Author
This is some text inside of a div block.
Last Updated
This is some text inside of a div block.
Editorial Transparency
This is some text inside of a div block.

Product Security Engineer

About the Role

We’re looking for a Product Security Engineer to join our team and help strengthen how security is built into Supabase’s products, platform, and engineering workflows as we continue to scale. You’ll work closely with software engineers, infrastructure teams, and technical leadership , helping us proactively reduce risk earlier in the development lifecycle and ship securely by default.

This role is ideal for someone who thrives in async, fast-paced environments and is excited about building developer tools that scale to millions. Success in this role means improving the security posture of the product without becoming a blocker to speed, autonomy, or builder velocity.

What You’ll Be Responsible for

In this role, you’ll:

  • Identifyand close gaps across application security, secure design review, and vulnerability management.
  • Conductthreat modeling, secure design reviews, and code reviews to identify practical remediation paths.
  • Partnerclosely with engineering teams to provide product-focused security expertise and shape a modern security program.
  • Maturehow we think about security in a developer-first environment, balancing pragmatism with strong technical judgment.
  • Distinguishbetween theoretical risk and material business risk to prioritize security efforts effectively.
  • Improvesecurity posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails.
  • Supportsecurity incident response by helping triage, investigate, and coordinate remediation for product and platform security issues.
  • Participatein security on-call rotations, helping respond to urgent security events with clear judgment and calm execution.
  • Help manage and matureour bug bounty and vulnerability disclosure processes, including triage, validation, prioritization, and coordination with engineering teams.

You Might Be a Good Fit If You

  • Havestrong experiencein product security, application security, or security engineering.
  • Are comfortable working withcloud-native, developer tools, SaaS, platform, or infrastructure products.
  • Communicate clearly across both technical and non-technical audiences, especially in awritten, asynchronous environment.
  • Are energized bysolving real-world problems for developersand navigating ambiguity while moving quickly.
  • Possess a deep understanding of application security fundamentals, includingauth, session management, APIs, and secrets handling.
  • Have experience with vulnerability triage,bug bounty programs, responsible disclosure, or security incident response.
  • Are comfortable participating in potentialsecurity on-call rotationand can balance urgency, risk, and practical remediation.
  • Have experience with or interest inPostgres, Kubernetes, or building security guardrailsthat enable rather than enforce.

What We Offer

  • Fully Remote We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
  • ESOP Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
  • Tech Allowance Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
  • Health Benefits Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.
  • Annual Off-Sites Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
  • Flexible Work We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
  • Professional Development Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.

About the Team

Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.

  • 280+ team members
  • 55+ countries
  • 20+ languages spoken
  • $500M raised
  • 500,000+ community members

We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.

Hiring Process

We keep things simple, async-friendly, and respectful of your time:

  1. Apply – Our team will review your application.
  2. Intro Call – A short video chat to get to know each other.
  3. Interviews – Up to four calls with: Team LeadsFuture teammatesSomeone cross-functional from product, growth, or engineering (depending on the role)Someone from our leadership/founding team
  • Team Leads
  • Future teammates
  • Someone cross-functional from product, growth, or engineering (depending on the role)
  • Someone from our leadership/founding team
  1. Decision – We may follow up with a final question or go straight to offer.

All communication is remote and we aim to move fast.

About Supabase

Supabase is the Postgres development platform, offering a suite of tools to build applications quickly and efficiently.
Create an account to apply