USD per year
Internal Auditor
Location
Remote
Employment Type
Full time
Location Type
Remote
Department
Operations OverviewApplication We're looking for an Internal Auditor to join our Security & Compliance team and help strengthen our governance, risk, and compliance posture as we scale. You'll work closely with engineering, product, security, and business teams across Supabase, leading audit processes and ensuring we maintain the highest standards of compliance. This role is ideal for someone who thrives in async, fast-paced environments and is excited about building robust compliance programs in a rapidly growing, developer-focused company.
What You'll Be Responsible for
In this role, you'll:
- Lead audit readiness and execution for SOC 2, ISO 27001, PCI DSS, and other compliance frameworks relevant to our customer base
- Manage the compliance lifecycle in a compliance platfom (such as Vanta, Drata etc) including evidence collection, control mapping, and continuous monitoring
- Coordinate cross-functional audit activities with engineering, product, security, infrastructure, and support teams to gather evidence and remediate findings
- Design and implement internal audit programs that scale with our rapid growth, identifying gaps and driving process improvements
- Partner with external auditors to facilitate smooth audits and ensure timely completion of certifications
- Document policies, procedures, and controls that align with industry standards and support our security-by-design approach
- Build relationships across the organization to embed compliance thinking into product development and operational workflows
- Track and report on compliance metrics, providing visibility to leadership on audit status, risk areas, and remediation progress
You Might Be a Good Fit If You
- Have 5+ years of experience in internal audit, compliance, or GRC roles,...
Supabase is the Postgres development platform. Start your project with a Postgres database, Authentication, instant APIs, Edge Functions, Realtime subscriptions, Storage, and Vector embeddings. It offers a full Postgres database with built-in Auth and Row Level Security, Edge Functions for custom code without server management, Storage for large files, Realtime data synchronization, Vector integration for ML-models, and instant ready-to-use Restful APIs.
View Company Profile