产品经理 - 安全与信任(EMEA/AMER)
Product Manager - Security & Trust (EMEA/AMER)
Supabase 是基于 Postgres 的开发平台,由开发者为开发者打造,帮助他们交付无数受人喜爱的产品。超过 700 万开发者将他们的数据交给我们,我们是每字节数据的保管者。安全是这种信任的基础,随着我们深入 AI 原生开发、监管行业和企业市场,这决定了开发者是否在第一天就选择我们,也决定了监管公司能否在 Supabase 上构建最敏感的工作负载。
关于该职位
我们正在寻找一位产品经理,能够在平台规模下平衡安全与开发者体验之间的持续紧张关系。你添加的每个控制措施都会给开发者带来摩擦,而你放宽的每个默认设置都可能成为攻击者进入的途径。找到保护客户与保持速度之间的正确平衡,就是这个职位的工作。
你将与安全工程、合规以及负责认证、网络和审计的平台团队合作。
这是一个远程职位,我们考虑来自 EMEA 和 AMER 时区的候选人。
在这个职位中,你将:
- 设定平台的安全议程。从保护开发者原型开发第一个项目的默认设置,到财富 500 强 CISO 在批准我们之前需要的高级控制,全程领导 Supabase 平台安全路线图。
- 在安全与开发者体验之间守住底线。每个安全功能都在保护与摩擦之间进行权衡。一个控制过于严格会把开发者推离平台;一个容易绕过的控制则无法保护任何人。
- 领导我们的 AI 代理安全策略。代理现在可以代表开发者和公司读取、写入和部署,通常以机器速度进行。你将领导 Supabase 如何对代理活动进行身份验证、作用域划分和审计,使客户能够赋予它们真正的能力,同时保持对其数据的控制。
- 主导我们的安全产品范围。推动客户在 Supabase 上安全运营所使用的安全工具路线图:防火墙、安全顾问、审计日志、Supabase Vault、即时数据库访问,以及让监管客户能与安全团队达成“同意”的 IAM 基础设施。
- 定义 Supabase 中统一的访问模型。角色、权限、个人访问令牌、OAuth 集成、组织和项目建模、SSO 和 SCIM 是客户管理谁可以做什么的基础。你将制定将它们联系在一起的战略,并推动其发展。
查看英文原文
Supabase is the Postgres development platform, built by developers for developers to help them ship countless products that people love. More than 7 million developers trust us with their data, and we are custodians of every byte of it. Security is foundational to that trust, and as we move deeper into AI-native development, regulated industries, and enterprise, it shapes whether a developer chooses us on day one and whether a regulated company can build their most sensitive workloads on Supabase.
ABOUT THE ROLE
We're looking for a PM who can balance the constant tension between security and developer experience at platform scale. Every control you add is friction a developer has to absorb, and every default you loosen is a door an attacker could walk through. Finding the right balance between protecting customers and keeping them fast is the work of this role.
You'll partner with Security Engineering, Compliance, and the platform teams that own auth, networking, and audit.
This is a remote position and we're open to considering candidates located across EMEA and AMER time zones.
IN THIS ROLE YOU WILL
- Set the security agenda for the platform. Lead Supabase's platform security roadmap end-to-end, from the defaults that protect a developer prototyping their first project to the advanced controls a Fortune 500 CISO needs before approving us.
- Hold the line between security and developer experience. Every security feature trades protection against friction. A control that's too strict pushes developers off the platform; one that's too easy to bypass doesn't protect anyone.
- Lead our security strategy for AI agents. Agents now read, write, and deploy on behalf of developers and companies, often at machine speed. You'll lead how Supabase authenticates, scopes, and audits agent activity so customers can give them real capability while staying in control of their data.
- Own our security product surface. Drive the roadmap for the security tooling customers use to operate safely on Supabase: firewall, security advisors, audit logs, Supabase Vault, just-in-time database access, and the IAM primitives that let regulated customers get to "yes" with their security team.
- Define the unified access model across Supabase. Roles, permissions, personal access tokens, OAuth integrations, organization and project modeling, SSO, and SCIM are foundational to how customers manage who can do what. You'll set the strategy that ties them together and drive the cross-cutting RFCs from proposal to shipped code.
- Drive the compliance roadmap. Supabase already runs a strong compliance program with SOC2 and HIPAA in place. Your job is to define what comes next so more regulated companies can adopt us.
- Be the customer's voice for security. Talk to enterprise prospects, regulated customers, and the security teams behind them. Translate what you hear into a roadmap that earns trust at every customer size, from the indie hacker prototyping their first project to the Fortune 500 CISO evaluating us for their most regulated workloads.
- Ship the docs that go with the code. Make the security guides https://supabase.com/docs/guides/security on supabase.com http://supabase.com the best in the category: clear, opinionated, and trustworthy enough that a developer evaluating us comes away convinced.
YOU MIGHT BE A GOOD FIT IF YOU
- Have 7+ years in product management, with serious time on security, identity and access, infrastructure, or developer platform products at a company where security mattered to enterprise buyers.
- Have deep working knowledge of the security primitives our customers use like authentication, authorization (RBAC, RLS), audit logging, secrets management, OAuth.
- Have a track record of leading cross-functional initiatives across Product, Engineering, Security, GTM, and Compliance, and driving multi-team RFCs from proposal to shipped code.
- Are 100% comfortable in a remote, async, write-it-down culture.
- Are an exceptional writer. You can draft a customer-facing security disclosure, an internal threat model, a docs page, or a one-pager for a CISO without losing voice or precision.
NICE TO HAVE
- Compliance fluency. You've worked alongside auditors and security teams on programs like SOC2, HIPAA, ISO 27001, PCI, or FedRAMP, and you can tell which requirements are real customer needs and which are checkbox theater.
- Technical depth in Postgres, auth systems, or networking primitives.
- Experience designing access models for AI agents or other automated systems.
- Shipped security features that enterprise CISOs had to approve before adoption.
WHAT WE OFFER
- Fully Remote
We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
- ESOP
Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
- Tech Allowance
Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
- Health Benefits
Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.
- Annual Off-Sites
Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
- Flexible Work
We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
- Professional Development
Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.
ABOUT THE TEAM
Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.
- ~400 team members
- 60+ countries
- 20+ languages spoken
- Over $1B raised (including our $500M Series F)
- 540,000+ community members
We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.