ClickHouse, Inc. is a database management system that allows users to generate analytical reports using real-time SQL queries. The company’s technology works faster than traditio
Product Security Engineer
Location
Netherlands
Posted
178 days ago
Salary
0
Seniority
Senior
Job Description
Product Security Engineer
ClickHouse
• Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing • Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL) • Nurture the engineering - security relationship, identify and implement process and technology improvements • Handle information security events and incidents across ClickHouse products and services • Develop processes, tooling and automation to scale security processes and mitigate risks to the business
Job Requirements
- Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
- Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium
- Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools)
- Significant development and automation experience, ability to work with C++ code
- Security as code mindset, with focus on solving problems with automation and scale in mind.
Benefits
- Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in 20 countries.
- Healthcare - Employer contributions towards your healthcare.
- Equity in the company - Every new team member who joins our company receives stock options.
- Time off - Flexible time off in the US, generous entitlement in other countries.
- A $500 Home office setup if you’re a remote employee.
- Global Gatherings – We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Cybersecurity Engineer
MindvalleyThe Future of Education- Mindvalley Membership lets you access the best coaches, training and programs on the planet
• Lead design, deployment, and tuning of Mindvalley’s cybersecurity tooling (SIEM, CSPM, vulnerability scanners, endpoint detection, and SaaS monitoring). • Manage and optimize GCP Security Command Center, Google Workspace, Okta/Auth0, and integrations across the SaaS ecosystem. • Automate detection and response using scripting / automation tools. • Operate the full lifecycle of vulnerability management. Discovery, triage, remediation coordination, validation, and metrics reporting. • Perform targeted penetration tests and purple-team simulations against high-value assets. • Correlate findings across multiple tools and automate risk reporting dashboards. • Continuously harden GCP configurations, GWS configurations and CI/CD pipelines. • Build secure defaults and reusable controls for Engineering teams (e.g., API authentication patterns, secret management, encryption policies). • Partner with Product and AI Innovation teams to embed secure development practices and data protection into new services. • Administer and optimize Okta/Auth0, ensuring robust identity governance, adaptive MFA, and automation of joiner–mover–leaver workflows. • Review and harden access policies across Google Workspace, GitHub, Slack, and internal apps. • Design alert enrichment, automated ticket creation, and response playbooks. • Act as incident commander for security incidents, coordinating detection, containment, and recovery. • Maintain runbooks, logging pipelines, and retrospectives that feed back into continuous improvement. • Support audits, vendor security assessments, and risk management processes. • Maintain key security KPIs and dashboards for leadership reporting.
• Enable and guide teams to adopt DevSecOps practices, ensuring security is built into CI/CD and infrastructure pipelines through shared standards, tooling, and best practices. • Work with IT Manager on company identity and access management: IdP configuration, user/group organization, and automation via cross-platform synchronization and SAML. • Administer and automate GitHub Enterprise and JFrog management (users, teams, org policies, and compliance) using IaC. • Operate and tune SIEM, DLP, and centralized logging systems; define and maintain detection and alerting rules. • Review audit logs and security telemetry across cloud, SaaS, and developer systems for anomalies and compliance issues. • Work with IT Manager to build automated onboarding/offboarding and access reviews aligned with least-privilege principles. • Collaborate with platform, product, and engineering teams to design secure-by-default workflows, infrastructure, and deployment practices, ensuring consistent security controls across products. • Conduct risk assessments, tabletop exercises, and threat simulations in concert with engineering and operations teams, ensuring security readiness is collaborative and integrated. • Lead and coordinate penetration testing efforts, including scoping, vendor engagement, and remediation tracking. • Support SOC 2 and related compliance efforts through control validation and evidence collection. • Help respond to and complete customer and vendor security questionnaires, collaborating with compliance and engineering teams to ensure accurate and timely answers
Information Security Auditor
SecurityPalApplied AI transforming Customer Assurance (CAx): security assessments with precision & speed like never before.
• Lead a team that provides comprehensive vendor assessments to evaluate security risks and compliance with standards and regulations • Serve as the main point of contact for clients, ensuring clear communication, understanding of requirements, and satisfaction with services provided • Develop and implement assessment methodologies tailored to client needs and industry best practices • Collaborate with clients to identify their security needs and customize assessment approaches accordingly • Analyze assessment findings and provide strategic security recommendations to clients to mitigate risks effectively • Generate detailed assessment reports outlining findings, risk levels, and recommendations for remediation • Present findings to clients in a clear, concise, and actionable manner • Foster strong client relationships by proactively addressing concerns, anticipating needs, and providing exceptional service • Act as a trusted advisor on security matters • Collaborate with clients during security incidents to provide technical guidance and support incident response efforts • Perform comprehensive risk assessments beyond vendor assessments, such as enterprise-wide risk assessments, to identify and prioritize risks across different business units or systems • Collaborate with other teams within the organization (e.g., IT, legal, compliance) on security-related initiatives such as policy development, security awareness programs, or incident response exercises • Conduct readiness assessments for ISO, SOC 2, Fedramp Compliance, evaluating current processes, controls, and documentation to identify gaps and areas needing improvement to achieve compliance and certification
Senior Customer Success Manager – Identity Security
SaviyntThe #1 Converged Identity Platform with Intelligent Access Governance for Employees, Third Parties & Machines.
• Serve as the primary point of contact for customers. • Participate with the Sales team to provide a strong customer-focused sales, orientation, and launch engagement process. • Develop excellent relationship up to customer’s C-level executives. • Develop a deep understanding of customer’s identity and access governance landscape and business challenges and advise on possible solutions delivered by the Saviynt product. • Develop trusting relationship with customers and executive sponsors to drive product adoption and ensure they achieve full business value. • Partner with internal Saviynt teams to align product development and support activities with the customer's business case and strategy. • Represent the customer in internal prioritization process. • Proactive preparation for important events (go-lives, releases, etc..) • Develop and maintain an accurate account plan / success plan for each customer in the portfolio. • Develop and monitor key performance indicators and review monthly for necessary corrective actions. • Monitor and identify utilization trends, provide recommendations based on risk and customers’ needs. • Plan education for customers on new features and releases. • Manage renewal pipeline including potential at-risk customers to remediate and ensure a successful renewal. • Assist with the management of delivery projects. • Assist with transformation and process improvements across the organization. • Act as the voice of the customer and collect feedback to drive continuous improvement across all areas including product.




