Staff Software Engineer - Site Defense
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
About the job
Responsibilities
- Design, build, and operate high-scale, low-latency systems that protect Reddit from DDoS attacks, bots, and automated abuse.
- Analyze, develop, and evolve ingress-level defenses across CDN, edge, and internal infrastructure layers.
- Build systems to detect, score, and mitigate malicious traffic in real time at per-request and per-user granularity.
- Collaborate with Infrastructure, Security, and Safety teams to balance security, performance, and user experience.
- Mentor junior engineers.
- Contribute to ML-at-ingress initiatives, including traffic classification, bot detection, and anomaly detection models.
- Own services end to end, including design, implementation, on-call, and operational excellence.
- Participate in incident response and post-incident analysis for large-scale network or abuse events.
Requirements
- 7+ years of experience building and operating high-throughput, low-latency production distributed systems.
- Software development experience in one or more general-purpose programming languages, including Python, Go, Rust, Java, or C++.
- Excellent communication and collaboration skills.
- Experience with DDoS mitigation, WAFs, bot management, or abuse prevention systems.
- Experience with networking fundamentals, including HTTP, TLS, TCP/IP, proxies, CDNs, and load balancing.
Nice to Have
- Experience with anti-abuse frameworks and bot scoring, such as ReCaptcha, DataDome, or Turnstile.
- Experience with browser fingerprinting frameworks, such as FingerprintJS or ThumbmarkJS.
- Familiarity with production ML systems, especially real-time inference or feature pipelines.
Compensation
- Base salary range: $217,000–$303,900 USD.
- Eligible for equity in the form of restricted stock units.
- Comprehensive healthcare and income replacement programs.
- 401(k) with employer match.
- Global benefits supporting workspace, professional development, and caregiving.
- Family planning support.
- Gender-affirming care.
- Mental health and coaching benefits.
- Flexible vacation and paid volunteer time off.
- Paid parental leave.
Skills
Distributed Systems, Python, Go, Rust, Java, C++, Ddos Mitigation, Web Application Firewall, Bot Management, Http, Tls, TCP/IP, Cdns, Load Balancing, Machine Learning
Similar jobs
Security Engineering jobsStaff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.