• Join Supabase, the Postgres development platform trusted by more than 7 million developers, in a full-time fully remote role.
• Balance the constant tension between security and developer experience at platform scale.
• Lead the platform security roadmap, from defaults for first-time developers to controls a Fortune 500 CISO needs.
• Lead the security strategy for AI agents acting on behalf of developers and companies.
• Partner with Security Engineering, Compliance and the platform teams that own auth, networking and audit.
• Work asynchronously from anywhere in the EMEA or AMER time zones.
📋 Job Requirements
• Bring 7+ years in product management, with serious time on security, identity and access, infrastructure or developer platform products.
• Show experience at a company where security mattered to enterprise buyers.
• Bring deep working knowledge of authentication, authorization (RBAC, RLS), audit logging, secrets management and OAuth.
• Show a track record leading cross-functional initiatives across Product, Engineering, Security, GTM and Compliance.
• Drive multi-team RFCs from proposal through to shipped code.
• Work comfortably in a remote, async, write-it-down culture.
• Write exceptionally well, from customer-facing security disclosures to threat models and CISO one-pagers.
• Be based in an EMEA or AMER time zone.
🌟 Nice-to-have
• Bring compliance fluency from working alongside auditors on SOC 2, HIPAA, ISO 27001, PCI or FedRAMP.
• Tell the difference between real customer needs and checkbox compliance theatre.
• Bring technical depth in Postgres, auth systems or networking primitives.
• Show experience designing access models for AI agents or other automated systems.
• Bring experience shipping security features that enterprise CISOs had to approve.
🎯 Responsibilities
• Lead the platform security roadmap end to end.
• Balance protection against friction so controls neither push developers away nor fail to protect them.
• Define how Supabase authenticates, scopes and audits AI agent activity.
• Own the security product surface, including firewall, security advisors, audit logs, Supabase Vault and just-in-time database access.
• Set the strategy tying together roles, permissions, access tokens, OAuth integrations, SSO and SCIM.
• Drive cross-cutting RFCs from proposal to shipped code.
• Define what comes next on the compliance roadmap beyond SOC 2 and HIPAA.
• Talk to enterprise prospects and their security teams, and turn what you hear into roadmap.
• Make the security guides on supabase.com the best in the category.
About Supabase
😃 What Supabase offers
• Work fully remotely from anywhere, with a WeWork membership or co-working allowance.
• Receive equity ownership through the ESOP.
• Use a tech allowance to set up your ideal work environment.
• Get 100% health insurance cover for employees and 80% for dependents.
• Join annual company off-sites in a new city each year.
• Manage your own time in an asynchronous, flexible working culture.
• Use an annual education allowance on courses, books or conferences.
💖 What makes Supabase unique
Supabase is the Postgres development platform built by developers for developers, trusted with the data of more than 7 million developers. The company was born remote and open-source-first, with around 400 team members across more than 60 countries. It has raised over $1B, including a $500M Series F, and runs a compliance programme covering SOC 2 and HIPAA.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.