Anti Abuse Engineer

Supabase Supabase · Data AI · Remote · Security

This role focuses on building and operating systems to detect and remediate abuse on a large-scale, multi-tenant platform. Responsibilities include monitoring signals, triaging abuse cases, leading incident response, tuning detection logic, and automating repetitive tasks. The role emphasizes proactive security and platform architecture improvements to prevent abuse vectors.

What you'd actually do

  1. Monitor Signals: Monitor inbound abuse signals across platform telemetry, HackerOne reports, support queues, and internal alerting pipelines.
  2. Triage End-to-End: Triage abuse cases end-to-end, assessing severity and blast radius, classifying actor types, and routing to the correct response track.
  3. Lead Incidents: Lead response efforts for active abuse incidents, coordinating closely with Platform and Infrastructure teams to execute containment actions and drive remediation to closure.
  4. Tune Logic: Build and tune detection logic against platform telemetry and Supabase-native data sources, including Postgres query patterns, Edge Function invocations, auth anomalies, and storage abuse.
  5. Reduce Toil: Automate repetitive triage and response actions to aggressively reduce manual toil, increase response speed, and improve consistency.

Skills

Required

  • 3+ years of experience in a security operations, trust & safety, or abuse-focused engineering role at a cloud-native product or platform company.
  • hands-on experience with detection logic, including writing rules, tuning thresholds, and reducing noise in high-volume, highly complex signal environments.
  • demonstrate a proven ability to run incident response end-to-end (triage, containment, communication, and postmortems).
  • proficient in SQL and a scripting language (Python heavily preferred) for log analysis, pattern detection, and building automation workflows.
  • deeply familiar with abuse actor techniques, such as credential stuffing, account takeover (ATO), compute abuse, exfiltration, and spam/phishing infrastructure.
  • thrive operating async-first in a globally distributed team

Nice to have

  • Experience with Postgres, PostgREST, or Supabase platform internals.
  • Prior work building, scaling, or operating a multi-tenant abuse detection or trust & safety platform.
  • Familiarity with threat intelligence feeds and IOC enrichment pipelines.
  • Exposure to modern SIEM tooling (Scanner.dev, Splunk, Datadog, or similar).
  • Experience triaging and managing HackerOne or Bugcrowd reports at volume.
  • Working knowledge of SOC 2, ISO 27001, or similar compliance frameworks.

What the JD emphasized

  • treats detection and response as a craft
  • close the loop between signal, triage, and automated remediation
  • fully remote
  • APAC or the West Coast of the Americas
  • clear SLAs
  • aggressively reduce manual toil
  • eliminate abuse vectors by design rather than by reactive response
  • hands-on experience with detection logic
  • writing rules, tuning thresholds, and reducing noise
  • proven ability to run incident response end-to-end
  • script your way out of manual work
  • actual, real-world risk reduction