Product Security Engineer

10 hours, 9 minutes ago
Full-time
Senior
Cybersecurity
ClickHouse

ClickHouse

ClickHouse provides a fast open source column-oriented database management system that enables users to generate real-time analytical data reports through SQL queries, catering to the needs of industries requiring efficient data processing and analysis.

IT Services
51-250
Founded 2021
$300M raised

Description

  • Collaborate with engineering and product teams to improve existing features and build new ones with strong threat modeling, assurance, and secure implementation practices.
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, and triage issues from bug bounty, responsible disclosure, and GitHub reports across web, API, and server-client assets.
  • Improve and develop security assurance activities such as pentests, vulnerability assessments, bug bounty programs, and fuzzing.
  • Drive adoption and use of engineering security tools, including static and dynamic code analysis, dependency checks, and code licensing compliance tooling.
  • Nurture the engineering-security relationship and identify process and technology improvements.
  • Handle information security events and incidents across ClickHouse products and services.
  • Develop processes, tooling, and automation to scale security operations and reduce business risk.

Requirements

  • Experience supporting engineering and product implementation efforts through threat assessments, assurance activities, advisory work, and implementation support across distributed systems.
  • Strong knowledge of one or more cloud providers such as AWS, GCP, or Azure, plus Kubernetes and Cilium.
  • Experience implementing and operating security tools and processes such as static and dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, and fuzzing tools.
  • Significant development and automation experience, with ability to work with C++ code.
  • Security-as-code mindset with a focus on automation and scale.
  • BS, MS, or PhD in Computer Science or a related field is a plus.
  • Previous contributions to open source projects are a plus.
  • Security or cloud certifications from AWS, GCP, or Azure are a plus.

Benefits

  • Flexible remote-friendly work environment, with fully remote work available anywhere in Germany.
  • Employer contributions toward healthcare.
  • Equity in the company through stock options for every new team member.
  • Flexible time off in the US and generous time off in other countries.
  • $500 home office setup allowance for remote employees.
  • Opportunities to connect with colleagues through company-wide global gatherings and offsites.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Engineer - Product & Production Infrastructure

Wiz 251-1K IT Services

Wiz is hiring a Security Engineer for Product & Production Infrastructure to secure its cloud products, CI/CD, and production environments through security reviews, vulnerability management, and detection and response work.

AWS Azure CI/CD GCP Go Helm Kubernetes Python Rust Terraform
8 hours, 9 minutes ago

Senior Security Researcher

Veracode 251-1K Internet Software & Services

Veracode is hiring a Senior Security Researcher to lead Applied Research projects that improve its Static Application Security Testing platform while producing original security research for the broader community.

C C# C++ .NET Penetration Testing Prototyping
10 hours, 24 minutes ago

Senior Application Security Engineer

Abnormal AI Internet Software & Services

Abnormal AI is hiring a Senior Application Security Engineer to secure its AI-powered cybersecurity applications by embedding application security into development, architecture, and incident response across engineering teams.

Burp Suite CI/CD Encryption Git Go Java JavaScript Linux Microservices Python SonarQube TypeScript
10 hours, 39 minutes ago

Security Engineer - Product & Production Infrastructure

Wiz 251-1K IT Services

Wiz is seeking a Security Engineer for Product & Production Infrastructure to secure its cloud-native products, CI/CD, and production environments while helping shape defensive practices across the company.

AWS Azure CI/CD GCP Go Helm Kubernetes Python Rust Terraform
10 hours, 53 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers