Software Engineer - Auth
WFA Digital Insight
Supabase's Auth product is a cornerstone of their Postgres development platform, and they're seeking an experienced Software Engineer to further enhance its capabilities. This role stands out for its focus on building and maintaining secure, scalable authentication features, which are critical in today's digital landscape. The successful candidate will have a deep understanding of authentication protocols and a strong background in Go and TypeScript, as well as experience working with relational databases like Postgres. It's a unique opportunity to contribute to a product that's integral to the Supabase stack and work with a team that prioritizes developer experience.
Job Description
ABOUT SUPABASE Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth. ABOUT THE ROLE Auth https://supabase.com/auth, written in Go https://github.com/supabase/auth (server) and with client libraries for TypeScript https://github.com/supabase/auth-js, SSR https://github.com/supabase/ssr and for other frameworks and technologies, is one of the most popular products in the Supabase stack. We are seeking someone to help us build new and maintain existing Auth features. WHAT YOU’LL BE RESPONSIBLE FOR - Designing and implementing secure, scalable authentication features in Go and TypeScript.
- Working across the stack: from server-side protocols to client-side libraries for frameworks like Next.js.
- Owning the performance, reliability, and scalability of the Auth server across Supabase's infrastructure.
- Contributing to the evolution of our Auth architecture, including support for OAuth, OIDC, SAML, and other protocols.
- Planning and executing safe database migrations across a large fleet of Postgres instances.
- Building and improving observability: metrics, tracing, alerting, and dashboards to keep the system healthy at scale.
- Writing and reviewing RFCs as part of our product development process.
- Collaborating with engineers across Supabase to ensure a seamless experience for developers using our tools.
- Supporting the community and responding to developer feedback on GitHub, Discord, and other channels.
- (Required) Have 2+ years of professional experience working on an authentication system (implementing protocol support, maintenance at scale).
- (Required) Have strong relational database experience (Postgres or MySQL); Postgres experience is a bonus.
- Have strong knowledge of TypeScript in addition to Go (languages used daily).
- Have strong knowledge of web technology fundamentals (cookies, sessions, JWT, HTTP, browser APIs).
- Have good knowledge of and deep interest in authentication security (passwords, protocols such as OAuth, OIDC or SAML, cryptography fundamentals such as hash functions, signatures and ciphers).
- Have experience working with multiple web frameworks like Next.js (or other SSR alternative in the JavaScript space) and traditional web frameworks like Ruby on Rails, Django, Laravel or equivalent (in any language).
- Have good technical writing skills (RFC process is an important part of making changes to the Auth product).
- Have hands-on experience building and operating services at significant scale.
- Have deep understanding of systems-level concerns: memory management, concurrency patterns, and compute resource optimization in Go.
- Have experience with Kubernetes and AWS (or comparable cloud platform) in a production setting.
- Have solid grasp of observability practices — metrics, distributed tracing, structured logging, and alerting (e.g., Prometheus, Grafana, OpenTelemetry).
- Have experience managing database schema migrations safely at scale.
- ESOP Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
- Tech Allowance Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
- Health Benefits Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are.
- Annual Off-Sites Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
- Flexible Work We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
- Professional Development Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.
- ~400 team members - 60+ countries - 20+ languages spoken - Over $1B raised (including our $500M Series F) - 540,000+ community members We move fast, build in public, and use what we ship.
How to Stand Out
- Highlight your Go and TypeScript experience: Make sure your resume and cover letter showcase your proficiency in these programming languages.
- Prepare to talk about authentication protocols: Be ready to discuss your experience with OAuth, OIDC, SAML, and other authentication protocols.
- Showcase your understanding of web technology fundamentals: Highlight your knowledge of cookies, sessions, JWT, HTTP, and browser APIs.
- Demonstrate your ability to work across the stack: Be prepared to discuss your experience working on both server-side and client-side projects.
- Be ready to talk about your experience with relational databases: Highlight your experience working with Postgres or other relational databases.
- Showcase your technical writing skills: Be prepared to discuss your experience with technical writing, including writing and reviewing RFCs.
- Prepare to discuss your experience with observability practices: Be ready to discuss your experience with metrics, distributed tracing, structured logging, and alerting.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.