Offensive Security Engineer

ClickHouse
EMEA
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 7+ yearsSkills: ["Communication","Advisory","Analysis","Problem-solving","Automation"]

Drive offensive security across ClickHouse’s products by identifying vulnerabilities, triaging reports, and improving security assurance practices such as pentesting, vulnerability assessments, fuzzing, and bug bounty programs. Plan and execute internal red team exercises and penetration tests, assess AI/LLM attack surfaces, and build agentic tooling for reconnaissance and exploit chaining. Partner with detection engineering on control effectiveness while handling incidents and scaling security processes through automation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
ClickHouse
ClickHouse
1 month ago

Offensive Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Drive offensive security across ClickHouse’s products by identifying vulnerabilities, triaging reports, and improving security assurance practices such as pentesting, vulnerability assessments, fuzzing, and bug bounty programs. Plan and execute internal red team exercises and penetration tests, assess AI/LLM attack surfaces, and build agentic tooling for reconnaissance and exploit chaining. Partner with detection engineering on control effectiveness while handling incidents and scaling security processes through automation.
Location: EMEA
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Identify security gaps and vulnerabilities across ClickHouse offerings and triage vulnerabilities from bug bounty, responsible disclosure, and GitHub issues.
  • •Improve security assurance activities including pentests, vulnerability assessments, bug bounty programs, and fuzzing.
  • •Plan and execute internal red team assessments and penetration tests across infrastructure and cloud environments.
  • •Assess AI/LLM-specific attack surface across ClickHouse AI-powered features and internal AI tooling.
  • •Handle information security events and incidents and develop processes, tooling, and automation to scale security and mitigate risks.

Pay and Benefits

Perks:Health InsuranceEquityRemote WorkHome OfficeFlexible Time

Key Requirements

  • •7+ years of experience in pentesting, red teaming, and product security.
  • •Experience performing threat assessments and offensive security engagements across cloud, network, and application environments.
  • •Hands-on ability to conduct internal red teaming, penetration testing, and adversary simulation.
  • •Ability to design adversary scenarios grounded in real threat intelligence tailored to a multi-tenant cloud data platform.
  • •Experience building or adapting agentic and LLM-assisted tooling (e.g., recon automation, exploit chaining, fuzzing harnesses) and knowing where AI helps vs adds noise.
Experience:7+ yearsCloud securityOffensive securityRed teamingBug bountyMulti-tenantAI/LLM security
Skills:CommunicationAdvisoryAnalysisProblem-solvingAutomation
Certifications:AWSGCPAzureOSCPOSCEOSEPOSWE
Tech Stack:AWSGCPAzureKubernetesCiliumStatic code analysisDynamic code analysisSoftware composition analysisSBOMOWASP SAMMClient fuzzingNetwork fuzzingFuzzingLLMAI

Company Brief

ClickHouse
Develops ClickHouse, a high-performance open-source columnar database for real-time analytics, enabling fast querying and processing of large volumes of data for analytics, monitoring, and business intelligence workloads.
Industry: Data Infrastructure
Headquarters: Menlo Park, United States
Founded: 2016
WebsiteLinkedIn