Senior Product Security Engineer

ClickHouse
United States
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Automation","Incident response","Collaboration","Problem-solving","Security-as-code"]

Partner with engineering and product teams to improve and build security for ClickHouse Cloud and OSS, driving threat modeling, assurance, and secure implementation. Identify vulnerabilities across web, API, and server-client assets, handle incidents and events, and scale security processes through automation and tooling. Improve security assurance activities like pentests, vulnerability assessments, bug bounty programs, and fuzzing, using engineering security tools such as static/dynamic analysis and dependency checks.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
ClickHouse
ClickHouse
1 month ago

Senior Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Partner with engineering and product teams to improve and build security for ClickHouse Cloud and OSS, driving threat modeling, assurance, and secure implementation. Identify vulnerabilities across web, API, and server-client assets, handle incidents and events, and scale security processes through automation and tooling. Improve security assurance activities like pentests, vulnerability assessments, bug bounty programs, and fuzzing, using engineering security tools such as static/dynamic analysis and dependency checks.
Location: United States
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Collaborate with engineering and product to build and enhance security features, including threat modeling, assurance, and secure implementation.
  • •Identify security gaps and vulnerabilities across ClickHouse Cloud and OSS, triage vulnerabilities from bug bounty and responsible disclosure programs, and address issues across web, API, and server-client assets.
  • •Improve and develop security assurance activities such as pentests, vulnerability assessments, bug bounty programs, and fuzzing.
  • •Drive implementation and usage of engineering security tools including static/dynamic code analysis, dependency checks, and code licensing compliance.
  • •Handle information security events and incidents and develop processes, tooling, and automation to scale security activities.

Pay and Benefits

Equity and Bonus:Equity
Perks:Health InsuranceEquityPaid LeaveHome Office

Key Requirements

  • •Experience supporting engineering and product implementation with threat assessments and security assurance, including work across distributed web and API systems.
  • •Strong hands-on knowledge of one or more cloud providers (AWS, GCP, or Azure) plus Kubernetes-related environments (e.g., Cilium, Crossplane).
  • •Experience implementing and operating engineering security tools and processes such as static/dynamic code analysis, software composition analysis, SBOM, and fuzzing.
  • •Significant development and automation experience, with C++ preferred.
  • •Security-as-code mindset focused on automation and scaling security processes and risk mitigation.
Skills:AutomationIncident responseCollaborationProblem-solvingSecurity-as-code
Tech Stack:AWSGCPAzureKubernetesCiliumCrossplaneSnykSemgrepGitHub CodeQLSBOMOWASP SAMMStatic analysisDynamic analysisFuzzing

Company Brief

ClickHouse
Develops ClickHouse, a high-performance open-source columnar database for real-time analytics, enabling fast querying and processing of large volumes of data for analytics, monitoring, and business intelligence workloads.
Industry: Data Infrastructure
Headquarters: Menlo Park, United States
Founded: 2016
WebsiteLinkedIn