Full-Time

Product Marketing

Updated on 9/3/2026

Metabase

Metabase

51-200 employees

Open-source BI tool for dashboards

Compensation Overview

$150k - $225k/yr

+ Equity

Remote in USA

Remote

Category
Growth & Marketing (1)
Required Skills
Market Research
SEO
Data Analysis

Get referred to Metabase

See people who can refer or advise you

Requirements
  • Experience in product marketing in B2B SaaS; analytics, data tooling, or developer tools experience is a strong plus
  • Exceptional writer — you can take a dense technical concept and make it land for a non-technical audience without losing accuracy
  • Comfortable working with data: you've used tools like Metabase and can speak credibly to data workflows
  • Proven track record of launching products or features end-to-end
  • Strong cross-functional collaborator who thrives in a fast-moving, async-friendly environment
Responsibilities
  • Own positioning and messaging for one or more product areas (e.g., embedded analytics, self-serve BI, AI features, enterprise/cloud)
  • Drive product launch strategy for new features and releases, coordinating across product, engineering, design, sales, and customer success
  • Build and maintain sales enablement materials — battlecards, pitch decks, one-pagers, and objection handling guides
  • Conduct ongoing competitive research and maintain a sharp understanding of the BI and analytics landscape
  • Partner with content and demand gen on campaigns, SEO narratives, and thought leadership that drives pipeline
  • Conduct customer and prospect interviews to surface insights that sharpen positioning and inform roadmap
  • Represent the customer voice internally — synthesizing insights from win/loss analysis, interviews, and community feedback to influence product and marketing strategy
  • Support category-level storytelling at industry events
Desired Qualifications
  • experience marketing to both technical buyers (data engineers, developers) and business buyers (ops, finance, product)
  • experience working across multiple GTM motions (product-led, sales-assisted, enterprise) and buyer personas

Metabase provides an open-source business intelligence tool that helps organizations analyze and visualize data. It focuses on usability for non-technical users, allowing people to connect data sources, create dashboards and reports, and embed analytics into applications without deep SQL knowledge. The product supports both self-hosted (open-source) and hosted (premium) options, including features like advanced analytics, priority support, and white-labeling through a freemium model. Compared to competitors, Metabase differentiates itself with its open-source foundation, easy-to-use interface, and flexible deployment and branding options, making it accessible to small and medium-sized businesses as well as larger enterprises. Its goal is to enable data-driven decision-making by democratizing access to data analytics and visualization across organizations.

Company Size

51-200

Company Stage

Series B

Total Funding

$38M

Headquarters

San Francisco, California

Founded

2014

Get referred to Metabase

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Metabase patched the August 2026 zero-day within days and hardened cloud instances.
  • Under 3% of Metabase Cloud customers were compromised before patching.
  • Metabase 62-63 broadened AI, schema, and embedded-analytics workflows for enterprises.

What critics are saying

  • August 2026 SQL injection let attackers create admin sessions and steal database credentials.
  • Self-hosted versions 0.58-0.63 stayed exposed until customers patched immediately.
  • Another public exploit would destroy trust in Metabase Cloud and stall enterprise adoption.

What makes Metabase unique

  • Metabase 63, July 2026, ships treemaps, two-factor authentication, and PDF dashboard subscriptions.
  • Metabase 62, June 2026, adds CLI, plugin SDK, and programmatic embedded filters.
  • Metabase 60-61, April-May 2026, open-sources AI tools and adds dashboards-as-code.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
LBank
Sep 3rd, 2026
Wallet owners face multiple threats.

Wallet owners face multiple threats. Trezor's own systems were not breached, and devices, private keys and wallet backups are untouched. The danger is that the records identify confirmed hardware wallet owners at specific front doors. Alongside fake emails, calls and letters, Trezor warned affected customers about risks to their physical security, and repeated that a wallet backup should never be shared or typed into a website. Owners of both Trezor and rival hardware wallet Ledger were already receiving forged letters in February, printed with holograms, QR codes and forged executive signatures, demanding they activate a fictitious security check or lose access to their wallets. At the time, cybercrime consultant David Sehyeon Baek told Decrypt that a letter carrying a name and home address signals "we can locate you," and that stolen data stays useful for years because people rarely move or change their numbers. The intrusion traces to a critical SQL injection flaw in the analytics tool Metabase, disclosed on August 6, which let unauthenticated attackers steal credentials for connected databases. Laptop maker Framework and form builder Tally were caught in the same wave. ShipMonk has reportedly received extortion emails attributed to ShinyHunters, though that attribution remains unconfirmed. Trezor said it is working to ship anonymous delivery as quickly as possible, an option using locker pickup, neutral packaging and generic sender details so that buyers need not hand over a home address at all.

SMBtech
Aug 30th, 2026
Ticket resale platform Tixel warns users of data breach in Metabase zero-day attack.

Ticket resale platform Tixel warns users of data breach in Metabase zero-day attack. Surprisingly useful AI article enhancements. Melbourne-based ticket resale platform, Tixel, has notified users that their email addresses and mobile numbers may have been accessed after an attacker exploited a zero-day vulnerability in its third-party analytics provider, Metabase. Tixel told affected users that the incident occurred inside Metabase's systems, not within the Tixel platform itself. "Our website and account systems were not breached," the company stated in a notification sent to users. No passwords, credit card details, payment information or purchase history were involved in the incident, according to the company. Part of a wider Metabase breach. The Tixel disclosure is the latest in a growing list of companies affected by a critical SQL injection vulnerability in Metabase that was exploited as a zero-day, impacting versions 1.58 and above. The vulnerability, tracked as CVE-2026-72898, carries a CVSS severity score of 10.0 - the highest possible rating. It affects the password-reset functionality and can be reached through the publicly accessible POST /api/session/reset_password endpoint, allowing a remote attacker to inject SQL into the Metabase application database without authenticating. Metabase CEO, Sameer Al-Sakran, warned in a blog post that the company's cloud platform had been compromised through the previously unknown flaw. Metabase confirmed that attackers were actively exploiting the vulnerability against real-world environments. Metabase is an open-source business intelligence and data visualisation tool that customers can connect to databases including Databricks, MongoDB, Oracle, Snowflake, Amazon and BigQuery, among others, to access analytics, query and visualise data, and build dashboards. What was accessed. In its notification to users, Tixel indicated that the breach was limited in scope. "Our investigation with Metabase indicates your email address and mobile number may have been accessed as part of this incident," the company stated. Tixel confirmed that user accounts, including any tickets or listings, were unaffected. The company warned users to watch for phishing and spam as a result of the exposure. "Be cautious of any unexpected message about your tickets, orders or account," Tixel advised. "If a message feels off, don't click anything in it - go straight to tixel.com or contact us." Tixel also reminded users that it would never ask for passwords or payment details by email or text, and would never direct payments outside tixel.com. Remediation steps. Tixel stated that it changed the keys connecting its systems to Metabase, checked for any further access - finding none - and strengthened its security and data-handling practices. On Metabase's side, the company blocked the endpoints used for the attack, then identified and patched the vulnerability. Metabase Cloud customers had their instances upgraded and patched automatically. Metabase has also engaged an independent forensic firm and notified relevant authorities and regulators, according to Tixel's notification. The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalogue, requiring federal agencies to apply fixes by 14 August 2026. Other companies affected. Tixel is not alone in disclosing a breach stemming from the Metabase vulnerability. Several companies have already confirmed they were affected, including Kilo Code, Tally, Framework, n8n and ChecklyHQ, with stolen data including usernames, emails, API keys and Slack tokens across various incidents. Laptop manufacturer, Framework, disclosed that attackers accessed names, email addresses, phone numbers, physical addresses and login IP addresses through its compromised Metabase cloud instance, though payment information and order records were not affected. Workflow automation platform, n8n, confirmed that 136 records containing names and email addresses were accessed across its user base. Scale of exposure. Roughly 2,500 Metabase instances are estimated to be internet-exposed, and about 25 per cent of self-hosted cloud deployments are fully accessible online. Dataminr's threat research team conducted a broad exposure assessment on 8 August, with approximately 11,000 hosts observed as probable self-hosted Metabase deployments. Tixel directed users with further questions to [email protected] and pointed to the Australian Cyber Security Centre at cyber.gov.au and the ACCC's Scamwatch at scamwatch.gov.au for general online safety guidance. About tixel. Tixel is a Melbourne-based ticket resale marketplace founded in 2017. The platform operates as a fan-to-fan marketplace for buying and selling tickets to concerts, festivals and events, with AI-powered fraud detection and price caps that prevent scalping. Unlike some resale platforms, Tixel caps resale prices at 110 per cent of face value, verifies tickets before transfer and works with event organisers to provide a secondary market. Last Updated on August 30, 2026 by Nick Ross

HookPhish
Aug 14th, 2026
Ransomware Group shinyhunters hits: Metabase.

Ransomware Group shinyhunters hits: Metabase. HookPhish team Summary. In the latest cybersecurity news, Metabase - an organization based in US - has fallen victim to a ransomware attack conducted by the group shinyhunters. This data breach, discovered on Aug 14, 2026, 06:01 UTC, underscores the increasing need for proactive cybersecurity defenses as HookPhish continue through 2026. Incident report. | Target Organization | Metabase | | Threat Group | shinyhunters | | Summary | Updated: 12 August 2026 | SHA256: 84daf8f33954a0b03238a1e0da3ee109d5bc32acc134cfdddfac36b4b75d2480 | | Date of Breach | Aug 12, 2026, 11:10 UTC | | Discovery Date | Aug 14, 2026, 06:01 UTC | | Region | US | | Business Sector | Technology | How to reduce your ransomware risk. Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure: * awareness training - close the gap attackers exploit. * keep watch on the dark web - close the gap attackers exploit. Disclaimer. HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Metabase
Aug 12th, 2026
Security-focused metabase release announcement.

Security-focused metabase release announcement. Sameer al-sakran. - Aug 12, 2026 in News Following its security update last week, today Metabase is releasing hardened versions of Metabase which incorporate several security improvements, including hardening its api and fixing issues that are derivatives of the vulnerability Metabase encountered last week. Metabase strongly encourage you to upgrade immediately. This update was largely a result of its first-party security research (with hat tips to DOS, Ophion Security and Anthropic for helping identify areas of focus). While Metabase is proud of the new features Metabase has developed, Metabase is holding off on its next release, and will instead focus on weekly minor releases. These will be largely security and observability centered. Metabase understand you are interested in what happened and how you can best protect yourself. Metabase appreciate your patience as its internal and external investigations proceed, and Metabase will update you if Metabase has additional relevant information to share. In the meantime, Metabase is working hard to protect you and help you protect yourselves. Metabase will continue to invest heavily in its internal security research as well as engage with third-party researchers. Upgrade instructions. See the list of versions below and find the latest point version for the Metabase version you're running. For example, if you are running 0.58.6, you should upgrade to 0.58.31 release or later. Minimum safe releases for each Metabase version. (Updated 2026-08-14) The downloads below include the minimum safe release for each Metabase version. * Docker image: metabase/metabase:v0.63.13 * Download the JAR here: https://downloads.metabase.com/v0.63.13/metabase.jar * Docker image: metabase/metabase:v0.62.16 * Download the JAR here: https://downloads.metabase.com/v0.62.16/metabase.jar * Docker image: metabase/metabase:v0.61.18 * Download the JAR here: https://downloads.metabase.com/v0.61.18/metabase.jar * Docker image: metabase/metabase:v0.60.24 * Download the JAR here: https://downloads.metabase.com/v0.60.24/metabase.jar * Docker image: metabase/metabase:v0.59.28 * Download the JAR here: https://downloads.metabase.com/v0.59.28/metabase.jar * Docker image: metabase/metabase:v0.58.31 * Download the JAR here: https://downloads.metabase.com/v0.58.31/metabase.jar

CloudLink Tech
Aug 10th, 2026
Metabase patches zero-day SQL injection vulnerability.

Metabase patches zero-day SQL injection vulnerability. Metabase released urgent patches for a zero-day SQL injection that allowed unauthenticated attackers to inject SQL and gain administrative access; Cloud instances are updated and self-hosted users must patch. Metabase released urgent patches for a critical SQL injection vulnerability that was exploited in the wild. Metabase Cloud instances have already been updated. Self-hosted users are urged to apply the vendor's patches or use a temporary workaround until they can update. The vulnerability was discovered after a threat actor exploited it in an attack against Metabase Cloud. The company blocked the endpoints used in the intrusion and produced fixes for affected releases. A CVE identifier has not been assigned. Patched builds are listed as versions 63.5, 62.9, 61.11, 60.17, 59.21 and 58.24. The flaw allows remote, unauthenticated attackers to inject arbitrary SQL into the Metabase application. The advisory warned that an attacker who gains that access could obtain full administrative control, change application configuration, steal stored credentials for connected databases, read data available through those connections, and export data. The advisory stated that Metabase identified and patched the issue quickly after blocking the endpoints used in the attack. Metabase recommends that self-hosted administrators apply the released patches as soon as possible. Where immediate patching is not feasible, the vendor advises blocking the /api/session/reset_password endpoint as a temporary workaround. After applying patches, administrators should revoke all active user sessions, remove any unrecognized API keys, inspect administrative accounts for unauthorized changes, rotate credentials used by connected databases, and review logs and Metabase activity for suspicious access. To help detect potential compromises, Metabase pointed to a specific log pattern: a "POST /api/session/reset_password" request returning a 400 status code followed by a "GET /api/user/current" request returning 200. Finding that sequence in application or ingress logs likely indicates the instance was compromised. Administrators unable to update immediately are advised to isolate affected instances from the internet until they can apply the patched releases and complete the cleanup and verification steps outlined in the advisory.