Offensive Security Engineer

ClickHouse
Netherlands
Workplace: RemoteFull timeFunction: CybersecurityExperience: 7+ yearsSkills: ["Communication","Threat assessment","Security automation","Incident response","Engineering collaboration"]

Identify and triage security gaps across web, API, and server-client assets, including memory vulnerabilities found through bug bounty, responsible disclosure, and GitHub issues. Lead security assurance work such as pentests, vulnerability assessments, fuzzing, and internal red-team assessments against ClickHouse infrastructure and cloud environments. Assess AI/LLM attack surfaces, build agentic reconnaissance and LLM-assisted fuzzing tooling, and partner with detection engineering to improve control effectiveness and incident response.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
ClickHouse
ClickHouse
3 days ago

Offensive Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 20 hours agoStatus: Live

Job Summary

Identify and triage security gaps across web, API, and server-client assets, including memory vulnerabilities found through bug bounty, responsible disclosure, and GitHub issues. Lead security assurance work such as pentests, vulnerability assessments, fuzzing, and internal red-team assessments against ClickHouse infrastructure and cloud environments. Assess AI/LLM attack surfaces, build agentic reconnaissance and LLM-assisted fuzzing tooling, and partner with detection engineering to improve control effectiveness and incident response.
Location: Netherlands
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Identify security gaps and vulnerabilities across all ClickHouse offerings, triaging reports from bug bounty, responsible disclosure, and GitHub issues.
  • •Improve security assurance activities including pentests, vulnerability assessments, bug bounty programs, and fuzzing.
  • •Plan and execute internal red team assessments and penetration tests against ClickHouse infrastructure and cloud environments with realistic adversary scenarios.
  • •Assess AI/LLM-specific attack surface (e.g., prompt injection, model/data exfiltration, unsafe agentic tool use patterns) across ClickHouse AI features and internal tooling.
  • •Develop and operate agentic tooling for reconnaissance, exploit-chaining/attack-path discovery, and LLM-assisted fuzzing; partner with detection engineering and handle security incidents.

Pay and Benefits

Equity and Bonus:Equity
Perks:Health InsuranceEquityPaid LeaveHome Office

Key Requirements

  • •7+ years of experience in pentesting, red teaming, and product security.
  • •Hands-on experience conducting offensive security engagements (internal red teaming, penetration testing, adversary simulation) across cloud, network, and application environments.
  • •Ability to support engineering/product teams with threat assessments, assurance activities, and advisory (and sometimes implementation) across distributed systems.
  • •Experience designing adversary scenarios grounded in real threat intelligence tailored to a multi-tenant cloud data platform.
  • •Strong knowledge of cloud environments and engineering security tooling, including Kubernetes and offensive testing/automation (e.g., static/dynamic analysis, fuzzing, SBOM/SCA, OWASP SAMM).
Experience:7+ years
Education:
Skills:CommunicationThreat assessmentSecurity automationIncident responseEngineering collaboration
Certifications:AWSGCPAzureOSCPOSCEOSEPOSWE
Languages:English
Tech Stack:AWSGCPAzureKubernetesCiliumLLMPrompt injectionFuzzingSBOMOWASP SAMMSoftware composition analysis

Company Brief

ClickHouse
Develops ClickHouse, a high-performance open-source columnar database for real-time analytics, enabling fast querying and processing of large volumes of data for analytics, monitoring, and business intelligence workloads.
Industry: Data Infrastructure
Headquarters: Menlo Park, United States
Founded: 2016
WebsiteLinkedIn