All remote jobs
Open role
Remote opportunity atSupabase

Product Manager – Security & Trust (EMEA/AMER)

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
22Listing views
1Application actions
25 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

Supabase is hiring a senior Product Manager to own the strategy and roadmap for platform security and trust capabilities. The role covers identity and access management, authentication and authorization, audit logging, secrets management, security tooling, AI-agent controls, and compliance readiness. This PM will partner closely with Security Engineering, Compliance, platform engineering, GTM, and enterprise customers to balance strong controls with a low-friction developer experience. The position is fully remote for candidates across EMEA and AMER time zones and requires strong async writing, cross-functional leadership, and enterprise security product expertise.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a high-seniority, technically demanding product role spanning security architecture, regulated-enterprise requirements, developer experience, and AI-agent access controls. Success depends on independently aligning multiple technical and commercial stakeholders while making consequential platform-wide tradeoffs.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$190,000
US market range$160k–$225k
AI insightNo actual salary was disclosed, so these are estimated US-market annual base-salary figures in USD for a senior Product Manager specializing in platform security, identity, and enterprise infrastructure. Equity, benefits, location-based pay practices, and any bonus or variable compensation could materially change total compensation.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you prioritize security improvements that add friction for developers but are required by enterprise customers?

I would first define the threat, customer segment, regulatory driver, and measurable reduction in risk. I would favor secure-by-default controls with progressive disclosure, allowing advanced customers to apply stricter policies without burdening early-stage developers. I would validate the tradeoff through customer research, telemetry, and a clear adoption plan.

Describe how you would develop a unified access model across roles, permissions, personal access tokens, OAuth, SSO, and SCIM.

I would begin with a shared authorization model and clear resource hierarchy for organizations, projects, environments, and data. I would document key personas, delegation paths, token lifecycles, and audit requirements, then align engineering teams through an RFC process. The roadmap would sequence foundational primitives first and ensure every access path is consistently enforceable and observable.

What security considerations are most important when designing permissions for AI agents?

Agents should receive narrowly scoped, short-lived, revocable credentials rather than broad standing access. I would prioritize explicit consent, policy-based authorization, strong attribution, immutable audit trails, rate limits, and safeguards for high-impact actions. The product should also make it easy for customers to understand, monitor, and interrupt an agent's activity.

How would you turn enterprise security feedback into a product roadmap rather than a collection of one-off requests?

I would categorize feedback by underlying capability gaps, affected customer segments, revenue or retention impact, compliance relevance, and security risk. I would look for reusable platform primitives that solve repeated needs, such as policy controls, audit APIs, or identity integrations. I would communicate what is productized, what is configuration or documentation work, and what does not align with the platform strategy.

How do you drive alignment when Security, Engineering, Compliance, and GTM disagree on a roadmap decision?

I create a shared decision document that makes the customer problem, risk posture, constraints, options, and tradeoffs explicit. I use evidence from threat modeling, customer demand, implementation cost, and compliance obligations to frame the decision. Once a decision owner is clear, I document the outcome, milestones, and unresolved risks so teams can execute with accountability.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Supabase is the Postgres development platform, built by developers for developers to help them ship countless products that people love. More than 7 million developers trust us with their data, and we are custodians of every byte of it. Security is foundational to that trust, and as we move deeper into AI-native development, regulated industries, and enterprise, it shapes whether a developer chooses us on day one and whether a regulated company can build their most sensitive workloads on Supabase.

About the role

We’re looking for a PM who can balance the constant tension between security and developer experience at platform scale. Every control you add is friction a developer has to absorb, and every default you loosen is a door an attacker could walk through. Finding the right balance between protecting customers and keeping them fast is the work of this role.

You’ll partner with Security Engineering, Compliance, and the platform teams that own auth, networking, and audit.

This is a remote position and we’re open to considering candidates located across EMEA and AMER time zones.

In This Role You Will

  • Set the security agenda for the platform. Lead Supabase’s platform security roadmap end-to-end, from the defaults that protect a developer prototyping their first project to the advanced controls a Fortune 500 CISO needs before approving us.

  • Hold the line between security and developer experience. Every security feature trades protection against friction. A control that’s too strict pushes developers off the platform; one that’s too easy to bypass doesn’t protect anyone.

  • Lead our security strategy for AI agents. Agents now read, write, and deploy on behalf of developers and companies, often at machine speed. You’ll lead how Supabase authenticates, scopes, and audits agent activity so customers can give them real capability while staying in control of their data.

  • Own our security product surface. Drive the roadmap for the security tooling customers use to operate safely on Supabase: firewall, security advisors, audit logs, Supabase Vault, just-in-time database access, and the IAM primitives that let regulated customers get to “yes” with their security team.

  • Define the unified access model across Supabase. Roles, permissions, personal access tokens, OAuth integrations, organization and project modeling, SSO, and SCIM are foundational to how customers manage who can do what. You’ll set the strategy that ties them together and drive the cross-cutting RFCs from proposal to shipped code.

  • Drive the compliance roadmap. Supabase already runs a strong compliance program with SOC2 and HIPAA in place. Your job is to define what comes next so more regulated companies can adopt us.

  • Be the customer’s voice for security. Talk to enterprise prospects, regulated customers, and the security teams behind them. Translate what you hear into a roadmap that earns trust at every customer size, from the indie hacker prototyping their first project to the Fortune 500 CISO evaluating us for their most regulated workloads.

  • Ship the docs that go with the code. Make the security guides on supabase.com the best in the category: clear, opinionated, and trustworthy enough that a developer evaluating us comes away convinced.

You Might Be a Good Fit If You

  • Have 7+ years in product management, with serious time on security, identity and access, infrastructure, or developer platform products at a company where security mattered to enterprise buyers.

  • Have deep working knowledge of the security primitives our customers use like authentication, authorization (RBAC, RLS), audit logging, secrets management, OAuth.

  • Have a track record of leading cross-functional initiatives across Product, Engineering, Security, GTM, and Compliance, and driving multi-team RFCs from proposal to shipped code.

  • Are 100% comfortable in a remote, async, write-it-down culture.

  • Are an exceptional writer. You can draft a customer-facing security disclosure, an internal threat model, a docs page, or a one-pager for a CISO without losing voice or precision.

Nice to have

  • Compliance fluency. You’ve worked alongside auditors and security teams on programs like SOC2, HIPAA, ISO 27001, PCI, or FedRAMP, and you can tell which requirements are real customer needs and which are checkbox theater.

  • Technical depth in Postgres, auth systems, or networking primitives.

  • Experience designing access models for AI agents or other automated systems.

  • Shipped security features that enterprise CISOs had to approve before adoption.

What We Offer

  • Fully Remote

    We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.

  • ESOP

    Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.

  • Tech Allowance

    Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.

  • Health Benefits

    Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.

  • Annual Off-Sites

    Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.

  • Flexible Work

    We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.

  • Professional Development

    Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.

About the Team

Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.

  • ~400 team members

  • 60+ countries

  • 20+ languages spoken

  • Over $1B raised (including our $500M Series F)

  • 540,000+ community members

We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu