoS events.
  • Lead post-incident reviews and identify systemic causes of recurring bot incidents.
  • Build tooling, secure defaults, and playbooks that enable service teams to protect their endpoints.
  • Establish cross-team ownership for attack vectors across Security, Platform, service teams, and Anti-Abuse.
  • Communicate residual risk and traffic-abuse exposure to leadership and drive outstanding business decisions.

Requirements

  • Hands-on production ownership of a CDN or edge security platform such as Cloudflare, Akamai, Fastly, or AWS CloudFront/WAF/Shield, managed as code.
  • Experience defending high-traffic consumer sites against scraping and application-layer DDoS attacks.
  • Practical knowledge of bot detection signals including TLS and HTTP fingerprinting, JA3/JA4, behavioral signals, mobile device attestation, and challenges.
  • Experience designing distributed Layer 7 rate limiting using per-IP, per-ASN, per-session, and per-fingerprint keying.
  • Ability to measure detection precision and recall, establish false-positive tolerances, and justify threshold changes with data.
  • Experience building and maintaining internal tooling for incident response and on-call engineering.
  • Ability to read and review code in an object-oriented language such as Kotlin, Java, Python, or TypeScript.
  • Working fluency with infrastructure as code and cloud environments including Terraform, AWS or GCP, and Kubernetes.
  • Experience owning incident response for live traffic attacks, including making time-sensitive traffic-blocking decisions.
  • Track record of setting technical direction in ambiguous domains and sequencing competing priorities.
  • Experience establishing cross-team ownership models without direct authority.
  • Ability to deliver through other teams and communicate security risks, attack trade-offs, revenue impact, cost, and reputational exposure to technical and executive audiences.

Benefits

  • Base salary range of $190,500 to $262,000 per year in Canada, plus equity and comprehensive benefits.
  • Hybrid work requires three office days per week on Tuesdays, Thursdays, and one flex day on Monday, Wednesday, or Friday.
  • Hybrid employees may work remotely for up to four weeks per year.
  • Employees receive access to enterprise AI tools and opportunities for growth in an inclusive workplace.
Faire

About Faire

10,000+ employees

Faire builds a B2B wholesale marketplace that connects independent retailers with consumer brands for product discovery, ordering, and net terms. It monetizes through marketplace commissions and financial services, and provides tools for payments, returns, and analytics to help shops source inventory. Founded in 2017 and headquartered in San Francisco, it operates across North America and Europe and is privately held.

Contact me