Security Operations Engineer
crypto:securityengineeringIC4Security
Compensation
Not disclosed
ABOUT SUPABASE
Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.
ABOUT THE ROLE
We’re looking for a Security Operations Engineer to join our Product Security team and help provide front-line coverage for security alerts, customer security tickets, and internal IT requests as Supabase continues to scale.
This is an entry-level role designed for someone with strong judgment, curiosity, and clear communication. You’ll be one of three Security Operations Engineers working in a follow-the-sun rotation across New Zealand/Australia, Sri Lanka, and US Eastern, helping Supabase maintain effective 24-hour coverage for security-relevant work. You’ll triage alerts, handle customer security requests, support internal IT operations, improve runbooks, and escalate clearly to the right teams when issues need deeper investigation.
WHAT YOU’LL BE RESPONSIBLE FOR
In this role, you’ll:
- First Response & Triage: Act as the first responder for security alerts from GuardDuty, dependency advisories, and other detection sources. Assess severity and escalate to the right lead across Platform, Product, Anti-Abuse, or Security.
- Customer Security Operations: Own customer security tickets in Front, including account recovery, MFA reset, GitHub-linked account loss, billing-based ownership verification, and org ownership disputes.
- Incident Response Support: Participate in the on-call pager rotation alongside other Security Operations Engineers and use documented playbooks to make consistent decisions.
- Process Improvement: Maintain and improve runbooks, decision trees, Front macros, and escalation paths. Identify patterns in tickets and alerts to flag opportunities for automation or workflow improvements.
- Internal IT Support & Compliance: Triage internal IT requests (acc