CareerPlanGet AI match score →

Product Security Engineer

🌐 Remote💼 Full-time🗓 2026-05-27 → 2026-07-31

Core

Strengthen security built into Supabase's products, platform, and engineering workflows by proactively reducing risk earlier in the development lifecycle.

Role type

Product Security Engineer

Builds

Developer tools and platform infrastructure for millions of users

Domain

Cloud-native, SaaS, and open-source developer tools

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

application security fundamentals, threat modeling, secure design review, vulnerability triage, security incident response, bug bounty program management, cloud-native security, API security, secrets handling, automation tooling

Preferred skills

Postgres, Kubernetes, building security guardrails

Responsibilities

Identify and close gaps across application security and vulnerability management; Conduct threat modeling, secure design reviews, and code reviews; Partner with engineering teams to shape a modern security program; Improve security posture through scalable mechanisms like tooling and automation; Support security incident response and triage; Manage bug bounty and vulnerability disclosure processes; Participate in security on-call rotations

Seniority

Mid-to-Senior, hands-on IC

Rewrite
## About the Role We’re looking for a Product Security Engineer to join our team and help strengthen how security is built into Supabase’s products, platform, and engineering workflows as we continue to scale. You’ll work closely with software engineers, infrastructure teams, and technical leadership, helping us proactively reduce risk earlier in the development lifecycle and ship securely by default. This role is ideal for someone who thrives in async, fast-paced environments and is excited about building developer tools that scale to millions. Success in this role means improving the security posture of the product without becoming a blocker to speed, autonomy, or builder velocity. ## Responsibilities In this role, you’ll: - Identify and close gaps across application security, secure design review, and vulnerability management. - Conduct threat modeling, secure design reviews, and code reviews to identify practical remediation paths. - Partner closely with engineering teams to provide product-focused security expertise and shape a modern security program. - Mature how we think about security in a developer-first environment, balancing pragmatism with strong technical judgment. - Distinguish between theoretical risk and material business risk to prioritize security efforts effectively. - Improve security posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails. - Support security incident response by helping triage, investigate, and coordinate remediation for product and platform security issues. - Participate in security on-call rotations, helping respond to urgent security events with clear judgment and calm execution. - Help manage and mature our bug bounty and vulnerability disclosure processes, including triage, validation, prioritization, and coordination with engineering teams. ## Requirements You Might Be a Good Fit If You: - Have strong experience in product security, application security, or security engineering. - Are comfortable working with cloud-native, developer tools, SaaS, platform, or infrastructure products. - Communicate clearly across both technical and non-technical audiences, especially in a written, asynchronous environment. - Are energized by solving real-world problems for developers and navigating ambiguity while moving quickly. - Possess a deep understanding of application security fundamentals, including auth, session management, APIs, and secrets handling. - Have experience with vulnerability triage, bug bounty programs, responsible disclosure, or security incident response. - Are comfortable participating in potential security on-call rotation and can balance urgency, risk, and practical remediation. - Have experience with or interest in Postgres, Kubernetes, or building security guardrails that enable rather than enforce. ## Benefits - Fully Remote - ESOP - Tech Allowance - Health Benefits - Annual Off-Sites - Flexible Work - Professional Development ## About the Team Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love. - 280+ team members - 55+ countries - 20+ languages spoken - $500M raised - 500,000+ community members We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities. ## Hiring Process We keep things simple, async-friendly, and respectful of your time: - Apply – Our team will review your application. - Intro Call – A short video chat to get to know each other. - Interviews – Up to four calls with: - Team Leads - Future teammates - Someone cross-functional from product, growth, or engineering (depending on the role) - Someone from our leadership/founding team - Decision – We may follow up with a final question or go straight to offer. All communication is remote and we aim to move fast.
Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Ashby ↗