• Join the Security team to strengthen how security is built into Supabase's products, platform, and engineering workflows as the company continues to scale.
• Proactively reduce risk earlier in the development lifecycle and help Supabase ship securely by default without becoming a blocker to speed, autonomy, or builder velocity.
• Work closely with software engineers, infrastructure teams, and technical leadership in an async, fast-paced environment building developer tools that scale to millions.
📋 Job Requirements
• Have strong experience in product security, application security, or security engineering.
• Be comfortable working with cloud-native, developer tools, SaaS, platform, or infrastructure products.
• Communicate clearly across both technical and non-technical audiences, especially in a written, asynchronous environment.
• Be energised by solving real-world problems for developers and navigating ambiguity while moving quickly.
• Possess a deep understanding of application security fundamentals including auth, session management, APIs, and secrets handling.
• Have experience with vulnerability triage, bug bounty programmes, responsible disclosure, or security incident response.
• Be comfortable participating in a potential security on-call rotation and be able to balance urgency, risk, and practical remediation.
🌟 Nice-to-have
• Have experience with or interest in Postgres, Kubernetes, or building security guardrails that enable rather than enforce.
• Bring experience conducting threat modelling and secure design reviews for developer-facing platforms.
• Have experience improving security posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails.
• Have experience managing and maturing bug bounty and vulnerability disclosure processes including triage, validation, and coordination with engineering teams.
🎯 Responsibilities
• Identify and close gaps across application security, secure design review, and vulnerability management.
• Conduct threat modelling, secure design reviews, and code reviews to identify practical remediation paths.
• Partner closely with engineering teams to provide product-focused security expertise and shape a modern security programme.
• Mature how Supabase thinks about security in a developer-first environment, balancing pragmatism with strong technical judgement.
• Distinguish between theoretical risk and material business risk to prioritise security efforts effectively.
• Improve security posture through scalable mechanisms like tooling, automation, secure defaults, and developer-friendly guardrails.
• Support security incident response by helping triage, investigate, and coordinate remediation for product and platform security issues.
• Participate in security on-call rotations, helping respond to urgent security events with clear judgement and calm execution.
• Help manage and mature the bug bounty and vulnerability disclosure processes including triage, validation, prioritisation, and coordination with engineering teams.
About Supabase
😃 What Supabase offers
• Work fully remotely from anywhere in the world.
• Receive ESOP equity ownership in the company.
• Get a tech allowance to set up your ideal work environment.
• Receive 100% employer-covered health insurance with 80% coverage for dependents.
• Attend annual company off-sites in a new city each year.
• Work flexibly and asynchronously with full trust to manage your own time.
• Receive a professional development allowance for courses, books, conferences, and learning.
• Access a WeWork membership or co-working allowance usable anywhere in the world.
💖 What makes Supabase unique
Supabase is the open-source Postgres development platform that 7M+ developers and thousands of enterprises depend on every day. Providing a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search, Supabase is born-remote and open-source-first with around 400 team members across 60+ countries. The company has raised over $1B including a $500M Series F.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.