Product Security Engineer

Supabase Supabase · Data AI · Remote · Security

Product Security Engineer at Supabase, a developer tools company. This role focuses on integrating security into the product development lifecycle, working with engineering and infrastructure teams to reduce risk and ship securely. Responsibilities include threat modeling, secure design reviews, vulnerability management, and improving security posture through automation and guardrails. The role emphasizes a developer-first approach, balancing security with speed and autonomy.

What you'd actually do

  1. Identify and close gaps across application security, secure design review, and vulnerability management.
  2. Conduct threat modeling, secure design reviews, and code reviews to identify practical remediation paths.
  3. Partner closely with engineering teams to provide product-focused security expertise and shape a modern security program.
  4. Mature how we think about security in a developer-first environment, balancing pragmatism with strong technical judgment.
  5. Distinguish between theoretical risk and material business risk to prioritize security efforts effectively.

Skills

Required

  • Product security
  • Application security
  • Security engineering
  • Threat modeling
  • Secure design review
  • Vulnerability management
  • Code review
  • Security incident response
  • Bug bounty program management
  • Responsible disclosure
  • Auth
  • Session management
  • APIs
  • Secrets handling

Nice to have

  • Cloud-native
  • Developer tools
  • SaaS
  • Platform
  • Infrastructure products
  • Asynchronous communication
  • Postgres
  • Kubernetes
  • Security guardrails

What the JD emphasized

  • strong experience in product security, application security, or security engineering
  • cloud-native, developer tools, SaaS, platform, or infrastructure products
  • written, asynchronous environment
  • solving real-world problems for developers
  • auth, session management, APIs, and secrets handling
  • bug bounty programs
  • security on-call rotation
  • Postgres, Kubernetes, or building security guardrails