Product Manager - Security & Trust (EMEA/AMER)
WFA Digital Insight
Supabase is seeking a Product Manager to oversee Security and Trust, a role that stands out for its focus on balancing security measures with developer experience. This position requires a deep understanding of security primitives and the ability to drive cross-functional initiatives. What makes this role unique is the need to set the security agenda for the platform, defining the unified access model and driving the compliance roadmap. Candidates should be prepared to navigate the tension between security and developer experience, with a keen eye on protecting customers while keeping them fast.
Job Description
Supabase is the Postgres development platform, built by developers for developers to help them ship countless products that people love. More than 7 million developers trust us with their data, and we are custodians of every byte of it. Security is foundational to that trust, and as we move deeper into AI-native development, regulated industries, and enterprise, it shapes whether a developer chooses us on day one and whether a regulated company can build their most sensitive workloads on Supabase. ABOUT THE ROLE We're looking for a PM who can balance the constant tension between security and developer experience at platform scale. Every control you add is friction a developer has to absorb, and every default you loosen is a door an attacker could walk through. Finding the right balance between protecting customers and keeping them fast is the work of this role. You'll partner with Security Engineering, Compliance, and the platform teams that own auth, networking, and audit. This is a remote position and we're open to considering candidates located across EMEA and AMER time zones. IN THIS ROLE YOU WILL - Set the security agenda for the platform. Lead Supabase's platform security roadmap end-to-end, from the defaults that protect a developer prototyping their first project to the advanced controls a Fortune 500 CISO needs before approving us.
- Hold the line between security and developer experience.
- Lead our security strategy for AI agents. Agents now read, write, and deploy on behalf of developers and companies, often at machine speed. You'll lead how Supabase authenticates, scopes, and audits agent activity so customers can give them real capability while staying in control of their data.
- Own our security product surface.
- Define the unified access model across Supabase. Roles, permissions, personal access tokens, OAuth integrations, organization and project modeling, SSO, and SCIM are foundational to how customers manage who can do what.
- Drive the compliance roadmap. Supabase already runs a strong compliance program with SOC2 and HIPAA in place. Your job is to define what comes next so more regulated companies can adopt us.
- Be the customer's voice for security.
- Ship the docs that go with the code.
- Have deep working knowledge of the security primitives our customers use like authentication, authorization (RBAC, RLS), audit logging, secrets management, OAuth.
- Have a track record of leading cross-functional initiatives across Product, Engineering, Security, GTM, and Compliance, and driving multi-team RFCs from proposal to shipped code.
- Are 100% comfortable in a remote, async, write-it-down culture.
- Are an exceptional writer.
- Technical depth in Postgres, auth systems, or networking primitives.
- Experience designing access models for AI agents or other automated systems.
- Shipped security features that enterprise CISOs had to approve before adoption.
- ESOP Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
- Tech Allowance Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
- Health Benefits Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are.
- Annual Off-Sites Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
- Flexible Work We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
- Professional Development Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.
- ~400 team members - 60+ countries - 20+ languages spoken - Over $1B raised (including our $500M Series F) - 540,000+ community members We move fast, build in public, and use what we ship.
How to Stand Out
- Highlight your experience with security primitives, including authentication, authorization, and audit logging, in your resume and cover letter.
- Develop a portfolio that showcases your ability to drive cross-functional initiatives and lead multi-team efforts.
- Prepare to discuss your approach to balancing security measures with developer experience, and how you would navigate the tensions between these two competing demands.
- Research Supabase and its platform to understand the security challenges and opportunities it presents, and be prepared to ask informed questions during the interview process.
- Emphasize your writing skills, as the ability to produce high-quality documentation is essential for this role.
- Be prepared to discuss your experience with compliance initiatives and your understanding of regulatory frameworks such as SOC2 and HIPAA.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.