SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Engineer - Bot & Traffic Defence

Faire Wholesale, Inc. - Kitchener-Waterloo, ON, Canada - Hybrid - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: CAD 190,500 - 262,000 / annual

Faire is a technology wholesale platform connecting independent retailers globally with suppliers. The Bot & Traffic Defence function owns Faire's defenses against automated threats: scraping, credential abuse, and application-layer DDoS attacks, from edge controls through detection and scoring. As the first dedicated Staff Security Engineer in this domain, you will own the technical strategy and roadmap end-to-end. You will author and tune edge security controls as code (WAF rules, rate limiting policies, challenge mechanisms) against real adversaries who actively respond to your changes. You'll build higher-confidence bot and trust signals to enable more aggressive enforcement without blocking legitimate users, and design distributed layer 7 rate limiting with decisions on keying strategies, counter state management, and stack placement. You will make incident response for bot and DDoS events a solved problem: establishing clear paging paths, creating runbooks that non-specialists can execute during incidents, and building observability that shows whether humans are actually affected. You'll lead post-incident reviews to surface systemic causes and prevent recurring incidents. You'll build tooling, secure defaults, and playbooks that empower service-owning teams to protect their own endpoints without requiring your involvement in every decision. Critically, you will establish a durable ownership model across Security, Platform, service teams, and Anti-Abuse—ensuring every attack vector has a named owner who has accepted responsibility. You'll make Faire's bot posture legible to leadership with a defensible view of residual risk, forcing the business decisions that engineering is currently making by default. This role requires hands-on operational ownership of CDN/edge security platforms (Cloudflare, Akamai, Fastly, AWS CloudFront/WAF/Shield) managed as code in production against real adversaries. You need practical experience defending high-traffic consumer sites against scraping and application-layer DDoS, understanding that attackers shift vectors after each control ships—designing to raise attacker cost rather than achieve permanent blocks. You must have deep knowledge of bot detection signals (TLS/HTTP fingerprinting, behavioral signals, mobile device attestation, challenges) and their precision/recall trade-offs. Experience designing distributed rate limiting at layer 7 with different keying strategies (per-IP, per-ASN, per-session, per-fingerprint) and understanding when each gets evaded is essential. You bring quantitative rigor to detection work: measuring precision and recall, setting false-positive tolerances with the business, and defending threshold changes with data. You prefer solving traffic and abuse problems with code rather than manual operations, including writing and maintaining internal tooling that on-call engineers depend on mid-incident. You're comfortable reading and reviewing code in OOP languages (Kotlin, Java, Python, TypeScript) to identify control bypasses and open fixes. You have working fluency with infrastructure-as-code and cloud environments (Terraform, AWS/GCP, Kubernetes) sufficient to own a security control plane, with judgment on when Terraform workflows are too slow for incidents and need break-glass paths with audit trails. You have a track record of owning incident response for live traffic attacks, including holding authority to block traffic under time pressure. You've set technical direction in ambiguous domains with no existing owner and sequenced work when everything is nominally urgent. You've landed cross-team ownership models without formal authority, moving responsibility away from teams that currently hold it and getting other teams to accept new obligations. You deliver primarily through other teams rather than personal throughput, and you can translate traffic and abuse metrics into revenue, cost, and reputational exposure for executives. You communicate clearly with engineers outside security, describing attacks and trade-offs without alarmism or unexplained jargon. Technologies: Kotlin, TypeScript, Python; edge and CDN security tooling (WAF, rate limiting, bot management, challenge policies); AWS, OCI, Terraform, Kubernetes; HTTP, JSON, Protocol Buffers. Hybrid arrangement: 3 days per week in office (Tuesdays, Thursdays, and one flex day), with flexibility to work remotely up to 4 weeks per year.

Similar roles