Offensive Security Engineer

4 weeks ago
Full-time
Senior
Cybersecurity
ClickHouse

ClickHouse

ClickHouse provides a fast open source column-oriented database management system that enables users to generate real-time analytical data reports through SQL queries, catering to the needs of industries requiring efficient data processing and analysis.

IT Services
51-250
Founded 2021
$300M raised

Description

  • Identify security gaps and vulnerabilities across ClickHouse offerings, including web, API, and server-client assets.
  • Triage vulnerabilities reported through bug bounty, responsible disclosure, and GitHub issues, including low-level memory issues.
  • Improve and develop security assurance activities such as penetration tests, vulnerability assessments, bug bounty programs, and fuzzing.
  • Plan and execute internal red team assessments and penetration tests against infrastructure and cloud environments.
  • Design realistic adversary scenarios to test detection, response, and control effectiveness.
  • Assess AI/LLM-specific attack surfaces in customer-facing features and internal AI tooling.
  • Build and operate agentic tooling for reconnaissance, exploit chaining, and attack-path discovery.
  • Partner with detection engineering to validate and improve detection coverage during red team exercises.
  • Handle information security events and incidents across products and services.
  • Develop processes, tooling, and automation to scale security operations and reduce business risk.

Requirements

  • 7+ years of experience in pentesting, red teaming, and product security.
  • Experience supporting engineering and product teams through threat assessments, assurance activities, advisory work, and some implementation work.
  • Hands-on experience with offensive security engagements across cloud, network, and application environments.
  • Ability to design adversary scenarios based on real threat intelligence and tailored to a multi-tenant cloud data platform.
  • Strong written and verbal communication skills.
  • Experience building or adapting agentic and LLM-assisted tooling for offensive security use cases.
  • Familiarity with AI/LLM-specific vulnerability classes and testing methodology.
  • Strong knowledge of one or more cloud providers such as AWS, GCP, or Azure, plus Kubernetes and Cilium.
  • Experience implementing security tools and processes such as static/dynamic code analysis, SCA, SBOM, OWASP SAMM, and fuzzing tools.
  • Security-as-code mindset with a focus on automation and scale.
  • BS, MS, or PhD in Computer Science or a related field (bonus).
  • Open source contributions (bonus).
  • Security or cloud certifications such as AWS, GCP, or Azure (bonus).
  • Experience using AI security harnesses for pentesting (bonus).
  • Experience building internal red team tooling and infrastructure from scratch (bonus).
  • Offensive security certifications such as OSCP, OSCE, OSEP, or OSWE (bonus).

Benefits

  • Flexible, remote-friendly work environment across 20+ countries.
  • Employer contributions toward healthcare.
  • Equity in the company through stock options.
  • Flexible time off in the US and generous entitlement in other countries.
  • $500 home office setup budget for remote employees.
  • Opportunities to attend company-wide offsites and global gatherings.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Technical Consultant - Network Security

AHEAD 1K-5K IT Services

AHEAD is seeking a Principal Technical Consultant to lead complex, client-facing network security engagements spanning firewalls, network access control, application delivery, SASE, and Zero Trust, from architecture through implementation and knowledge transfer.

Ansible AWS Azure CI/CD CloudFormation DNS GCP HIPAA JSON Kubernetes Microservices Network Security OpenAPI SIEM Splunk Terraform XML
17 hours, 40 minutes ago

Senior Consultant - Cyber Resilience

AHEAD 1K-5K IT Services

AHEAD is hiring a Senior Consultant to help enterprise clients improve cyber incident recovery, disaster recovery, resilience programs, and recovery validation from strategy through implementation.

Cybersecurity Network Security
1 day, 17 hours ago

Associate, Compliance Security Penetration Tester

Coalfire 251-1K Internet Software & Services

Coalfire is seeking a penetration testing professional to conduct cybersecurity assessments and simulate sophisticated attacks for clients across network, application, cloud, wireless, and social engineering environments.

C Cybersecurity HIPAA Network Security Penetration Testing PowerShell Python Ruby Shell Scripting
1 day, 17 hours ago

Security Officer

European Dynamics 251-1K IT Services

European Dynamics is seeking a remote Security Officer to support a major client’s IT team by leading information security, risk management, governance, and resilience activities.

Agile Cybersecurity DevSecOps
3 days, 17 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers