Supabase is the Postgres development platform, built by developers for developers to help them ship countless products that people love.
More than 7 million developers trust us with their data, and we are custodians of every byte of it.
Security is foundational to that trust, and as we move deeper into AI-native development, regulated industries, and enterprise, it shapes whether a developer chooses us on day one and whether a regulated company can build their most sensitive workloads on Supabase.
Every control you add is friction a developer has to absorb, and every default you loosen is a door an attacker could walk through.
Finding the right balance between protecting customers and keeping them fast is the work of this role.
You'll partner with Security Engineering, Compliance, and the platform teams that own auth, networking, and audit.
This is a remote position and we're open to considering candidates located across EMEA and AMER time zones.
In This Role You Will Set the security agenda for the platform.
Hold the line between security and developer experience.
Every security feature trades protection against friction.
A control that's too strict pushes developers off the platform; one that's too easy to bypass doesn't protect anyone.
Agents now read, write, and deploy on behalf of developers and companies, often at machine speed.
You'll lead how Supabase authenticates, scopes, and audits agent activity so customers can give them real capability while staying in control of their data.
Drive the roadmap for the security tooling customers use to operate saf.