Platform Security Engineer
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
About the job
Responsibilities
- Identify and reduce security risks across AWS, Kubernetes, containerized workloads, and platform infrastructure.
- Conduct threat modeling, architecture reviews, and technical risk assessments for platform and infrastructure systems.
- Partner with infrastructure, platform, and SRE teams to design practical controls and secure-by-default patterns.
- Improve Kubernetes and container security, including workload isolation, RBAC, admission control, secrets, network policies, and runtime hardening.
- Assess container runtime and Linux isolation risks, including capabilities, seccomp/AppArmor, namespaces, cgroups, and container escape scenarios.
- Strengthen AWS security across IAM, account boundaries, network controls, logging, detection, encryption, and service configuration.
- Build scalable automation, guardrails, paved paths, detections, secure defaults, and review frameworks.
- Prioritize material platform risks over purely theoretical risks and coordinate security efforts across complex projects and stakeholders.
Requirements
- Senior-level experience in platform security, cloud security, infrastructure security, container security, or security engineering.
- Deep practical experience with AWS, Kubernetes, containers, and Linux security fundamentals.
- Experience in large cloud environments, multi-cluster Kubernetes deployments, developer platforms, SaaS platforms, or high-scale infrastructure teams.
- Strong understanding of identity, networking, workload isolation, runtime security, secrets, software supply chain security, and blast radius.
- Clear written and verbal communication with technical and non-technical audiences in an asynchronous environment.
- Ability to manage security efforts across complex projects with multiple stakeholders.
- Ability to solve infrastructure security problems, navigate ambiguity, and build guardrails, automation, and secure defaults.
Benefits
- Fully remote work from anywhere in the world.
- Employee equity through an ESOP.
- Technology allowance.
- Health insurance coverage for employees and dependents.
- Annual company off-sites.
- Flexible asynchronous work.
- Annual professional-development allowance.
Skills
AWS, Kubernetes, Linux, Containers, IAM, RBAC, Network Policies, Threat Modeling, Container Security, Cloud Security, Seccomp, Apparmor, Terraform
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Conduct cloud-focused red team operations, adversary simulations, and offensive security assessments while validating detection coverage and driving remediation. Requires at least five years of offensive security experience and familiarity with attacker techniques, cloud environments, and MITRE ATT&CK.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.