Anti Abuse Engineer
SupabaseAbout Supabase
Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.
About the Role
Supabase serves millions of developers on a shared, multi-tenant platform. At that scale, abuse is not an edge case — it is a continuous operational reality. Credential stuffing, free-tier compute abuse, API scraping, malicious project provisioning, and exfiltration attempts occur every day. We need someone who treats detection and response as a craft, and who can close the loop between signal, triage, and automated remediation.
You will work directly with our Anti-Abuse Lead and embed with Platform Security and Product Security to build and operate the systems that protect Supabase and its customers from abuse at scale. This role sits inside the security org but operates at the intersection of security engineering, data analysis, and platform operations.
This role provides follow-the-sun coverage alongside our existing Anti-Abuse and Platform Security team members. It is fully remote, with a strong preference for candidates based in APAC or the West Coast of the Americas.
What You’ll Own
Abuse Detection & Signal Triage
Monitor Signals: Monitor inbound abuse signals across platform telemetry, HackerOne reports, support queues, and internal alerting pipelines.
Triage End-to-End: Triage abuse cases end-to-end, assessing severity and blast radius, classifying actor types, and routing to the correct response track.
Queue Ownership: Own the abuse case queue with clear SLAs to ensure no active threats age out without a definitive decision.
Pattern Recognition: Identify complex patterns across distinct cases that point toward coordinated campaigns or emerging attack techniques.
Incident Response & Remediation
Lead Incidents: Lead response efforts for active abuse incidents, coordinating closely with Platform and Infrastructure teams to execute containment actions and drive remediation to closure.
Communications: Write clear, timely communications to affected users and internal stakeholders throughout the lifecycle