Offensive Security Engineer

1 month, 2 weeks ago
Full-time
Senior
Cybersecurity
ClickHouse

ClickHouse

ClickHouse provides a fast open source column-oriented database management system that enables users to generate real-time analytical data reports through SQL queries, catering to the needs of industries requiring efficient data processing and analysis.

IT Services
51-250
Founded 2021
$300M raised

Description

  • Identify security gaps and vulnerabilities across ClickHouse offerings, including web, API, and server-client assets.
  • Triage vulnerabilities reported through bug bounty, responsible disclosure, and GitHub issues, including low-level memory issues.
  • Improve and develop security assurance activities such as penetration tests, vulnerability assessments, bug bounty programs, and fuzzing.
  • Plan and execute internal red team assessments and penetration tests against infrastructure and cloud environments.
  • Design realistic adversary scenarios to test detection, response, and control effectiveness.
  • Assess AI/LLM-specific attack surfaces in customer-facing features and internal AI tooling.
  • Build and operate agentic tooling for reconnaissance, exploit chaining, and attack-path discovery.
  • Partner with detection engineering to validate and improve detection coverage during red team exercises.
  • Handle information security events and incidents across products and services.
  • Develop processes, tooling, and automation to scale security operations and reduce business risk.

Requirements

  • 7+ years of experience in pentesting, red teaming, and product security.
  • Experience supporting engineering and product teams through threat assessments, assurance activities, advisory work, and some implementation work.
  • Hands-on experience with offensive security engagements across cloud, network, and application environments.
  • Ability to design adversary scenarios based on real threat intelligence and tailored to a multi-tenant cloud data platform.
  • Strong written and verbal communication skills.
  • Experience building or adapting agentic and LLM-assisted tooling for offensive security use cases.
  • Familiarity with AI/LLM-specific vulnerability classes and testing methodology.
  • Strong knowledge of one or more cloud providers such as AWS, GCP, or Azure, plus Kubernetes and Cilium.
  • Experience implementing security tools and processes such as static/dynamic code analysis, SCA, SBOM, OWASP SAMM, and fuzzing tools.
  • Security-as-code mindset with a focus on automation and scale.
  • BS, MS, or PhD in Computer Science or a related field (bonus).
  • Open source contributions (bonus).
  • Security or cloud certifications such as AWS, GCP, or Azure (bonus).
  • Experience using AI security harnesses for pentesting (bonus).
  • Experience building internal red team tooling and infrastructure from scratch (bonus).
  • Offensive security certifications such as OSCP, OSCE, OSEP, or OSWE (bonus).

Benefits

  • Flexible, remote-friendly work environment across 20+ countries.
  • Employer contributions toward healthcare.
  • Equity in the company through stock options.
  • Flexible time off in the US and generous entitlement in other countries.
  • $500 home office setup budget for remote employees.
  • Opportunities to attend company-wide offsites and global gatherings.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

IT Systems Audit SME (SAP WMS)

C5MI 11-50 Internet Software & Services

C5MI is seeking an IT Systems Audit SME to lead audit readiness, internal-control evaluation, risk management, and compliance activities for mission-critical DoD/DLA warehouse management and SAP environments.

Cybersecurity
4 days, 1 hour ago

Principal Technical Consultant - Network & Security Solution Architect

AHEAD 1K-5K IT Services

AHEAD is seeking a Solution Architect – Network & Network Security to lead the design and delivery of enterprise-scale network and security solutions for a complex Fortune 10 client environment.

Azure Cisco Network Security
5 days, 1 hour ago

Technical Consultant

AHEAD 1K-5K IT Services

AHEAD is seeking a Technical Consultant to help enterprise clients improve cloud security and compliance through consulting delivery, business development, and security practice development.

AWS Azure Bash CI/CD Docker Kubernetes PowerShell Python SIEM Splunk Terraform
1 week ago

Senior Professional Services Technical Architect - Security

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Senior Professional Services Technical Architect, Security to design and lead secure enterprise DevSecOps solutions for Professional Services clients across AMER, from pre-sales scoping through implementation and enablement.

Ansible CI/CD DevSecOps GitLab Jenkins SonarQube Terraform
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers