RefolkCandidates

Platform Security Engineer (AMER/APAC)

Supabase · Remote, Global

Location
Remote, Global
Workplace
Remote
Employment
Full time
Posted
Yesterday
EngineeringEngineeringSecurity
Tailor my resume to this role

About a minute 25 sent a week, free No card

  1. I read this posting
  2. Rewrite your resume against it
  3. Draft the cover letter, score the fit

Prefer Supabase’s own form? Open the original posting

About this role

About Supabase

Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.

Start in minutes with a fully managed, scalable Postgres database and a suite of tools that eliminate the complexity of backend development. Use one or use all - Supabase gives teams the flexibility of open source with the speed and simplicity of a modern platform, so they can move fast without sacrificing control.

What Are We Looking For

We’re looking for a Platform Security Engineer to join our team and help strengthen the security of Supabase’s infrastructure, cloud platform, Kubernetes environments, and containerized workloads as we continue to scale. You’ll work closely with infrastructure, platform, SRE, product engineering, and technical leadership, helping us proactively reduce risk across the systems that run Supabase.

This role is ideal for someone who has deep hands-on experience with AWS, Kubernetes, containers, Linux, and large cloud environments and is excited about securing developer infrastructure without slowing teams down. Success in this role means improving the security posture of the platform through pragmatic engineering, clear technical judgment, and scalable guardrails.

What You’ll Be Responsible for

In this role, you’ll:

  • Identify and reduce security risk across AWS, Kubernetes, containerized workloads, and platform infrastructure.

  • Conduct threat modeling, architecture reviews, and technical risk assessments for platform and infrastructure systems.

  • Partner closely with infrastructure, platform, and SRE teams to design practical controls and secure-by-default patterns.

  • Improve Kubernetes and container security across areas like workload isolation, RBAC, admission control, secrets, network policy, and runtime hardening.

  • Assess container runtime and Linux isolation risks, including capabilities, seccomp/AppArmor, namespaces, cgroups, and container escape scenarios.

  • Strengthen AWS security posture across IAM, account boundaries, network controls, logging, detection, encryption, and service configuration.

  • Build scalable mechanisms such as automation, guardrails, paved paths, detection, secure defaults, and review frameworks.

  • Distinguish between theoretical risk and material platform risk to prioritize security efforts effectively.

You Might Be a Good Fit If You

  • Have senior-level experience in platform security, cloud security, infrastructure security, container security, or security engineering.

  • Have deep practical experience with AWS, Kubernetes, containers, and Linux security fundamentals.

  • Have worked in large cloud environments, multi-cluster Kubernetes setups, developer platforms, SaaS platforms, or high-scale infrastructure teams.

  • Can reason clearly about identity, networking, workload isolation, runtime security, secrets, supply chain, and blast radius.

  • Communicate clearly across both technical and non-technical audiences, especially in a written, asynchronous environment.

  • Are able to manage security efforts across complex projects with various stakeholders

  • Are energized by solving real-world infrastructure security problems and navigating ambiguity while moving quickly.

  • Prefer building guardrails, automation, and secure defaults over creating unnecessary process or bottlenecks.

What We Offer

  • Fully Remote

    We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.

  • ESOP

    Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.

  • Tech Allowance

    Use this budget to set up your ideal work environment - laptop, monitor, headphones, or whatever helps you do your best work.

  • Health Benefits

    Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.

  • Annual Off-Sites

    Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.

  • Flexible Work

    We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.

  • Professional Development

    Every team member receives an annual education allowance to spend on learning - courses, books, conferences, or anything that supports your growth.

About the Team

Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.

  • ~400 team members

  • 60+ countries

  • 20+ languages spoken

  • Over $1B raised (including our $500M Series F)

  • 540,000+ community members

We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support - not replace - existing tools and communities.

As published by Supabase. Applications are handled on their site.

One click, then it is written

Apply to Supabase with a resume written for this role.

Queue Platform Security Engineer (AMER/APAC) and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Supabase’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Supabase

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Supabase publishes. Refolk is not the employer and does not handle their hiring. Applications go to Supabase directly.