Product Security Engineer
SupabaseAbout the role
Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.
Safeguarding that data is core to our mission. We’re hiring a Product Security Engineer to be secure our cloud platform, reviewing product security and working with teams to create innovative security solutions that set the industry standard. Ensuring every product at Supabase stays secure by default.
What You’ll Be Responsible for
Bridge and support security triage
Own HackerOne bug-bounty reports, product support tickets, and internal security requests.
Quickly assess severity and business impact, create actionable actions for resolution, and route them to the relevant product teams.
Work with product teams to validate security fixes and prevent regressions.
Work with Security Operations to respond to incoming threats and understand how they pertain to the Supabase product.
Assist product teams in keeping all product dependencies up to date.
Assist incident response & follow-through
Extension of the above bridging role between Security and Product
Work with Security Operations on investigation, remediation, and post-mortem activities for security events related to Supabase products.
Track SLAs, chase blockers, and close the loop with reporters - ensuring clear, timely communication throughout.
Manage and improve secure development and keep our security signals healthy
Help oversee, extend and maintain our secure development pipelines and training
Ensure code analysis systems and workflows remain effective, actionable, and low-noise.
Create and extend code scanning rules or new tools
Tune alert rules, improve duplicate/false-positive handling, and feed lessons learned back into detections and playbooks.
Maintain and refine runbooks, workflows, and metrics dashboards for continuous improvement.
Triage and follow up on code scanning alerts with Engineering and Infrastructure teams where needed.
Perform continuous in-house security reviews of products and new features.
Work with external pentesters
Manage compliance & assurance initiatives
Understand our compliance responsibilities, namely SOC 2 and HIPAA audits.
Partner with the Product, Security Engineering and Compliance teams to add meaningful compliance controls to our customer facing products.
Add customer value by ensuring products are secure and compliant by default, shifting burden from customers and improving our shared responsibility model.
Champion security culture
Create, review and contribute to product RFCs
Respond to ad-hoc security questions from engineers, sales, and support.
Contribute to internal training, FAQs, and knowledge-base articles to raise the overall security IQ of the company.
You Might Be a Good Fit If You
Experienced in product security: 5+ years in a Product Security team, preferably for a cloud-native product company.
Tool-savvy: Comfortable with bug-bounty platforms (HackerOne, Bugcrowd), compliance tooling (Vanta, Drata), ticketing/CRM systems (HubSpot, Jira), Burpsuite and Code analysis tooling (Snyk, CodeQL, Semgrep).
Process-oriented & relentless at follow-up: You enjoy turning chaos into checklists, measuring progress, and nudging tasks over the finish line.
Clear and empathetic communicator: Able to translate security jargon into developer-friendly action items and customer-friendly updates.
Familiar with common frameworks: Working knowledge of SOC 2, HIPAA, ISO 27001, or related standards.
Comfortable in an async-first, globally distributed team: You write things down, default to transparency, and can triage effectively across time zones.
What We Offer
Fully Remote
We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
ESOP
Every team member receives ESOP (equity ownership) in the company. We want everyone t
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s