Product Security Engineer

USD 169,200-225,000 per year
MIDDLE
✅ Remote

Tech Stack

API @ 3 AWS @ 6 Azure @ 6 ClickHouse @ 3 Compliance Distributed Systems @ 3 GCP @ 6 GitHub Kubernetes @ 3 OWASP @ 3 Security @ 3

Details

ClickHouse is seeking an experienced, hands-on security practitioner to support engineering and product teams in improving the security posture of its platforms and services. The Security Team provides application, cloud, enterprise security, incident response, detection, and governance, risk, and compliance capabilities.

Responsibilities

  • Collaborate with engineering and product teams to improve existing and build new product features, focusing on threat modeling, security assurance, and secure implementation.
  • Support secure key management, passwordless authentication, machine-to-machine authentication, sandboxing, and compute, network, and storage isolation.
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and open-source ClickHouse.
  • Triage vulnerabilities reported through bug bounty programs, responsible disclosure, and GitHub Issues across web, API, and server-client assets, including low-level memory issues such as heap and buffer overflows.
  • Improve and develop security assurance activities, including penetration testing, vulnerability assessments, bug bounty programs, and fuzzing.
  • Drive the implementation and adoption of engineering security tools for static and dynamic code analysis, dependency checks, and code licensing compliance.
  • Nurture the engineering-security relationship and identify and implement process and technology improvements.
  • Handle information security events and incidents across ClickHouse products and services.
  • Develop processes, tooling, and automation to scale security processes and mitigate business risks.

Requirements

  • Experience supporting engineering and product implementation efforts through threat assessments, security assurance activities, advisory work, and, in some cases, implementation across distributed systems covering web, API, and client-server assets.
  • Strong knowledge of and experience with one or more cloud service providers, such as AWS, GCP, or Azure.
  • Experience with Kubernetes, Cilium, and Crossplane.
  • Experience implementing and operating engineering security tools and processes, including static and dynamic code analysis, software composition analysis, software bills of materials, OWASP SAMM, and client and network fuzzing tools.
  • Significant development and automation experience; ability to work with C++ code is preferred.
  • A security-as-code mindset, with a focus on solving problems through automation and scalable processes.

Bonus Points

  • Bachelor's, master's, or PhD in Computer Science or a related field.
  • Previous contributions to open-source projects.
  • Security- or cloud-related certifications, including AWS, GCP, or Azure certifications.

Compensation

The typical starting salary in the United States is $169,150–$191,250 USD. In US premium markets, the typical starting salary range is $169,150–$225,000 USD. Actual compensation depends on factors including education, qualifications, certifications, experience, skills, location, performance, and business needs.

Benefits

  • Flexible, remote-friendly work environment.
  • Employer healthcare contributions.
  • Company stock options for new team members.
  • Flexible time off in the United States and generous entitlement in other countries.
  • $500 home office setup allowance for remote employees.
  • Opportunities to participate in company-wide offsites and global gatherings.

More jobs at ClickHouse

Similar jobs