ClickHouse is an open-source, column-oriented OLAP database management system.
Manager, Information Security
Location
Worldwide
Posted
6 days ago
Salary
$180K - $300K / year
Seniority
Lead
Job Description
Manager, Information Security
ClickHouse
Role Description This role sits at the intersection of product management, security engineering, compliance, legal, and cloud infrastructure. You will own the information security strategy for regulated cloud offerings, certifications, sovereign cloud deployments, and specialized regional offerings that enable customers to operate ClickHouse in highly restricted environments. - Define and execute the multi-year roadmap for achieving ClickHouse for Government certifications (FEDRAMP, DOD-IL, StateRAMP, CJIS, etc). - Partner closely with Security, Engineering, Compliance, Legal, GTM, and Operations teams to ensure ClickHouse Cloud meets the requirements of frameworks including SOC 2, ISO 27001/27701, HIPAA, PCI DSS, and government-specific standards (FIPS, Common Criteria / Protection Profile, NIST SP800-171, CMMC, Sec 508/VPAT, DISA STIG). - Translate complex regulatory and security requirements into scalable product capabilities across identity and access management (IAM), encryption, key management, audit logging, access controls, and operational security. - Drive product requirements for FIPS-compliant cryptographic modules and government-specific deployment and licensing models. - Establish long-term strategy for enterprise security capabilities that support regulated industries worldwide. - Own the product strategy and roadmap for sovereign cloud offerings, including the European Sovereign Cloud (ESC), Kingdom of Saudi Arabia (KSA), and future sovereign cloud regions. - Own and deliver long-term Five-Eyes Sovereign Cloud Deployments. - Define product capabilities that address data residency, personnel access controls, customer-managed encryption, and operational sovereignty requirements. - Work with cloud providers and strategic partners to enable deployments in restricted and regulated environments, including offerings such as Assured Workloads and sovereign cloud frameworks. - Partner with legal, compliance, and regional stakeholders to navigate evolving global regulations and regional market requirements. Qualifications - 8+ years of product management experience, including significant experience building cloud infrastructure, platform, security, or enterprise SaaS products. - Deep understanding of FedRAMP certification requirements and the challenges of operating compliant multi-tenant cloud services. - Strong technical understanding of modern cloud architectures across AWS, Azure, and GCP. - Experience with security domains including IAM, network isolation, private connectivity, encryption, key management systems (KMS/BYOK), audit logging, and access controls. - Familiarity with global data residency and sovereignty requirements, including GDPR and emerging regional regulatory frameworks. - Demonstrated success leading complex cross-functional initiatives involving engineering, security, compliance, legal, and GTM teams. - Strong written and verbal communication skills, with the ability to influence both technical and executive audiences. Requirements - Experience with US Government Security and Risk Frameworks (FEDRAMP, DOD IL, RMF, etc). - Experience with sovereign clouds, government cloud regions, and regulated industry offerings. - Background in databases, data platforms, analytics, or infrastructure software. - Experience commercializing open-source technologies for enterprise and government customers. - Familiarity with FIPS 140-2/140-3 validation requirements and government procurement processes. Benefits - Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in over 20 countries. - Healthcare - Employer contributions towards your healthcare. - Equity in the company - Every new team member who joins our company receives stock options. - Time off - Flexible time off in the US, generous entitlement in other countries. - A $500 Home office setup if you’re a remote employee. - Global Gatherings – We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites. - Culture - We All Shape It - As part of a rapidly scaling startup, you will be instrumental in shaping our culture.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Assess IT security risks and coordinate appropriate countermeasures. • Develop and maintain network and security standards. • Support implementation of regulatory requirements such as ISO 27001, NIS2 and BSI IT-Grundschutz. • Manage and continuously optimize SIEM, EDR and XDR solutions. • Develop detection rules, use cases, alerts and automated response measures. • Conduct security reviews and support internal and external audits. • Monitor current threat landscapes and evaluate new security technologies and attack techniques.
Full Stack Engineer – IAM Security
PROSTAFF Schweiz GmbHPROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.
Role Description Für ein langfristiges Entwicklungsprojekt im Bereich Identity & Access Management suchen wir einen erfahrenen Senior Software Engineer Full Stack. Der Schwerpunkt der Position liegt auf der Analyse und Behebung von Security Vulnerabilities innerhalb einer modernen IAM-Anwendung. - Analyse und Behebung von Vulnerabilities im IAM-Umfeld - Weiterentwicklung und Optimierung bestehender Full-Stack-Anwendungen - Umsetzung sicherheitsrelevanter Anpassungen im Backend und Frontend - Entwicklung mit Java, Spring Boot, React und TypeScript - Betrieb und Deployment von Anwendungen auf einer OpenShift-Plattform - Zusammenarbeit mit Security-, Architektur-, DevOps- und IAM-Spezialisten - Durchführung von Code Reviews sowie nachhaltige Dokumentation der Änderungen - Sicherstellung von Qualität, Stabilität und Wartbarkeit der Software Qualifications - Mehrjährige Erfahrung in der Full-Stack-Softwareentwicklung - Sehr gute Kenntnisse in Java und Spring Boot - Fundierte Erfahrung mit React, JavaScript und TypeScript - Erfahrung mit OpenShift, Kubernetes oder vergleichbaren Containerplattformen - Kenntnisse in der Analyse und Behebung von Software-Schwachstellen - Verständnis für Secure Coding, Dependency Management und Application Security - IAM-Erfahrung ist von Vorteil, jedoch keine zwingende Voraussetzung - Selbstständige, kommunikative und lösungsorientierte Arbeitsweise - Deutschkenntnisse sind bevorzugt; sehr gute Englischkenntnisse sind ebenfalls möglich Company Description PROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.
Cybersecurity Engineer
RainFocusManage your virtual, in-person, and hybrid events seamlessly with the world’s only insight-driven platform.
• Safeguard organization's digital assets and ensure information systems' confidentiality, integrity, and availability. • Identify and mitigate security vulnerabilities. • Monitor security incidents. • Contribute to developing security policies and procedures.
• Perform holistic tabletop reviews covering both technical and non-technical risk across OT environments • Analyze for areas of negative impact, high risk, and single points of failure (SPOF) within sensitive, legacy networks • Identify vulnerabilities and weaknesses across Operational Technology environments, including Industrial Control Systems (ICS), SCADA, and field devices • Assess legacy and sensitive networks where conventional testing methods carry unacceptable operational risk • Support OT clients with security program improvements, identifying which critical controls are needed • Contribute to the maturity of Packetlabs' OT testing methodology and practice • Help raise the standard of OT security work across the firm




