The opportunity
Supabase serves millions of developers on a shared, multi-tenant platform. At that scale, abuse is not an edge case — it is a continuous operational reality.
What you'll do
Monitor Signals: Monitor inbound abuse signals across platform telemetry, HackerOne reports, support queues, and internal alerting pipelines.
Triage End-to-End: Triage abuse cases end-to-end, assessing severity and blast radius, classifying actor types, and routing to the correct response track.
Queue Ownership: Own the abuse case queue with clear SLAs to ensure no active threats age out without a definitive decision.
Pattern Recognition: Identify complex patterns across distinct cases that point toward coordinated campaigns or emerging attack techniques.
Lead Incidents: Lead response efforts for active abuse incidents, coordinating closely with Platform and Infrastructure teams to execute containment actions and drive remediation to closure.
Communications: Write clear, timely communications to affected users and internal stakeholders throughout the lifecycle of an incident.
What they're looking for
- Postmortems: Conduct thorough post-incident reviews, feeding findings back: into detection rules, runbooks, and platform controls.
- Runbook Maintenance: Maintain and improve incident runbooks to ensure response execution is consistent, scalable, and reproducible across time zones.
- Tune Logic: Build and tune detection logic against platform telemetry and: Supabase-native data sources, including Postgres query patterns, Edge Function invocations, auth anomalies, and storage abuse.
- Reduce Toil: Automate repetitive triage and response actions to aggressively: reduce manual toil, increase response speed, and improve consistency.