Cloud Platform Engineer
Job Description
About the Role
As a Cloud Platform Engineer at Supabase, you’ll join Cloud Engineering, part of Engineering Operations, and shape the foundations that let engineering teams build, ship, and operate infrastructure safely and independently across AWS and GCP.
This is a role spanning cloud governance, platform engineering, and hands-on operations. You’ll work across AWS and GCP account structure, identity and access management, Infrastructure as Code (IaC), reusable platform primitives, security boundaries, and self-service workflows for engineers.
You’ll be joining at a point where many of these foundations are being actively defined or reworked. We’re looking for someone who can take ambiguous, messy, business-critical infrastructure problems and turn them into pragmatic systems, tools, standards, and written guidance that scale with the company and empower teams to go faster.
What You’ll Be Responsible For
• Designing and implementing cloud governance across AWS and GCP, including identity, account organization, access controls, and guardrails.
• Building reusable infrastructure and building blocks using Infrastructure as Code (IaC), enabling teams to provision and manage infrastructure safely and consistently.
• Creating self-service capabilities that reduce organizational friction and let engineers move more quickly within sensible boundaries.
• Owning resource governance and visibility: management tagging, a trustworthy inventory of what exists and who owns it, and consistent cross-account billing data.
• Developing reusable security primitives, including secrets storage, KMS, certificate management, token vending, direct service-to-service authentication, mTLS, and related platform services.
• Owning cloud-level network and operational primitives: IP address management, DNS, and health signals such as service-limit and quota alerting.
• Combining software engineering with hands-on operations and total ownership: building, deploying, monitoring, troubleshooting, and improving what you own.
• Establishing and sharing cloud engineering best practices through documentation, internal tooling, examples, and enablement.
You Might Be a Good Fit If You
• Have 5+ years of experience in cloud governance, platform engineering, and/or operations, have operated production systems at scale, and carried on-call for them.
• Have previously undertaken a significant migration, e.g. rearchitected an AWS account topology, introduced IaC for existing infrastructure, centralized identity/SSO, or brought a second cloud under governance.
• Enjoy building internal platform and self-service experiences for other engineers.
• Are genuinely deep in at least one—ideally two—of the three strength areas below (and tell us which is your center of gravity):
• Tooling & ecosystem: You’re intimately familiar with the breadth of AWS services in general, and IAM/SSO in particular. You know their Well-Architected Framework, and when to reach outside. You have working knowledge of GCP. You use IaC routinely and have run it in production, whichever tool. You’ve probably collaborated with auditors on meeting compliance requirements.
• Software engineering: You write real production code (Go, Rust, or a comparable systems language), and can build reliable, maintainable services. You thrive across all stages of the SDLC, set technical direction, know how to de-risk projects, and produce written artifacts such as RFCs.
• Operations: You’ve run production infrastructure yourself: carried the pager, written the alerts and runbooks, used SLOs or similar to decide what to fix first, and made shared systems less risky over time. You like owning systems, simplifying complex infrastructure problems, and turning best practices into reusable building blocks.
• Are comfortable treating infrastructure as software and have relevant experience with IaC and automation.
• Communicate clearly, work with a wide range of stakeholders, and thrive in async, globally distributed teams.
• Are comfortable navigating ambiguity and iterating toward better systems over time.
What We Offer
• Fully Remote
We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
• ESOP
Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
• Tech Allowance
Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
• Health Benefits
Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.
• Annual Off-Sites
Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
• Flexible Work
We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
• Professional Development
Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.
About the Team
Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.
• ~400 team members
• 60+ countries
• 20+ languages spoken
• Over $1B raised (including our $500M Series F)
• 540,000+ community members
We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.
Requirements
Department: Engineering
Team: Container Engineering