About the company
Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.
Start in minutes with a fully managed, scalable Postgres database and a suite of tools that eliminate the complexity of backend development. Use one or use all—Supabase gives teams the flexibility of open source with the speed and simplicity of a modern platform, so they can move fast without sacrificing control.
Responsibilities
- Identify and reduce security risk across AWS, Kubernetes, containerized workloads, and platform infrastructure.
- Conduct threat modeling, architecture reviews, and technical risk assessments for platform and infrastructure systems.
- Partner closely with infrastructure, platform, and SRE teams to design practical controls and secure-by-default patterns.
- Improve Kubernetes and container security across areas like workload isolation, RBAC, admission control, secrets, network policy, and runtime hardening.
- Assess container runtime and Linux isolation risks, including capabilities, seccomp/AppArmor, namespaces, cgroups, and container escape scenarios.
- Strengthen AWS security posture across IAM, account boundaries, network controls, logging, detection, encryption, and service configuration.
- Build scalable mechanisms such as automation, guardrails, paved paths, detection, secure defaults, and review frameworks.
- Distinguish between theoretical risk and material platform risk to prioritize security efforts effectively.
Requirements
- Senior-level experience in platform security, cloud security, infrastructure security, container security, or security engineering.
- Deep practical experience with AWS, Kubernetes, containers, and Linux security fundamentals.
- Experience in large cloud environments, multi-cluster Kubernetes setups, developer platforms, SaaS platforms, or high-scale infrastructure teams.
- Ability to reason clearly about identity, networking, workload isolation, runtime security, secrets, supply chain, and blast radius.
- Clear communication across both technical and non-technical audiences, especially in a written, asynchronous environment.
- Ability to manage security efforts across complex projects with various stakeholders.
- Energized by solving real-world infrastructure security problems and navigating ambiguity while moving quickly.
- Prefer building guardrails, automation, and secure defaults over creating unnecessary process or bottlenecks.
Conditions
- Fully remote: We hire globally. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
- ESOP: Every team member receives equity ownership in the company.
- Tech Allowance: Budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
- Health Benefits: Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are.
- Annual Off-Sites: Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun.
- Flexible Work: We operate asynchronously and trust you to manage your own time.
- Professional Development: Annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.