Supabase

Anti Abuse Engineer

Middle · Удалённо · Английский B2

Не указано: география

Навыки

  • API (интеграции)
  • Анализ данных
  • Datadog / New Relic
  • Форензика и реагирование
  • ISO 27001 / PCI DSS
  • Мониторинг и observability
  • Ответственность за результат
Ещё 10
  • PostgreSQL
  • Python
  • RAG
  • Маршрутизация и NAT
  • SIEM
  • SOC
  • Splunk / ArcSight / QRadar
  • SQL
  • Первая и вторая линия
  • YARA / threat intelligence

О компании и продукте

  • Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.
  • Supabase serves millions of developers on a shared, multi-tenant platform. At that scale, abuse is not an edge case — it is a continuous operational reality. Credential stuffing, free-tier compute abuse, API scraping, malicious project provisioning, and exfiltration attempts occur every day. We need someone who treats detection and response as a craft, and who can close the loop between signal, triage, and automated remediation.
  • You will work directly with our Anti-Abuse Lead and embed with Platform Security and Product Security to build and operate the systems that protect Supabase and its customers from abuse at scale. This role sits inside the security org but operates at the intersection of security engineering, data analysis, and platform operations.
  • This role provides follow-the-sun coverage alongside our existing Anti-Abuse and Platform Security team members. It is fully remote, with a strong preference for candidates based in APAC or the West Coast of the Americas.

Задачи

  • ABUSE DETECTION & SIGNAL TRIAGE
  • Monitor Signals: Monitor inbound abuse signals across platform telemetry, HackerOne reports, support queues, and internal alerting pipelines
  • Triage End-to-End: Triage abuse cases end-to-end, assessing severity and blast radius, classifying actor types, and routing to the correct response track
  • Queue Ownership: Own the abuse case queue with clear SLAs to ensure no active threats age out without a definitive decision
  • Pattern Recognition: Identify complex patterns across distinct cases that point toward coordinated campaigns or emerging attack techniques
  • INCIDENT RESPONSE & REMEDIATION
  • Lead Incidents: Lead response efforts for active abuse incidents, coordinating closely with Platform and Infrastructure teams to execute containment actions and drive remediation to closure
  • Communications: Write clear, timely communications to affected users and internal stakeholders throughout the lifecycle of an incident
  • Postmortems: Conduct thorough post-incident reviews, feeding findings back into detection rules, runbooks, and platform controls
  • Runbook Maintenance: Maintain and improve incident runbooks to ensure response execution is consistent, scalable, and reproducible across time zones
  • DETECTION ENGINEERING & AUTOMATION
  • Tune Logic: Build and tune detection logic against platform telemetry and Supabase-native data sources, including Postgres query patterns, Edge Function invocations, auth anomalies, and storage abuse
  • Reduce Toil: Automate repetitive triage and response actions to aggressively reduce manual toil, increase response speed, and improve consistency
  • Platform Architecture: Contribute to the Anti-Abuse Platform architecture, optimizing the blocklist schema, the remediation action ladder (L1–L4), and enforcement pipelines
  • Metrics & Fidelity: Instrument metrics for detection coverage and alert fidelity, closely tracking false positive rates, detection latency, and remediation time
  • TOOLING & PLATFORM IMPROVEMENT
  • Toolchain Operations: Maintain and improve the abuse operations toolchain, including case management systems, escalation workflows, and engineering reporting dashboards
  • Proactive Security: Partner with Core Engineering to design and implement platform-layer controls that eliminate abuse vectors by design rather than by reactive response
  • Enterprise Support: Support Supabase for Platforms (SfP) customers by operationalizing the centralized Anti-Abuse platform for enterprise-grade use cases
  • YOU MIGHT BE A GOOD FIT IF YOU
  • Are proficient in SQL and a scripting language (Python heavily preferred) for log analysis, pattern detection, and building automation workflows
  • Are deeply familiar with abuse actor techniques, such as credential stuffing, account takeover (ATO), compute abuse, exfiltration, and spam/phishing infrastructure

Требования

  • Have 3+ years of experience in a security operations, trust & safety, or abuse-focused engineering role at a cloud-native product or platform company
  • Possess hands-on experience with detection logic, including writing rules, tuning thresholds, and reducing noise in high-volume, highly complex signal environments
  • Demonstrate a proven ability to run incident response end-to-end (triage, containment, communication, and postmortems)

Будет плюсом

  • Experience with Postgres, PostgREST, or Supabase platform internals
  • Prior work building, scaling, or operating a multi-tenant abuse detection or trust & safety platform
  • Familiarity with threat intelligence feeds and IOC enrichment pipelines
  • Exposure to modern SIEM tooling (Scanner.dev http://Scanner.dev, Splunk, Datadog, or similar)
  • Experience triaging and managing HackerOne or Bugcrowd reports at volume
  • Working knowledge of SOC 2, ISO 27001, or similar compliance frameworks
  • WHAT WE’RE NOT LOOKING FOR
  • A ticket-closer who doesn't own outcomes. We care about resolved, thoroughly mitigated issues, not just triaged tickets
  • A pure analyst who doesn’t write code. Automation is a first-class expectation at this level
  • you must be able to script your way out of manual work
  • A compliance-first mindset that mistakes rigid documentation for actual, real-world risk reduction

Условия

  • Fully Remote
  • We hire globally
  • We believe you can do your best work from anywhere
  • There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world
  • Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together
  • Tech Allowance
  • Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work
  • Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us
  • Annual Off-Sites
  • Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year
  • Flexible Work
  • We operate asynchronously and trust you to manage your own time. You know what needs to be done and when
  • Professional Development
  • Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth

Паспорт вакансии

История публикации

Появилась в Вакандии30 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели 30 дней назад
Среди похожихНет данных138 из 30 · у похожих вакансий почти одинаковый возраст — сравнивать нечего

Откуда что взялось

Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.

ГрейдMiddleвыведено из другого признака
Формат работыУдалённовычитано из текста вакансии
Географияне указана
Зарплата≈ 16 667 USD в месяцнаша оценка, в вакансии не названа

Почему на этом месте в выдаче

Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.

Полнота карточки753 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка

Проверка Вакандии

Источники и свежесть

Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
  • ashbyОсновная публикация · 2026-06-18

Работодатель

Supabase

39 активных вакансий · вилка работодателя указана в 0%

Открыть профиль компании

Безопасность

Отклик уходит на сайт источника

Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайтеjobs.ashbyhq.com.

Признаки мошенничества
  • Просят предоплату, «залог» или деньги за обучение и оборудование.
  • Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
  • Быстро уводят в мессенджер и торопят с решением.
  • Обещают большой доход без опыта и без деталей задач.

Настоящий работодатель не просит денег и платёжных данных до трудоустройства.

Продолжить поиск

Похожие вакансии

Причина сходства указана на каждой карточке

  1. Почему похожа: похожая специализация · тот же грейд

    CSSSR

    DevOps-инженер

    • Middle
    • Удалённо
    Подробнее