The posting, in Faire's own words
archived Oct 5, 2026About Faire Faire is a technology wholesale platform built on the belief that the future is local. Independent retailers around the globe collectively represent a multi-hundred-billion-dollar wholesale market that has historically been fragmented and offline. At Faire, we're using the power of tech, data, and machine learning to connect this thriving community of entrepreneurs across the globe. Picture your favorite boutique in town — we help them discover the best products from around the world to sell in their stores. With the right tools and insights, we believe that we can level the playing field so businesses can grow and local communities can thrive. We’re looking for smart, resourceful and passionate people to join us as we power the shop local movement. If you believe in community, come join ours.
About this role:
Our Engineering organization owns the software that makes our marketplace work. Our Bot & Traffic Defence function owns how Faire holds up against automated traffic: scraping, credential abuse, and application-layer DDoS, from the edge through to detection and scoring. We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate. As a Staff Security Engineer, Bot & Traffic Defence, you will be the first dedicated owner of this domain. You will set the technical direction, build the controls and signals that back it, and establish an ownership model that holds across Security, Platform, service teams, and Anti-Abuse. As a Staff Security Engineer, Bot & Traffic Defence, you’ll collaborate with us to: Own the technical strategy and roadmap for bot, scraping, and application-layer DDoS defence end to end, from edge controls through detection and scoring, including revising the strategy where the evidence contradicts it. Author and tune edge security controls as code: WAF rules, rate limiting policies, and challenge mechanisms, against real adversaries who respond to every change you make. Build higher-confidence bot and trust signals so that Faire can enforce more aggressively without turning legitimate logged-out buyers away. Design and operate distributed layer 7 rate limiting, and make the calls on keying, counter state, and where in the stack enforcement belongs. Make incident response for bot and DDoS events a solved problem: clear paging paths, runbooks a non-specialist on-call can execute at 3am, and observability that answers whether humans are actually being affected. Lead post-incident reviews on recurring classes of bot incidents so systemic causes surface instead of repeating. Build the tooling, secure defaults, and playbooks that let service-owning teams protect their own endpoints correctly without you in the loop for every decision. Land a durable ownership model across Security, Platform, service teams, and Anti-Abuse, where every attack vector has a named owner who has accepted it and it holds without escalation. Make Faire's bot posture legible to leadership, including a defensible view of residual risk, and force the outstanding business decisions that engineering is currently making by default.