平台安全工程师(美洲/亚太)
Platform Security Engineer (AMER/APAC)
关于 SUPABASE
Supabase 是基于 Postgres 的开发平台,由开发者为开发者打造。我们提供完整的后端解决方案,包括数据库、认证、存储、边缘函数、实时功能和向量搜索。所有服务深度集成,专为增长而设计。
几分钟内即可启动一个完全托管、可扩展的 Postgres 数据库和一套工具,消除后端开发的复杂性。可以使用其中一项或全部——Supabase 为团队提供了开源的灵活性以及现代平台的速度和简便性,让他们在不牺牲控制权的情况下快速前进。
我们正在寻找谁
我们正在寻找一名平台安全工程师加入我们的团队,帮助加强 Supabase 基础设施、云平台、 Kubernetes 环境和容器化工作负载的安全性,随着我们持续扩展。你将与基础设施、平台、SRE、产品工程和技术领导团队紧密合作,帮助我们主动降低运行 Supabase 的系统中的风险。
这个职位适合那些在 AWS、Kubernetes、容器、Linux 和大型云环境方面有深入实践经验,并且对在不拖慢团队进度的前提下保护开发者基础设施充满热情的人。在这个职位上取得成功意味着通过务实的工程、清晰的技术判断和可扩展的防护措施来提升平台的安全态势。
你将负责什么
在这个职位中,你将:
- 识别并减少在 AWS、Kubernetes、容器化工作负载和平台基础设施中的安全风险。
- 对平台和基础设施系统进行威胁建模、架构评审和技术风险评估。
- 与基础设施、平台和 SRE 团队紧密合作,设计实用的控制措施和默认安全模式。
- 提升 Kubernetes 和容器安全,涵盖工作负载隔离、RBAC、准入控制、密钥、网络策略和运行时加固等方面。
- 评估容器运行时和 Linux 隔离风险,包括能力、seccomp/AppArmor、命名空间、cgroups 和容器逃逸场景。
- 在 IAM、账户边界、网络控制、日志、检测、加密和服务配置等方面加强 AWS 安全态势。
- 构建可扩展的机制,如自动化、防护措施、标准路径、检测、安全默认设置和评审框架。
- 区分理论风险和实际平台风险,以有效优先安排安全工作。
查看英文原文
ABOUT SUPABASE
Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.
Start in minutes with a fully managed, scalable Postgres database and a suite of tools that eliminate the complexity of backend development. Use one or use all—Supabase gives teams the flexibility of open source with the speed and simplicity of a modern platform, so they can move fast without sacrificing control.
WHAT ARE WE LOOKING FOR
We’re looking for a Platform Security Engineer to join our team and help strengthen the security of Supabase’s infrastructure, cloud platform, Kubernetes environments, and containerized workloads as we continue to scale. You’ll work closely with infrastructure, platform, SRE, product engineering, and technical leadership, helping us proactively reduce risk across the systems that run Supabase.
This role is ideal for someone who has deep hands-on experience with AWS, Kubernetes, containers, Linux, and large cloud environments and is excited about securing developer infrastructure without slowing teams down. Success in this role means improving the security posture of the platform through pragmatic engineering, clear technical judgment, and scalable guardrails.
WHAT YOU’LL BE RESPONSIBLE FOR
In this role, you’ll:
- Identify and reduce security risk across AWS, Kubernetes, containerized workloads, and platform infrastructure.
- Conduct threat modeling, architecture reviews, and technical risk assessments for platform and infrastructure systems.
- Partner closely with infrastructure, platform, and SRE teams to design practical controls and secure-by-default patterns.
- Improve Kubernetes and container security across areas like workload isolation, RBAC, admission control, secrets, network policy, and runtime hardening.
- Assess container runtime and Linux isolation risks, including capabilities, seccomp/AppArmor, namespaces, cgroups, and container escape scenarios.
- Strengthen AWS security posture across IAM, account boundaries, network controls, logging, detection, encryption, and service configuration.
- Build scalable mechanisms such as automation, guardrails, paved paths, detection, secure defaults, and review frameworks.
- Distinguish between theoretical risk and material platform risk to prioritize security efforts effectively.
YOU MIGHT BE A GOOD FIT IF YOU
- Have senior-level experience in platform security, cloud security, infrastructure security, container security, or security engineering.
- Have deep practical experience with AWS, Kubernetes, containers, and Linux security fundamentals.
- Have worked in large cloud environments, multi-cluster Kubernetes setups, developer platforms, SaaS platforms, or high-scale infrastructure teams.
- Can reason clearly about identity, networking, workload isolation, runtime security, secrets, supply chain, and blast radius.
- Communicate clearly across both technical and non-technical audiences, especially in a written, asynchronous environment.
- Are able to manage security efforts across complex projects with various stakeholders
- Are energized by solving real-world infrastructure security problems and navigating ambiguity while moving quickly.
- Prefer building guardrails, automation, and secure defaults over creating unnecessary process or bottlenecks.
WHAT WE OFFER
- Fully Remote
We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
- ESOP
Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
- Tech Allowance
Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
- Health Benefits
Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.
- Annual Off-Sites
Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
- Flexible Work
We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
- Professional Development
Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.
ABOUT THE TEAM
Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.
- ~400 team members
- 60+ countries
- 20+ languages spoken
- Over $1B raised (including our $500M Series F)
- 540,000+ community members
We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.