fastly
San Francisco · On-site · Full-time
<div class="content-intro"><p>Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastly’s customers include many of the world’s most prominent companies, including GitHub, Yelp, Paramount, and JetBlue.</p> <p>We're building a more trustworthy Internet. Come join us.</p></div><p><span style="color: #000000;"><strong>Posting Open Date: </strong>Sep 21st, 2026</span></p> <p><span style="color: #000000;"><strong>Anticipated Posting Close Date*: </strong>Nov 30, 2026</span></p> <p><span style="color: #000000;"><em>*Job posting may close early due to the volume of applicants.</em></span></p> <p><span style="color: #000000;"><strong>Senior Technical Product Manager, API Traffic and Enforcement</strong></span></p> <p><span style="color: #000000;">APIs are how software talks to software, and the volume and variety of that traffic is growing rapidly. AI agents now discover and call APIs directly, and MCP servers are a new kind of endpoint with the same questions attached: what exists, what it's supposed to do, and who is allowed to call it. Enterprises are challenged to respond to those questions. This role owns Fastly's answer.</span></p> <p><span style="color: #000000;">As a Senior Technical Product Manager on Fastly's Core Infrastructure Product Management team, you will own how Fastly defines what traffic is allowed and how traffic is held to that definition. That means our customers' API surface end to end – discovery and inventory of the APIs they actually run, the schemas that describe intended behavior, and the API gateway itself – and the enforcement primitives underneath it, including ACLs, allowlists, rate limiting, and the request-path controls that turn a declared model into something the platform actually enforces. Much of security is about detecting the bad. Your charter is the other half: defining what good looks like and enforcing it.</span></p> <p><span style="color: #000000;">Customer APIs are the first and largest surface for the positive model, and the primitives you own are the ones other products adopt as that model extends across the platform. This role reports to the Director of Core Infrastructure Product Management and has real latitude to set direction.</span></p> <p><span style="color: #000000;"><strong>What You'll Do:</strong></span></p> <ul> <li style="color: #000000 !important;"><span style="color: #000000;"><strong>Own the positive model end to end: </strong>drive the strategy and roadmap for defining what traffic is allowed. You will take customers from not knowing what APIs they run, to describing intended behavior precisely, to enforcing it in the request path.</span></li> <li style="color: #000000 !important;"><span style="color: #000000;"><strong>Make API discovery tell customers something they didn't know: </strong>own discovery and inventory across the API surfaces customers actually operate. Discovery is where most customers start, and how good it is determines whether they trust anything built on top of it.</span></li> <li style="color: #000000 !important;"><span style="color: #000000;"><strong>Turn schemas into enforceable contracts:</strong> own schema definition, generation, and validation. When customers can't hand you an accurate spec for their own APIs, the product has to produce one worth enforcing against, then keep it accurate as their APIs change.</span></li> <li style="color: #000000 !important;"><span style="color: #000000;"><strong>Own enforcement in the request path: </strong>ACLs, allowlists, rate limiting, and the controls that turn a declared model into something the platform enforces, along with the gateway that applies them. Build these as primitives other products can adopt, not features scoped to one surface.</span></li> <li style="color: #000000 !important;"><span style="color: #000000;"><strong>Make agents first-class: </strong>agents calling APIs are a new kind of client, and MCP s
fastly
Posted via Greenhouse_public
Apply Now takes you to Rozgoo, where auto-apply can submit your application for this role. Updated 4 days ago.
Apply Now