Apply on company website Remote Remote (Global) Full-time

Supabase is hiring an Anti Abuse Engineer

Responsibilities

  • Monitor inbound abuse signals across platform telemetry, HackerOne reports, support queues, and internal alerting pipelines.
  • Triage abuse cases end-to-end, assessing severity and blast radius, classifying actor types, and routing to the correct response track.
  • Own the abuse case queue with clear SLAs to ensure no active threats age out without a definitive decision.
  • Identify complex patterns across distinct cases that point toward coordinated campaigns or emerging attack techniques.
  • Lead response efforts for active abuse incidents, coordinating closely with Platform and Infrastructure teams to execute containment actions and drive remediation to closure.
  • Write clear, timely communications to affected users and internal stakeholders throughout the lifecycle of an incident.
  • Conduct thorough post-incident reviews, feeding findings back into detection rules, runbooks, and platform controls.
  • Maintain and improve incident runbooks to ensure response execution is consistent, scalable, and reproducible across time zones.
  • Build and tune detection logic against platform telemetry and Supabase-native data sources, including Postgres query patterns, Edge Function invocations, auth anomalies, and storage abuse.
  • Automate repetitive triage and response actions to aggressively reduce manual toil, increase response speed, and improve consistency.
  • Contribute to the Anti-Abuse Platform architecture, optimizing the blocklist schema, the remediation action ladder (L1–L4), and enforcement pipelines.
  • Instrument metrics for detection coverage and alert fidelity, closely tracking false positive rates, detection latency, and remediation time.
  • Maintain and improve the abuse operations toolchain, including case management systems, escalation workflows, and engineering reporting dashboards.
  • Partner with Core Engineering to design and implement platform-layer controls that eliminate abuse vectors by design rather than by reactive response.
  • Support Supabase for Platforms (SfP) customers by operationalizing the centralized Anti-Abuse platform for enterprise-grade use cases.

Requirements

  • 3+ years of experience in a security operations, trust & safety, or abuse-focused engineering role at a cloud-native product or platform company.
  • Hands-on experience with detection logic, including writing rules, tuning thresholds, and reducing noise in high-volume, highly complex signal environments.
  • Proven ability to run incident response end-to-end (triage, containment, communication, and postmortems).
  • Proficient in SQL and a scripting language (Python heavily preferred) for log analysis, pattern detection, and building automation workflows.
  • Deeply familiar with abuse actor techniques, such as credential stuffing, account takeover (ATO), compute abuse, exfiltration, and spam/phishing infrastructure.
  • Thrive operating async-first in a globally distributed team — you write clearly, default to explicit documentation, and close loops without needing reminders.

Nice to Have

  • Experience with Postgres, PostgREST, or Supabase platform internals.
  • Prior work building, scaling, or operating a multi-tenant abuse detection or trust & safety platform.
  • Familiarity with threat intelligence feeds and IOC enrichment pipelines.
  • Exposure to modern SIEM tooling (Scanner.dev, Splunk, Datadog, or similar).
  • Experience triaging and managing HackerOne or Bugcrowd reports at volume.
  • Working knowledge of SOC 2, ISO 27001, or similar compliance frameworks.

Benefits

  • Fully Remote: We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
  • ESOP: Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
  • Tech Allowance: Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
  • Health Benefits: Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.
  • Annual Off-Sites: Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
  • Flexible Work: We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
  • Professional Development: Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.

Work Arrangement

Remote (Worldwide) — APAC, West Coast of the Americas

Team

Team size: ~400 team members. Structure: globally distributed team

Additional Information

  • The role provides follow-the-sun coverage alongside our existing Anti-Abuse and Platform Security team members.
  • There are no Supabase offices.
  • We operate asynchronously.
  • The company has 60+ countries represented and 20+ languages spoken.
  • Over $1B raised (including our $500M Series F).
  • 540,000+ community members.
  • We move fast, build in public, and use what we ship.
Required Skills
SQLPostgreSQL
Test your skills for this role

Take a short quiz and show this employer what you can do.

Job Details
Location Remote
Work mode Remote (Global)
Employment Full-time
Department Engineering
Category Security
Posted 2 months ago
Application On company website
About company
Supabase logo
Supabase is the Postgres development platform, built by developers for developers. It provides a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search, all deeply integrated and designed for growth.
All jobs at Supabase Visit website