Skip to content

Open nowPosted 3 days ago

Staff Security Engineer - Bot & Traffic Defence

Faire80 open roles

Pay
$190,500 – $262,000 a year
Where
Kitchener-Waterloo, ON; Toronto, ON
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Security Engineer - Bot & Traffic DefenceFaire · Kitchener-Waterloo, ON; Toronto, ON
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Faire's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Faire postings stay open a median of 38 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 3 days ago

Faire median: 38 days open

The posting

About Faire

Faire is a technology wholesale platform built on the belief that the future is local. Independent retailers around the globe collectively represent a multi-hundred-billion-dollar wholesale market that has historically been fragmented and offline. At Faire, we're using the power of tech, data, and machine learning to connect this thriving community of entrepreneurs across the globe. Picture your favorite boutique in town — we help them discover the best products from around the world to sell in their stores. With the right tools and insights, we believe that we can level the playing field so businesses can grow and local communities can thrive.

We’re looking for smart, resourceful and passionate people to join us as we power the shop local movement. If you believe in community, come join ours.

About this role:

Our Engineering organization owns the software that makes our marketplace work. Our Bot & Traffic Defence function owns how Faire holds up against automated traffic: scraping, credential abuse, and application-layer DDoS, from the edge through to detection and scoring. We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate.

As a Staff Security Engineer, Bot & Traffic Defence, you will be the first dedicated owner of this domain. You will set the technical direction, build the controls and signals that back it, and establish an ownership model that holds across Security, Platform, service teams, and Anti-Abuse.

As a Staff Security Engineer, Bot & Traffic Defence, you’ll collaborate with us to:

  • Own the technical strategy and roadmap for bot, scraping, and application-layer DDoS defence end to end, from edge controls through detection and scoring, including revising the strategy where the evidence contradicts it.
  • Author and tune edge security controls as code: WAF rules, rate limiting policies, and challenge mechanisms, against real adversaries who respond to every change you make.
  • Build higher-confidence bot and trust signals so that Faire can enforce more aggressively without turning legitimate logged-out buyers away.
  • Design and operate distributed layer 7 rate limiting, and make the calls on keying, counter state, and where in the stack enforcement belongs.
  • Make incident response for bot and DDoS events a solved problem: clear paging paths, runbooks a non-specialist on-call can execute at 3am, and observability that answers whether humans are actually being affected.
  • Lead post-incident reviews on recurring classes of bot incidents so systemic causes surface instead of repeating.
  • Build the tooling, secure defaults, and playbooks that let service-owning teams protect their own endpoints correctly without you in the loop for every decision.
  • Land a durable ownership model across Security, Platform, service teams, and Anti-Abuse, where every attack vector has a named owner who has accepted it and it holds without escalation.
  • Make Faire's bot posture legible to leadership, including a defensible view of residual risk, and force the outstanding business decisions that engineering is currently making by default.

We’re excited about you because you have:

  • Hands-on operational ownership of a CDN or edge security platform (Cloudflare, Akamai, Fastly, or AWS CloudFront/WAF/Shield) in production against real adversaries, managed as code rather than clicked through a vendor dashboard.
  • Experience defending a high-traffic consumer site against scraping and application-layer DDoS, including the part where the attacker shifts vectors a week after your control ships, and the instinct to design for raising attacker cost rather than for a permanent block.
  • A practical understanding of bot detection signals and where each one fails: TLS and HTTP fingerprinting (JA3/JA4), behavioural signals, mobile device attestation (App Attest, Play Integrity), and challenges, with a real view on the precision and recall trade-off each one carries.
  • Experience designing distributed rate limiting at layer 7, including the differences between per-IP, per-ASN, per-session, and per-fingerprint keying, when each gets evaded, and how to hold counter state across a fleet without the limiter becoming the bottleneck.
  • Quantitative rigour in detection work: you can measure a detection's precision and recall, set a false-positive tolerance with the business, and defend a threshold change with data rather than intuition.
  • A preference for solving traffic and abuse problems with code rather than manual operations, including writing and maintaining internal tooling that on-call engineers depend on mid-incident.
  • Comfort writing and reviewing code in an OOP language such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, find where a control is being bypassed, and open the pull request that fixes it.
  • Working fluency with infrastructure as code and cloud environments (Terraform, AWS or GCP, Kubernetes) sufficient to own a security control plane, and the judgment to know when a Terraform-gated workflow is too slow for an incident and needs a break-glass path with an audit trail.
  • Experience owning incident response for a live traffic attack, including holding the authority to block traffic under time pressure.
  • A track record of setting technical direction in an ambiguous domain with no existing owner, and of sequencing work when everything is nominally urgent.
  • Experience landing a cross-team ownership model without authority, including moving responsibility away from a team that currently holds it and getting other teams to accept obligations they did not ask for.
  • Comfort delivering primarily through other teams rather than personal throughput.
  • The ability to put security risk in business terms for executives, translating traffic and abuse metrics into revenue, cost, and reputational exposure.
  • Clear communication with engineers outside security, describing an attack and its trade-offs without alarmism or unexplained jargon.

Technologies we use and teach:

  • Kotlin, Typescript, Python
  • Edge and CDN security tooling: WAF, rate limiting, bot management, challenge policies
  • AWS, OCI, Terraform, Kubernetes
  • HTTP, JSON, and Protocol Buffers

Salary range:

Canada: the pay range for this role is $190,500 to $262,000 per year.

This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future.

Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting.

Why you’ll love working at Faire

  • Move fast: You'll own meaningful problems that serve customers around the globe with the agency to move fast and see your results clearly.
  • Equipped to scale: We invest in what matters, including the latest enterprise AI tools, to help you work smarter and get more out of every day.
  • Best in class: Our team is full of sharp, kind, and generous colleagues who care about their craft and about helping you grow in yours.
  • Real rewards. Competitive pay, equity, and comprehensive benefits designed to support your life inside and outside of work.
  • Belonging: We're intentional about building an environment where every Faire employee has equal access to opportunities, growth, and success.

Faire was founded in 2017 by a team of early product and engineering leads from Square. We’re backed by some of the top investors in retail and tech including: Y Combinator, Lightspeed Venture Partners, Forerunner Ventures, Khosla Ventures, Sequoia Capital, Founders Fund, and DST Global. We have headquarters in San Francisco and Kitchener-Waterloo, and a global employee presence across offices in Toronto, London, and New York. To learn more about Faire and our customers, you can read more on our blog.

Faire provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity or gender expression.

Faire is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Accommodations are available throughout the recruitment process and applicants with a disability may request to be accommodated throughout the recruitment process. We will work with all applicants to accommodate their individual accessibility needs. To request reasonable accommodation, please fill out our Accommodation Request Form (https://bit.ly/faire-form)

Privacy

For information about the type of personal data Faire collects from applicants, as well as your choices regarding the data collected about you, please visit Faire’s Privacy Notice (https://www.faire.com/privacy)

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Faire's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Faire's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Faire's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.