Full-Time

Technical Product Lead

Metabase

Metabase

51-200 employees

Open-source BI tool for dashboards

Compensation Overview

$102k - $200k/yr

+ Equity

Remote in USA

Remote

Category
Product (1)
Required Skills
Product Management

Get referred to Metabase

See people who can refer or advise you

Requirements
  • Strong technical foundation (e.g., engineering or similarly technical experience).
  • Hands-on experience working with data tools (e.g., querying, modeling, or building with data).
  • Ability to understand user needs and translate them into clear problem definitions.
  • Strong product judgment - what’s worth solving, what isn’t, and why.
  • Comfortable working closely with engineers on feasibility and tradeoffs.
  • Able to operate with high judgment in ambiguous environments.
  • Clear thinker and communicator, especially when simplifying complex ideas.
  • You should be able to quickly build context, form strong opinions, and contribute at a high level.
Responsibilities
  • Talk directly to customers to understand how they use the product and where it falls short
  • Build a deep understanding of user workflows, especially in data-heavy environments
  • Identify and clearly define the most important problems to solve
  • Turn those insights into clear proposals for product direction
  • Move across engineering teams, focusing on where context is most useful
  • Work closely with engineers and design to shape solutions and tradeoffs
  • Bring clarity to ambiguous problems so teams can move quickly and make good decisions
Desired Qualifications
  • Experience working on data-heavy or technical products
  • Experience building or leading complex projects or initiatives
  • Track record of taking ownership and operating with autonomy

Metabase provides an open-source business intelligence tool that helps organizations analyze and visualize data. It focuses on usability for non-technical users, allowing people to connect data sources, create dashboards and reports, and embed analytics into applications without deep SQL knowledge. The product supports both self-hosted (open-source) and hosted (premium) options, including features like advanced analytics, priority support, and white-labeling through a freemium model. Compared to competitors, Metabase differentiates itself with its open-source foundation, easy-to-use interface, and flexible deployment and branding options, making it accessible to small and medium-sized businesses as well as larger enterprises. Its goal is to enable data-driven decision-making by democratizing access to data analytics and visualization across organizations.

Company Size

51-200

Company Stage

Series B

Total Funding

$38M

Headquarters

San Francisco, California

Founded

2014

Get referred to Metabase

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Metabase released hardened builds on 2026-08-12 and urged immediate upgrades.
  • The company says Cloud customers were patched by 2026-08-06, limiting immediate churn.
  • Metabase had 18 open roles on 2026-08-01, signaling continued hiring.

What critics are saying

  • CVE-2026-72898 enabled unauthenticated SQL injection, exposing connected database credentials on 2026-08-06.
  • Framework, n8n, and Checkly confirmed tenant data exposure after Metabase’s breach.
  • If self-hosted customers stay unpatched, CISA KEV exposure destroys trust and renewals fast.

What makes Metabase unique

  • Metabase’s open-source core keeps product switching costs low and community adoption high.
  • v61 on 2026-08-03 added AI governance controls, token limits, and dashboards-as-code.
  • Pro and Enterprise plans separate analyst permissions from admins, reducing governance friction.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
HookPhish
Aug 14th, 2026
Ransomware Group shinyhunters hits: Metabase.

Ransomware Group shinyhunters hits: Metabase. HookPhish team Summary. In the latest cybersecurity news, Metabase - an organization based in US - has fallen victim to a ransomware attack conducted by the group shinyhunters. This data breach, discovered on Aug 14, 2026, 06:01 UTC, underscores the increasing need for proactive cybersecurity defenses as HookPhish continue through 2026. Incident report. | Target Organization | Metabase | | Threat Group | shinyhunters | | Summary | Updated: 12 August 2026 | SHA256: 84daf8f33954a0b03238a1e0da3ee109d5bc32acc134cfdddfac36b4b75d2480 | | Date of Breach | Aug 12, 2026, 11:10 UTC | | Discovery Date | Aug 14, 2026, 06:01 UTC | | Region | US | | Business Sector | Technology | How to reduce your ransomware risk. Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure: * awareness training - close the gap attackers exploit. * keep watch on the dark web - close the gap attackers exploit. Disclaimer. HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Metabase
Aug 12th, 2026
Security-focused metabase release announcement.

Security-focused metabase release announcement. Sameer al-sakran. - Aug 12, 2026 in News Following its security update last week, today Metabase is releasing hardened versions of Metabase which incorporate several security improvements, including hardening its api and fixing issues that are derivatives of the vulnerability Metabase encountered last week. Metabase strongly encourage you to upgrade immediately. This update was largely a result of its first-party security research (with hat tips to DOS, Ophion Security and Anthropic for helping identify areas of focus). While Metabase is proud of the new features Metabase has developed, Metabase is holding off on its next release, and will instead focus on weekly minor releases. These will be largely security and observability centered. Metabase understand you are interested in what happened and how you can best protect yourself. Metabase appreciate your patience as its internal and external investigations proceed, and Metabase will update you if Metabase has additional relevant information to share. In the meantime, Metabase is working hard to protect you and help you protect yourselves. Metabase will continue to invest heavily in its internal security research as well as engage with third-party researchers. Upgrade instructions. See the list of versions below and find the latest point version for the Metabase version you're running. For example, if you are running 0.58.6, you should upgrade to 0.58.31 release or later. Minimum safe releases for each Metabase version. (Updated 2026-08-14) The downloads below include the minimum safe release for each Metabase version. * Docker image: metabase/metabase:v0.63.13 * Download the JAR here: https://downloads.metabase.com/v0.63.13/metabase.jar * Docker image: metabase/metabase:v0.62.16 * Download the JAR here: https://downloads.metabase.com/v0.62.16/metabase.jar * Docker image: metabase/metabase:v0.61.18 * Download the JAR here: https://downloads.metabase.com/v0.61.18/metabase.jar * Docker image: metabase/metabase:v0.60.24 * Download the JAR here: https://downloads.metabase.com/v0.60.24/metabase.jar * Docker image: metabase/metabase:v0.59.28 * Download the JAR here: https://downloads.metabase.com/v0.59.28/metabase.jar * Docker image: metabase/metabase:v0.58.31 * Download the JAR here: https://downloads.metabase.com/v0.58.31/metabase.jar

CloudLink Tech
Aug 10th, 2026
Metabase patches zero-day SQL injection vulnerability.

Metabase patches zero-day SQL injection vulnerability. Metabase released urgent patches for a zero-day SQL injection that allowed unauthenticated attackers to inject SQL and gain administrative access; Cloud instances are updated and self-hosted users must patch. Metabase released urgent patches for a critical SQL injection vulnerability that was exploited in the wild. Metabase Cloud instances have already been updated. Self-hosted users are urged to apply the vendor's patches or use a temporary workaround until they can update. The vulnerability was discovered after a threat actor exploited it in an attack against Metabase Cloud. The company blocked the endpoints used in the intrusion and produced fixes for affected releases. A CVE identifier has not been assigned. Patched builds are listed as versions 63.5, 62.9, 61.11, 60.17, 59.21 and 58.24. The flaw allows remote, unauthenticated attackers to inject arbitrary SQL into the Metabase application. The advisory warned that an attacker who gains that access could obtain full administrative control, change application configuration, steal stored credentials for connected databases, read data available through those connections, and export data. The advisory stated that Metabase identified and patched the issue quickly after blocking the endpoints used in the attack. Metabase recommends that self-hosted administrators apply the released patches as soon as possible. Where immediate patching is not feasible, the vendor advises blocking the /api/session/reset_password endpoint as a temporary workaround. After applying patches, administrators should revoke all active user sessions, remove any unrecognized API keys, inspect administrative accounts for unauthorized changes, rotate credentials used by connected databases, and review logs and Metabase activity for suspicious access. To help detect potential compromises, Metabase pointed to a specific log pattern: a "POST /api/session/reset_password" request returning a 400 status code followed by a "GET /api/user/current" request returning 200. Finding that sequence in application or ingress logs likely indicates the instance was compromised. Administrators unable to update immediately are advised to isolate affected instances from the internet until they can apply the patched releases and complete the cleanup and verification steps outlined in the advisory.

GBHackers
Aug 10th, 2026
Metabase 0-day flaw exploited in attack to inject arbitrary SQL and steal database credentials.

Metabase 0-day flaw exploited in attack to inject arbitrary SQL and steal database credentials. August 10, 2026 Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. Cloud security certification Discover more Antivirus & Malware According to the company, an attacker exploited this previously unknown flaw to target Metabase Cloud before the vulnerable endpoints were blocked and a patch was developed. Customers using Metabase Cloud have already been upgraded and are now protected. However, organizations running their own Metabase instances may still be at risk until they install a secure point release. Metabase 0-day flaw. This vulnerability allows an attacker who gains access to a compromised Metabase deployment to inject arbitrary SQL queries into the Metabase application database. This could grant them administrator-level access to the instance, allowing them to modify application settings. From this point, attackers may be able to steal credentials stored for connected databases, access data available through those connections, and export sensitive information. This issue poses a particular risk for organizations that use Metabase as a central analytics platform connected to production databases, cloud warehouses, and other critical data sources. Metabase indicated that the exposed attack surface is linked to the /api/session/reset_password endpoint. Administrators should evaluate whether this endpoint has been publicly accessible and review logs for indications of attempted or successful exploitation. Discover more Penetration testing services Malware removal software Attack Pattern and Detection The vendor identified a specific sequence that may indicate compromise: * A POST /api/session/reset_password request returning HTTP 400. * A subsequent GET /api/user/current request returning HTTP 200. Organizations that identify this pattern in Metabase application logs, reverse-proxy logs, or ingress logs should treat the instance as potentially compromised and initiate incident response procedures. The advisory states that versions prior to Metabase 58 are not affected. However, deployments running version 58 or later must upgrade to the latest safe point release in their release branch. Metabase has published the following minimum patched versions: Organizations using Metabase version 0.58.6 must upgrade to version 0.58.24 or a later supported release. Docker users should pull the corresponding patched `metabase/metabase` image, while JAR-based deployments should replace the existing application package with the updated version. Discover more Dark web monitoring Threat intelligence reports Cyberattack prevention tools After the upgrade, administrators whose password-reset endpoint was accessible over the Internet should revoke existing user sessions by deleting entries from the `core_session` table in the Metabase application database. They should also review API keys, check administrator accounts for any unauthorized changes, and delete unfamiliar keys. Since the flaw may expose stored database credentials, affected organizations should rotate the credentials for every connected database. Additionally, security teams should inspect data warehouse audit logs, Metabase activity records, and query history for any suspicious access, exports, or unexpected SQL activity. Cloud security certification Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world. Hot this week

The Hacker News
Aug 8th, 2026
Metabase zero-day exploited in wild allows admin access without authentication.

Metabase zero-day exploited in wild allows admin access without authentication. Ravie LakshmananAug 08, 2026 Zero-Day / Vulnerability Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance. Armed with the elevated access, the attacker can change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. "We recently identified that Metabase Cloud was attacked by someone utilizing an unknown ('0-day') security vulnerability in versions 1.58 and above," Metabase said in an advisory. Metabase Cloud instances have already been updated to the latest version. Users running self-hosted versions are advised to apply security patches released by Metabase with immediate effect. The following versions are affected - * >= x.58.0, < x.58.23 (Fixed in x.58.24) * >= x.59.0, < x.59.20 (Fixed in x.59.21) * >= x.60.0, < x.60.16 (Fixed in x.60.17) * >= x.61.0, < x.61.10 (Fixed in x.61.11) * >= x.62.0, < x.62.8 (Fixed in x.62.9) * >= x.63.0, < x.63.3 (Fixed in x.63.5) As a temporary workaround until the fixes can be applied, it's advised to block the "/api/session/reset_password" endpoint. Once the update is complete, customers who have their "/api/session/reset_password" endpoint publicly accessible are advised to perform the following steps - * Revoke all active user sessions by accessing the Metabase Application Database and deleting all rows in the core_session table * Review API keys and delete any unrecognized keys * Review administrator accounts for any unexpected changes * Rotate credentials for any of the connected databases * Review data warehouse logs for any sign of unauthorized access * Review Metabase activity and query history for unexpected or unauthorized activity Metabase has not shared any specifics about the malicious activity, but shared the following indicators of compromise (IoCs) - * A call to "POST /api/session/reset_password" with a 400 status code * This is followed by a call to "GET /api/user/current" with a 200 status code "If you find that pattern in your application logs or in your Metabase server ingress logs, it is likely that your instance has been compromised," Metabase CEO Sameer Al-Sakran said. One of the companies that has been affected is Framework. According to Engadget, the PC maker alerted all its customers that customer names, login IPs, addresses, phone numbers, and emails were accessed during the hack. It noted that no order or payment information was accessed. Exactly three years ago, Metabase moved to address another "extremely severe" flaw (CVE-2023-38646, CVSS score: 9.8) that could have resulted in pre-authenticated remote code execution on affected installations. Found this article interesting? Follow ASMGi on Google News, Twitter and LinkedIn to read more exclusive content ASMGi post.