← Back to results

Staff Security Engineer - Bot & Traffic Defence

Own the technical strategy for bot and traffic defense at Faire, leading security initiatives in a hybrid work environment.

Location
Kitchener-Waterloo, ON; Toronto, ON
Compensation
CA$190.5k–CA$262k/yr
Level
staff
Type
full time · Hybrid

Posted by employer 1 day ago

First seen on Joblaze 8 hours ago

Last verified on the company career page 8 hours ago

What you'll build

  • Own the technical strategy and roadmap for bot and DDoS defense
  • Author and tune edge security controls as code
  • Design and operate distributed layer 7 rate limiting
  • Lead post-incident reviews on bot incidents
  • Build tooling and playbooks for service-owning teams

Must have

  • Hands-on operational ownership of a CDN or edge security platform
  • Experience defending a high-traffic consumer site against scraping and DDoS
  • Practical understanding of bot detection signals
  • Experience designing distributed rate limiting at layer 7
  • Quantitative rigour in detection work

Nice to have

  • Comfort writing and reviewing code in an OOP language
  • Experience owning incident response for a live traffic attack
  • Track record of setting technical direction in an ambiguous domain
  • Experience landing a cross-team ownership model without authority
  • Ability to put security risk in business terms for executives

Practical constraints

  • Hybrid Faire employees currently go into the office 3 days per week

Not disclosed in this posting: years of experience, visa sponsorship.

Benefits

Equity/Stock Options Remote Work

Joblaze summary

In the role of Staff Security Engineer for Bot & Traffic Defence, the individual will lead efforts to protect Faire's platform from automated threats such as scraping and DDoS attacks, developing and implementing security controls and strategies. Key skills include hands-on experience with edge security platforms and a strong understanding of bot detection mechanisms, alongside proficiency in programming languages like Kotlin and Python. This position is suited for a senior engineer with a track record of setting technical direction in complex environments and fostering cross-team collaboration. Faire's engineering team emphasizes good practices and scalable solutions, making this a pivotal

Joblaze insights

  • Listed today — first seen on Joblaze October 1, 2026. Last confirmed on Faire's careers page October 1, 2026.
  • Starts above 7% of 96 comparable staff security roles we track (median $200,000 across 38 companies).

Quick facts

Is the Staff Security Engineer - Bot & Traffic Defence role remote?
It's hybrid — Faire expects some on-site time in Kitchener-Waterloo, ON; Toronto, ON.
What's the salary range?
Faire lists CAD 190,500–CAD 262,000 for this role.
Where is the role based?
Faire is hiring for this position in Kitchener-Waterloo, ON; Toronto, ON.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Kotlin, Kubernetes, Python, Terraform, TypeScript.
What seniority level is this role?
Faire targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Security Engineer - Bot & Traffic Defence role at Faire.

From the original posting

About Faire

About this role:

Our Engineering organization owns the software that makes our marketplace work. Our Bot & Traffic Defence function owns how Faire holds up against automated traffic: scraping, credential abuse, and application-layer DDoS, from the edge through to detection and scoring. We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate.

As a Staff Security Engineer, Bot & Traffic Defence, you will be the first dedicated owner of this domain. You will set the technical direction, build the controls and signals that back it, and establish an ownership model that holds across Security, Platform, service teams, and Anti-Abuse.

As a Staff Security Engineer, Bot & Traffic Defence, you’ll collaborate with us to:

  • Own the technical strategy and roadmap for bot, scraping, and application-layer DDoS defence end to end, from edge controls through detection and scoring, including revising the strategy where the evidence contradicts it.

  • Author and tune edge security controls as code: WAF rules, rate limiting policies, and challenge mechanisms, against real adversaries who respond to every change you make.

  • Build higher-confidence bot and trust signals so that Faire can enforce more aggressively without turning legitimate logged-out buyers away.

  • Design and operate distributed layer 7 rate limiting, and make the calls on keying, counter state, and where in the stack enforcement belongs.

  • Make incident response for bot and DDoS events a solved problem: clear paging paths, runbooks a non-specialist on-call can execute at 3am, and observability that answers whether humans are actually being affected.

  • Lead post-incident reviews on recurring classes of bot incidents so systemic causes surface instead of repeating.

  • Build the tooling, secure defaults, and playbooks that let service-owning teams protect their own endpoints correctly without you in the loop for every decision.

  • Land a durable ownership model across Security, Platform, service teams, and Anti-Abuse, where every attack vector has a named owner who has accepted it and it holds without escalation.

  • Make Faire's bot posture legible to leadership, including a defensible view of residual risk, and force the outstanding business decisions that engineering is currently making by default.

We’re excited about you because you have:

  • Hands-on operational ownership of a CDN or edge security platform (Cloudflare, Akamai, Fastly, or AWS CloudFront/WAF/Shield) in production against real adversaries, managed as code rather than clicked through a vendor dashboard.

  • Experience defending a high-traffic consumer site against scraping and application-layer DDoS, including the part where the attacker shifts vectors a week after your control ships, and the instinct to design for raising attacker cost rather than for a permanent block.

  • A practical understanding of bot detection signals and where each one fails: TLS and HTTP fingerprinting (JA3/JA4), behavioural signals, mobile device attestation (App Attest, Play Integrity), and challenges, with a real view on the precision and recall trade-off each one carries.

  • Experience designing distributed rate limiting at layer 7, including the differences between per-IP, per-ASN, per-session, and per-fingerprint keying, when each gets evaded, and how to hold counter state across a fleet without the limiter becoming the bottleneck.

  • Quantitative rigour in detection work: you can measure a detection's precision and recall, set a false-positive tolerance with the business, and defend a threshold change with data rather than intuition.

  • A preference for solving traffic and abuse problems with code rather than manual operations, including writing and maintaining internal tooling that on-call engineers depend on mid-incident.

  • Comfort writing and reviewing code in an OOP language such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, find where a control is being bypassed, and open the pull request that fixes it.

  • Working fluency with infrastructure as code and cloud environments (Terraform, AWS or GCP, Kubernetes) sufficient to own a security control plane, and the judgment to know when a Terraform-gated workflow is too slow for an incident and needs a break-glass path with an audit trail.

  • Experience owning incident response for a live traffic attack, including holding the authority to block traffic under time pressure.

  • A track record of setting technical direction in an ambiguous domain with no existing owner, and of sequencing work when everything is nominally urgent.

  • Experience landing a cross-team ownership model without authority, including moving responsibility away from a team that currently holds it and getting other teams to accept obligations they did not ask for.

  • Comfort delivering primarily through other teams rather than personal throughput.

  • The ability to put security risk in business terms for executives, translating traffic and abuse metrics into revenue, cost, and reputational exposure.

  • Clear communication with engineers outside security, describing an attack and its trade-offs without alarmism or unexplained jargon.

Technologies we use and teach:

  • Kotlin, Typescript, Python

  • Edge and CDN security tooling: WAF, rate limiting, bot management, challenge policies

  • AWS, OCI, Terraform, Kubernetes

  • HTTP, JSON, and Protocol Buffers

Salary range:

Canada: the pay range for this role is $190,500 to $262,000 per year.

Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting.

Standard company text repeated across Faire's postings is omitted here.

Similar positions

Faire
Staff Software Engineer - Code Authoring
Faire · Kitchener-Waterloo, ON; Toronto, ON
Faire
Senior Security Engineer - Application Security
Faire · Kitchener-Waterloo, ON; Toronto, ON
Faire
Senior Product Engineer - Value
Faire · Kitchener-Waterloo, ON; Toronto, ON
Faire
Staff Software Engineer - Growth Platform
Faire · Kitchener-Waterloo, ON; Toronto, ON
Faire
Senior Enterprise Security Engineer
Faire · San Francisco, CA