Senior Technical Product Manager, API Traffic and Enforcement
Fastly, Inc. · San Francisco Bay Area
📍 San Francisco, CA💰 $181,220via greenhousePosted 2026-09-22
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Fastly, Inc..
Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastly’s customers include many of the world’s most prominent companies, including GitHub, Yelp, Paramount, and JetBlue.
We're building a more trustworthy Internet. Come join us.
Posting Open Date: Sep 21st, 2026
Anticipated Posting Close Date*: Nov 30, 2026
*Job posting may close early due to the volume of applicants.
Senior Technical Product Manager, API Traffic and Enforcement
APIs are how software talks to software, and the volume and variety of that traffic is growing rapidly. AI agents now discover and call APIs directly, and MCP servers are a new kind of endpoint with the same questions attached: what exists, what it's supposed to do, and who is allowed to call it. Enterprises are challenged to respond to those questions. This role owns Fastly's answer.
As a Senior Technical Product Manager on Fastly's Core Infrastructure Product Management team, you will own how Fastly defines what traffic is allowed and how traffic is held to that definition. That means our customers' API surface end to end – discovery and inventory of the APIs they actually run, the schemas that describe intended behavior, and the API gateway itself – and the enforcement primitives underneath it, including ACLs, allowlists, rate limiting, and the request-path controls that turn a declared model into something the platform actually enforces. Much of security is about detecting the bad. Your charter is the other half: defining what good looks like and enforcing it.
Customer APIs are the first and largest surface for the positive model, and the primitives you own are the ones other products adopt as that model extends across the platform. This role reports to the Director of Core Infrastructure Product Management and has real latitude to set direction.
What You'll Do:
Own the positive model end to end: drive the strategy and roadmap for defining what traffic is allowed. You will take customers from not knowing what APIs they run, to describing intended behavior precisely, to enforcing it in the request path.
Make API discovery tell customers something they didn't know: own discovery and inventory across the API surfaces customers actually operate. Discovery is where most customers start, and how good it is determines whether they trust anything built on top of it.
Turn schemas into enforceable contracts: own schema definition, generation, and validation. When customers can't hand you an accurate spec for their own APIs, the product has to produce one worth enforcing against, then keep it accurate as their APIs change.
Own enforcement in the request path: ACLs, allowlists, rate limiting, and the controls that turn a declared model into something the platform enforces, along with the gateway that applies them. Build these as primitives other products can adopt, not features scoped to one surface.
Make agents first-class: agents calling APIs are a new kind of client, and MCP servers are a new kind of endpoint. Define how Fastly identifies them, authorizes them, and holds them to allowed behavior.
Take and defend clear positions: bring evidence-based points of view on how traffic should be described and constrained, and drive them to decisions across engineering, product, and partner teams. You will bring structure to ambiguous problems and move decisions forward earlier.
What We're Looking For:
Experience: 5+ years in product management or technical product leadership, ideally on API, security, or platform infrastructure products.
API and request-path fluency: you understand how API traffic is described, validated, and constrained — schemas and specs, gateway behavior, and the difference between allowlist models and detection-based ones. You can reason about where each fits and what it costs to run.
Platform thinking: a track record of building capabilities that serve more than one product or team. Shared primitives, enforcement points, or controls others build on, rather than features scoped to a single surface.
Execution focus: a demonstrated bias for shipping. You are hands-on and comfortable owning outcomes in ambiguous, fast-moving conditions rather than waiting for perfect clarity.
Conviction and influence: the ability to form clear, evidence-based positions and defend them across engineering and product partners, including pushing back constructively. You build alignment without relying on authority.
Communication and presentation: a clear communicator who can move between deep technical discussion with engineers and crisp framing for customers and executives, with genuine curiosity about the "why" behind a customer's problem. You can stand up in front of a room, make a case, and hold it under questioning.
We’ll be super impressed if you have experience in any of these:
Hands-on work with API gateways and OpenAPI-driven validation: schema generation from live traffic, drift detection as APIs change, and the gap between the spec a team publishes and what their API actually does.
The agentic traffic stack — workload and agent identity (SPIFFE/WIMSE, mTLS), OAuth 2.1 for delegated agent authorization, and agent protocols like MCP and its authorization spec.
Request-path enforcement at scale: WASM filters, eBPF, or policy engines like OPA and Rego.
Startup or 0-to-1 experience building API, security, or infrastructure products in a fast-moving environment.
Work Hours: This position will require you to be available during core business hours.
Work Location(s) & Travel Requirements:
T
More San Francisco Bay Area jobs
San Francisco Bay Area jobs · Browse all locations