Job Closed
This listing is no longer active.
ClickHouse is an open-source, column-oriented OLAP database management system.
Principal Product Manager, Security & Compliance
Location
United States
Posted
6 days ago
Salary
$180K - $300K / year
Seniority
Lead
Job Description
Principal Product Manager, Security & Compliance
ClickHouse
Role Description We are seeking a high-impact Principal Product Manager to lead ClickHouse’s strategy for highly regulated sectors, specifically focusing on FedRAMP compliance and the global expansion of our Sovereign Cloud offerings. As ClickHouse Cloud scales to support the world’s largest enterprise and public-sector customers, you will be responsible for ensuring our platform meets the most stringent security, isolation, and data residency requirements. This role sits at the intersection of product strategy, security engineering, and compliance. You will own the roadmap for achieving FedRAMP certification and define the product architecture for deployment in restricted environments like the European Sovereign Cloud (ESC) and the Kingdom of Saudi Arabia (KSA). Qualifications - Experience: 8+ years of product management experience, with at least 3 years deeply focused on cloud security, infrastructure, or enterprise SaaS compliance. - Domain Expertise: Deep understanding of FedRAMP (Moderate/High) requirements and the process of achieving certification for a multi-tenant cloud service. - Technical Depth: Strong grasp of cloud architectures (AWS, GCP, Microsoft Azure), including VPC peering, private endpoints, encryption (BYOK/KMS), and multi-tenant security. - Regulatory Knowledge: Familiarity with global data sovereignty trends and regulations such as GDPR, and their impact on cloud region strategy. - Communication: Exceptional ability to explain complex compliance and technical concepts to both engineering teams and executive stakeholders. - Leadership: Proven track record of working cross-functionally across legal, security, operations, and sales to launch products in regulated markets. Requirements - Define and execute the multi-year roadmap to achieve FedRAMP Moderate certification and, eventually, FedRAMP High certification for ClickHouse product offerings. - Partner with engineering and the compliance team to ensure product capabilities support SOC 2, ISO 27001, HIPAA, PCI and other frameworks. - Translate complex federal security requirements into actionable product specifications for Identity and Access Management (IAM), encryption, and audit logging, personnel access. - Serve as the primary product nominee for FIPS compliance modules and government-specific licensing models. - Lead the product strategy for the European Sovereign Cloud (ESC) and KSA regions, navigating prerequisites including legal, partnership (e.g., CNTXT), and infosec requirements. - Define data residency and personnel control requirements (e.g., in-country staff, cleared personnel) to support organizational data sovereignty. - Collaborate with AWS, Microsoft Azure and Google Cloud on specialized deployment packages like Assured Workloads for restricted jurisdictions. Benefits - Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in over 20 countries. - Healthcare - Employer contributions towards your healthcare. - Equity in the company - Every new team member who joins our company receives stock options. - Time off - Flexible time off in the US, generous entitlement in other countries. - A $500 Home office setup if you’re a remote employee. - Global Gatherings - We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites. - Culture - As part of a rapidly scaling start up, you will be instrumental in shaping our culture.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Alternate Facility Security Officer – AFSO
Initiate Government Solutions, LLC.We provide the framework to build solid foundations that allow you to leverage and grow your revenue and capabilities.
• Serve as a point of contact for all security matters related to government contracts • Ensure compliance with the National Industrial Security Program Operating Manual (NISPOM) and other relevant security requirements • Maintains and updates the company’s Standard Practices and Procedures (SPP) and Insider Threat Program (ITP) documents as required by DCSA, NISPOM or standard security best practices • Conduct security briefings, debriefings, and training for employees with security clearances • Manage personnel clearances, security documentation, and access to classified information through DISS and the National Background Investigation Services (NBIS) • Support physical security measures for the facility, including badging, visitor access, and secure storage • Perform self-inspections and coordinate with Defense Counterintelligence and Security Agency (DCSA) representatives for audits and inspections • Manage the National Industrial Security System (NISS) to maintain facility security information, upload applicable DD254s, submit applicable Change Conditions for the company, and monitor notifications to the company profile • Investigate and report security violations, follow through on incident reports, and prepare reports specifying preventive action to be taken • Support Ad Hoc projects as requested
Role Description Pixel Health is seeking a driven, relationship-oriented Healthcare IT Sales Executive to drive the Provider Groups sales motion across New England and to carry the adjacent FQHC consulting pipeline. This is a full-time, client-facing role responsible for: - Generating and qualifying pipeline - Booking discovery meetings - Managing opportunities through a five-stage sales cycle - Closing fixed cost-per-employee managed services contracts with specialty practices, physician groups, and ambulatory care organizations - Consulting-first Strategy & Transformation engagements with Federally Qualified Health Centers (FQHCs) and community hospitals The role reports to the Executive Vice President of Sales and works alongside three senior executives who provide sponsor-level relationship depth at key deal stages. Qualifications - 5+ years of B2B sales experience, preferably in healthcare IT, managed services, SaaS, or health technology - Demonstrated knowledge of provider group operations, physician practice management, and healthcare IT environments - Familiarity with clinical systems — EHR platforms (especially Epic and Epic Light), telehealth, UCaaS/CCaaS, and security/compliance frameworks (HIPAA, HITECH) - Familiarity with the FQHC operating model (HRSA funding, 330 grants, UDS reporting) is preferred - Strong presentation skills — able to credibly represent Pixel Health in executive-level conversations and group settings - Self-directed and comfortable managing a full sales cycle independently, from prospecting through deal close - Proficiency with CRM platforms; disciplined pipeline hygiene - Located in or able to travel across New England — frequent in-region travel required Responsibilities - Identify, research, and engage target Provider Group organizations (200–1,000 employees) across MA, CT, RI, NH, VT, and ME - Execute personalized outbound outreach to Practice Leaders, COOs, Operations Directors, and FQHC Executive Directors - Book and conduct discovery conversations and coordinate onsite/remote technology health assessments with qualified prospects; produce the one-page IT snapshot deliverable - Support preparation and delivery of customized MSP proposals built on the fixed monthly cost-per-employee model and projected ROI versus current spend - Manage the CRM pipeline with disciplined stage progression, activity logging, and forecasting - Coordinate and attend regional dinner events, lunch-and-learns, and co-branded T-Mobile events (Greater Boston and Hartford in August 2026, ongoing quarterly cadence) - Progress T-Mobile co-sell opportunities with 5G cellular partners to proposal stage in coordination with the 5G Sales Lead - Own the FQHC consulting motion: qualify Strategy & Transformation opportunities (digital maturity assessments, Epic Light readiness, IT governance, fractional CIO), structure fixed-fee engagements aligned to grant cycles, and progress consulting clients toward full MSP adoption - Nurture long-cycle prospects and FQHC consortium relationships (e.g., multi-FQHC Epic-deployment alliances) through consistent follow-up and content sharing - Collaborate with executive sponsors to bring senior leadership into validation-stage meetings and reference calls - Develop referrals from new customers Benefits - Competitive Salary - Flexible Hours - PTO - Paid Health, Dental and Vision Insurance - Matching 401k Plan - Great team-oriented work environment Salary $101,000.00 annual base salary plus commission
Role Description We're looking for a skilled and motivated Cloud Security Validation Engineer with strong experience in Java, using Selenide or Selenium, to join our team at Upwind- a fast-growing cloud security startup. This role is focused primarily on automation (80%), with some manual testing (20%). This is a startup environment: priorities shift quickly, release cycles are tight, and you'll often be juggling several testing efforts at once. The ideal candidate thrives under this kind of pressure- someone who is stress-resilient, comfortable working in short time frames and rapid iteration cycles, and skilled at prioritizing effectively when multiple tasks compete for attention. The ideal candidate has solid knowledge of software testing methodologies, experience building and maintaining automation frameworks for web applications, and a genuine interest in cloud computing and security- since our product operates directly in that space. This is a fully remote position. Responsibilities - Develop and maintain automated test scripts using Java (Selenide or Selenium) for web applications. - Collaborate with cross-functional teams (dev, product, DevOps) to understand fast-changing requirements and ensure adequate test coverage under tight deadlines. - Design, implement, and execute automated test cases to verify functionality, performance, and scalability of web applications. - Identify, prioritize, and report defects, working closely with development teams to drive resolution — often across multiple concurrent workstreams. - Participate in test planning, estimation, and review sessions, adapting quickly as priorities evolve. - Continuously improve and refactor automation test suites for speed, stability, and maintainability. - Apply sound judgment to prioritize testing efforts when time and resources are constrained. - Stay current with industry trends in test automation, cloud technologies, DevOps practices, and cybersecurity. Requirements - Minimum 1 year of commercial (paid, professional) experience as an AQA Engineer or similar role — required. - Strong proficiency in Java and familiarity with Selenide or Selenium WebDriver. - Basic understanding of OOP concepts. - Experience developing and executing automated test suites for web applications. - Proficiency in web technologies: HTML, CSS, JavaScript, and HTTP protocols. - Strong analytical and problem-solving skills, with excellent attention to detail and the ability to prioritize effectively under pressure. - Demonstrated ability to work in a fast-paced, high-ambiguity startup environment — comfortable handling multiple parallel tasks and shifting priorities without losing quality. - Stress resilience and adaptability; able to stay focused and effective under short deadlines.
AI Security Engineer
Bright Vision TechnologiesBright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications.
Role Description We are seeking an AI Security Engineer to lead the design and implementation of security controls, threat models, and incident response capabilities specifically tailored to AI and machine learning systems. The role addresses the unique security challenges posed by LLMs, model APIs, training data pipelines, and AI-powered applications, including prompt injection, model abuse, data exfiltration, and supply chain risks. The ideal candidate has strong security engineering fundamentals and a deep understanding of how modern AI systems work in practice, with hands-on experience designing defenses for both AI-powered applications and the AI infrastructure that supports them. Key Responsibilities - Define and implement security controls specifically targeting LLM and AI-powered application risks. - Build threat models for AI systems, including prompt injection, jailbreaks, data exfiltration, and abuse patterns. - Design and deploy guardrails, content filters, and policy enforcement layers around model endpoints. - Implement runtime detection and response capabilities for adversarial prompts and abusive behavior. - Secure training and fine-tuning pipelines, including data provenance, integrity, and access controls. - Design controls for sensitive data handling, retention, and redaction in LLM workflows. - Lead red-team exercises against AI systems and drive remediation of identified weaknesses. - Evaluate and harden third-party AI services and open-source AI components used internally. - Implement identity, authorization, and tenant-isolation patterns for multi-tenant AI services. - Drive supply chain security for ML artifacts including weights, datasets, and inference dependencies. - Collaborate with privacy, legal, and compliance teams to ensure AI systems meet regulatory obligations. - Develop monitoring, logging, and detection strategies tailored to AI workloads. - Lead incident response for AI-specific security events and drive durable improvements. - Stay current with adversarial ML, LLM security research, and emerging regulatory developments. Qualifications - Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or a related discipline. - Six or more years of security engineering experience, including significant work on AI or ML systems. - Strong understanding of LLM internals, modern AI architectures, and common failure modes. - Hands-on experience designing security controls for AI-powered applications. - Deep knowledge of application security, identity, and cryptography fundamentals. - Experience with threat modeling and security architecture review processes. - Familiarity with adversarial ML, prompt injection, and model abuse research. - Proficiency in Python and at least one systems language. - Strong understanding of cloud security and modern infrastructure controls. - Excellent written and verbal communication skills. Preferred Qualifications - Publications, talks, or CTF participation in AI security topics. - Experience with red-teaming LLM-based products. - Familiarity with privacy-preserving ML techniques such as differential privacy. - Exposure to regulated industries with strict data handling requirements. - Open-source contributions to AI security tooling. Requirements - 100% Remote (Continental United States) - In-house Bright Vision Technologies SOW engagement (no third-party client or vendor) - Salary: $100K - $150K / Annum - Employment Type: Full-time, direct W2 with Bright Vision Technologies (no C2C, no 1099, no third-party) - Long-term, multi-year engagement aligned to the Bright Vision SOW delivery roadmap - No new H1B sponsorship available. H1B transfers welcomed for qualified candidates. How to Apply For immediate consideration, please send your resume to [email protected] or contact us at (908) 505-3899. Learn more about Bright Vision Technologies at www.bvteck.com .


