The posting, in Supabase's own words
archived Sep 2, 2026About Supabase
Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth. Start in minutes with a fully managed, scalable Postgres database and a suite of tools that eliminate the complexity of backend development. Use one or use all—Supabase gives teams the flexibility of open source with the speed and simplicity of a modern platform, so they can move fast without sacrificing control.
What Are We Looking For
We’re looking for a Platform Security Engineer to join our team and help strengthen the security of Supabase’s infrastructure, cloud platform, Kubernetes environments, and containerized workloads as we continue to scale. You’ll work closely with infrastructure, platform, SRE, product engineering, and technical leadership , helping us proactively reduce risk across the systems that run Supabase. This role is ideal for someone who has deep hands-on experience with AWS, Kubernetes, containers, Linux, and large cloud environments and is excited about securing developer infrastructure without slowing teams down. Success in this role means improving the security posture of the platform through pragmatic engineering, clear technical judgment, and scalable guardrails.
Read the full posting ↓
In this role, you’ll:
Identify and reduce security risk across AWS, Kubernetes, containerized workloads, and platform infrastructure. Conduct threat modeling, architecture reviews, and technical risk assessments for platform and infrastructure systems. Partner closely with infrastructure, platform, and SRE teams to design practical controls and secure-by-default patterns. Improve Kubernetes and container security across areas like workload isolation, RBAC, admission control, secrets, network policy, and runtime hardening. Assess container runtime and Linux isolation risks, including capabilities, seccomp/AppArmor, namespaces, cgroups, and container escape scenarios. Strengthen AWS security posture across IAM, account boundaries, network controls, logging, detection, encryption, and service configuration. Build scalable mechanisms such as automation, guardrails, paved paths, detection, secure defaults, and review frameworks. Distinguish between theoretical risk and material platform risk to prioritize security efforts effectively.