SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Supabase is a Postgres development platform providing a complete backend solution including database, auth, storage, edge functions, realtime, and vector search. The company is seeking a Platform Security Engineer to strengthen security across Supabase's infrastructure, cloud platform, Kubernetes environments, and containerized workloads as it scales.
In this role, you will identify and reduce security risk across AWS, Kubernetes, containerized workloads, and platform infrastructure. You'll conduct threat modeling, architecture reviews, and technical risk assessments for platform and infrastructure systems. Working closely with infrastructure, platform, SRE, product engineering, and technical leadership teams, you'll design practical controls and secure-by-default patterns that don't slow down development.
Key responsibilities include improving Kubernetes and container security across workload isolation, RBAC, admission control, secrets management, network policy, and runtime hardening. You'll assess container runtime and Linux isolation risks, including capabilities, seccomp/AppArmor, namespaces, cgroups, and container escape scenarios. You'll strengthen AWS security posture across IAM, account boundaries, network controls, logging, detection, encryption, and service configuration.
You'll build scalable mechanisms such as automation, guardrails, paved paths, detection, secure defaults, and review frameworks. Success means distinguishing between theoretical risk and material platform risk to prioritize security efforts effectively.
Ideal candidates have senior-level experience in platform security, cloud security, infrastructure security, container security, or security engineering. You should have deep practical experience with AWS, Kubernetes, containers, and Linux security fundamentals, and have worked in large cloud environments, multi-cluster Kubernetes setups, developer platforms, or high-scale infrastructure teams. You can reason clearly about identity, networking, workload isolation, runtime security, secrets, supply chain, and blast radius. You communicate clearly across technical and non-technical audiences in written, asynchronous environments and can manage security efforts across complex projects with various stakeholders.