Volver al tablero de empleos

Confidencial

Remote

Product Security Engineer

RemotoMidFull-time

Publicado 27 de mayo de 2026

Oferta externa

Esta vacante proviene de una fuente externa. La descripción puede estar abreviada y algunos datos (salario, habilidades) pueden no estar disponibles. Regístrate como candidato para recibir la información completa.

Descripción del puesto

<h2>About the Role</h2><p style="min-height:1.5em">We’re looking for a <strong>Product Security Engineer</strong> to join our team and help strengthen how security is built into Supabase’s products, platform, and engineering workflows as we continue to scale. You’ll work closely with <strong>software engineers, infrastructure teams, and technical leadership</strong>, helping us proactively reduce risk earlier in the development lifecycle and ship securely by default.</p><p style="min-height:1.5em">This role is ideal for someone who thrives in async, fast-paced environments and is excited about building developer tools that scale to millions. Success in this role means improving the security posture of the product without becoming a blocker to speed, autonomy, or builder velocity.</p><p style="min-height:1.5em"></p><h2>What You’ll Be Responsible for</h2><p style="min-height:1.5em">In this role, you’ll:</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Identify</strong> and close gaps across application security, secure design review, and vulnerability management.</p></li><li><p style="min-height:1.5em"><strong>Conduct</strong> threat modeling, secure design reviews, and code reviews to identify practical remediation paths.</p></li><li><p style="min-height:1.5em"><strong>Partner</strong> closely with engineering teams to provide product-focused security expertise and shape a modern security program.</p></li><li><p style="min-height:1.5em"><strong>Mature</strong> how we think about security in a developer-first environment, balancing pragmatism with strong technical judgment.</p></li><li><p style="min-height:1.5em"><strong>Distinguish</strong> between theoretical risk and material business risk to prioritize security efforts effectively.</p></li><li><p style="min-height:1.5em"><strong>Improve</strong> security posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails.</p></li><li><p style="min-height:1.5em"><strong>Support</strong> security incident response by helping triage, investigate, and coordinate remediation for product and platform security issues.</p></li><li><p style="min-height:1.5em"><strong>Participate</strong> in security on-call rotations, helping respond to urgent security events with clear judgment and calm execution.</p></li><li><p style="min-height:1.5em"><strong>Help manage and mature</strong> our bug bounty and vulnerability disclosure processes, including triage, validation, prioritization, and coordination with engineering teams.</p></li></ul><h2>You Might Be a Good Fit If You</h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Have <strong>strong experience</strong> in product security, application security, or security engineering.</p></li><li><p style="min-height:1.5em">Are comfortable working with <strong>cloud-native, developer tools, SaaS, platform, or infrastructure products</strong>.</p></li><li><p style="min-height:1.5em">Communicate clearly across both technical and non-technical audiences, especially in a <strong>written, asynchronous environment</strong>.</p></li><li><p style="min-height:1.5em">Are energized by <strong>solving real-world problems for developers</strong> and navigating ambiguity while moving quickly.</p></li><li><p style="min-height:1.5em">Possess a deep understanding of application security fundamentals, including <strong>auth, session management, APIs, and secrets handling</strong>.</p></li><li><p style="min-height:1.5em">Have experience with vulnerability triage, <strong>bug bounty programs</strong>, responsible disclosure, or security incident response.</p></li><li><p style="min-height:1.5em">Are comfortable participating in potential <strong>security on-call rotation</strong> and can balance urgency, risk, and practical remediation.</p></li><li><p style="min-height:1.5em">Have experience with or interest in <strong>Postgres, Kubernetes, or building security guardrails</strong> that enable rather than enforce.</p></li></ul><h3><strong>What We Offer</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Fully Remote</strong></p><p style="min-height:1.5em">We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.</p></li><li><p style="min-height:1.5em"><strong>ESOP</strong></p><p style="min-height:1.5em">Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.</p></li><li><p style="min-height:1.5em"><strong>Tech Allowance</strong></p><p style="min-height:1.5em">Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.</p></li><li><p style="min-height:1.5em"><strong>Health Benefits</strong></p><p style="min-height:1.5em">Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.</p></li><li><p style="min-height:1.5em"><strong>Annual Off-Sites</strong></p><p style="min-height:1.5em">Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.</p></li><li><p style="min-height:1.5em"><strong>Flexible Work</strong></p><p style="min-height:1.5em">We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.</p></li><li><p style="min-height:1.5em"><strong>Professional Development</strong></p><p style="min-height:1.5em">Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.</p><p style="min-height:1.5em"></p></li></ul><h3><strong>About the Team</strong></h3><p style="min-height:1.5em">Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">280+ team members</p></li><li><p style="min-height:1.5em">55+ countries</p></li><li><p style="min-height:1.5em">20+ languages spoken</p></li><li><p style="min-height:1.5em">$500M raised</p></li><li><p style="min-height:1.5em">500,000+ community members</p></li></ul><p style="min-height:1.5em">We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.</p><p style="min-height:1.5em"></p><h3><strong>Hiring Process</strong></h3><p style="min-height:1.5em">We keep things simple, async-friendly, and respectful of your time:</p><ol style="min-height:1.5em"><li><p style="min-height:1.5em">Apply – Our team will review your application.</p></li><li><p style="min-height:1.5em">Intro Call – A short video chat to get to know each other.</p></li><li><p style="min-height:1.5em">Interviews – Up to four calls with:</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Team Leads</p></li><li><p style="min-height:1.5em">Future teammates</p></li><li><p style="min-height:1.5em">Someone cross-functional from product, growth, or engineering (depending on the role)</p></li><li><p style="min-height:1.5em">Someone from our leadership/founding team</p></li></ul></li><li><p style="min-height:1.5em">Decision – We may follow up with a final question or go straight to offer.</p></li></ol><p style="min-height:1.5em">All communication is remote and we aim to move fast.</p>