Jobs / Other locations / Supabase
Product Manager - Security & Trust (EMEA/AMER)
Supabase · 🌍 Remote, Global; Remote, EMEA; Remote, AMER · Remote
Sponsorship verdict
No sponsorship evidence yet
No government record and no wording either way. Not a refusal — ask the recruiter.
- No government sponsor record hereThis employer posted directly and does not match a government sponsor register.
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- Can’t check pay against the visa rulesWe don’t have visa salary rules for this country yet.
- Confirmed live todayWhen a source last listed this job as open.
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Why not apply?
No register record and no sponsorship wording in the posting. Worth asking the employer before investing significant time.
SponsorApply flags time-wasters so your applications go where they can land. These come from the posting's own wording — read the original listing to confirm. See better-fit alternatives →
Sponsor Radar — Supabase
This employer posted directly and does not match a government sponsor register.
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Supabase →
About the role
Supabase is the Postgres development platform, built by developers for developers to help them ship countless products that people love. More than 7 million developers trust us with their data, and we are custodians of every byte of it. Security is foundational to that trust, and as we move deeper into AI-native development, regulated industries, and enterprise, it shapes whether a developer chooses us on day one and whether a regulated company can build their most sensitive workloads on Supabase. ABOUT THE ROLE We're looking for a PM who can balance the constant tension between security and developer experience at platform scale. Every control you add is friction a developer has to absorb, and every default you loosen is a door an attacker could walk through. Finding the right balance between protecting customers and keeping them fast is the work of this role. You'll partner with Security Engineering, Compliance, and the platform teams that own auth, networking, and audit. This is a remote position and we're open to considering candidates located across EMEA and AMER time zones. IN THIS ROLE YOU WILL - Set the security agenda for the platform. Lead Supabase's platform security roadmap end-to-end, from the defaults that protect a developer prototyping their first project to the advanced controls a Fortune 500 CISO needs before approving us. - Hold the line between security and developer experience. Every security feature trades protection against friction. A control that's too strict pushes developers off the platform; one that's too easy to bypass doesn't protect anyone. - Lead our security strategy for AI agents. Agents now read, write, and deploy on behalf of developers and companies, often at machine speed. You'll lead how Supabase authenticates, scopes, and audits agent activity so customers can give them real capability while staying in control of their data. - Own our security product surface. Drive the roadmap for the security tooling customers use to operate safely on Supabase: firewall, security advisors, audit logs, Supabase Vault, just-in-time database access, and the IAM primitives that let regulated customers get to "yes" with their security team. - Define the unified access model across Supabase. Roles, permissions, personal access tokens, OAuth integrations, organization and project modeling, SSO, and SCIM are foundational to how customers manage who can do what. You'll set the strategy that ties them together and drive the cross-cutting RFCs from proposal to shipped code. - Drive the compliance roadmap. Supabase already runs a strong compliance program with SOC2 and HIPAA in place. Your job is to define what comes next so more regulated companies can adopt us. - Be the customer's voice for security. Talk to enterprise prospects, regulated customers, and the security teams behind them. Translate what you hear into a roadmap that earns trust at every customer size, from the indie hacker prototyping their first project to the Fortune 500 CISO evaluating us for their most regulated workloads. - Ship the docs that go with the code. Make the security guides https://supabase.com/docs/guides/security on supabase.com http://supabase.com the best in the category: clear, opinionated, and trustworthy enough that a developer evaluating us comes away convinced. YOU MIGHT BE A GOOD FIT IF YOU - Have 7+ years in product management, with serious time on security, identity and access, infrastructure, or developer platform products at a company where security mattered to enterprise buyers. - Have deep working knowledge of the security primitives our customers use like authentication, authorization (RBAC, RLS), audit logging, secrets management, OAuth. - Have a track record of leading cross-func