ClickHouse logo
ClickHouse

ClickHouse is an open-source, column-oriented OLAP database management system.

Manager, Information Security

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 51-200Since 2016H1B SponsorCompany SiteLinkedIn

Location

Worldwide

Posted

6 days ago

Salary

$180K - $300K / year

Seniority

Lead

Job Description

Manager, Information Security

ClickHouse

Role Description This role sits at the intersection of product management, security engineering, compliance, legal, and cloud infrastructure. You will own the information security strategy for regulated cloud offerings, certifications, sovereign cloud deployments, and specialized regional offerings that enable customers to operate ClickHouse in highly restricted environments. - Define and execute the multi-year roadmap for achieving ClickHouse for Government certifications (FEDRAMP, DOD-IL, StateRAMP, CJIS, etc). - Partner closely with Security, Engineering, Compliance, Legal, GTM, and Operations teams to ensure ClickHouse Cloud meets the requirements of frameworks including SOC 2, ISO 27001/27701, HIPAA, PCI DSS, and government-specific standards (FIPS, Common Criteria / Protection Profile, NIST SP800-171, CMMC, Sec 508/VPAT, DISA STIG). - Translate complex regulatory and security requirements into scalable product capabilities across identity and access management (IAM), encryption, key management, audit logging, access controls, and operational security. - Drive product requirements for FIPS-compliant cryptographic modules and government-specific deployment and licensing models. - Establish long-term strategy for enterprise security capabilities that support regulated industries worldwide. - Own the product strategy and roadmap for sovereign cloud offerings, including the European Sovereign Cloud (ESC), Kingdom of Saudi Arabia (KSA), and future sovereign cloud regions. - Own and deliver long-term Five-Eyes Sovereign Cloud Deployments. - Define product capabilities that address data residency, personnel access controls, customer-managed encryption, and operational sovereignty requirements. - Work with cloud providers and strategic partners to enable deployments in restricted and regulated environments, including offerings such as Assured Workloads and sovereign cloud frameworks. - Partner with legal, compliance, and regional stakeholders to navigate evolving global regulations and regional market requirements. Qualifications - 8+ years of product management experience, including significant experience building cloud infrastructure, platform, security, or enterprise SaaS products. - Deep understanding of FedRAMP certification requirements and the challenges of operating compliant multi-tenant cloud services. - Strong technical understanding of modern cloud architectures across AWS, Azure, and GCP. - Experience with security domains including IAM, network isolation, private connectivity, encryption, key management systems (KMS/BYOK), audit logging, and access controls. - Familiarity with global data residency and sovereignty requirements, including GDPR and emerging regional regulatory frameworks. - Demonstrated success leading complex cross-functional initiatives involving engineering, security, compliance, legal, and GTM teams. - Strong written and verbal communication skills, with the ability to influence both technical and executive audiences. Requirements - Experience with US Government Security and Risk Frameworks (FEDRAMP, DOD IL, RMF, etc). - Experience with sovereign clouds, government cloud regions, and regulated industry offerings. - Background in databases, data platforms, analytics, or infrastructure software. - Experience commercializing open-source technologies for enterprise and government customers. - Familiarity with FIPS 140-2/140-3 validation requirements and government procurement processes. Benefits - Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in over 20 countries. - Healthcare - Employer contributions towards your healthcare. - Equity in the company - Every new team member who joins our company receives stock options. - Time off - Flexible time off in the US, generous entitlement in other countries. - A $500 Home office setup if you’re a remote employee. - Global Gatherings – We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites. - Culture - We All Shape It - As part of a rapidly scaling startup, you will be instrumental in shaping our culture.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1-10H1B No Sponsor

• Assess IT security risks and coordinate appropriate countermeasures. • Develop and maintain network and security standards. • Support implementation of regulatory requirements such as ISO 27001, NIS2 and BSI IT-Grundschutz. • Manage and continuously optimize SIEM, EDR and XDR solutions. • Develop detection rules, use cases, alerts and automated response measures. • Conduct security reviews and support internal and external audits. • Monitor current threat landscapes and evaluate new security technologies and attack techniques.

Germany
€80K - €120K / year
PROSTAFF Schweiz GmbH logo

Full Stack Engineer – IAM Security

PROSTAFF Schweiz GmbH

PROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.

Full TimeRemoteTeam 201-500

Role Description Für ein langfristiges Entwicklungsprojekt im Bereich Identity & Access Management suchen wir einen erfahrenen Senior Software Engineer Full Stack. Der Schwerpunkt der Position liegt auf der Analyse und Behebung von Security Vulnerabilities innerhalb einer modernen IAM-Anwendung. - Analyse und Behebung von Vulnerabilities im IAM-Umfeld - Weiterentwicklung und Optimierung bestehender Full-Stack-Anwendungen - Umsetzung sicherheitsrelevanter Anpassungen im Backend und Frontend - Entwicklung mit Java, Spring Boot, React und TypeScript - Betrieb und Deployment von Anwendungen auf einer OpenShift-Plattform - Zusammenarbeit mit Security-, Architektur-, DevOps- und IAM-Spezialisten - Durchführung von Code Reviews sowie nachhaltige Dokumentation der Änderungen - Sicherstellung von Qualität, Stabilität und Wartbarkeit der Software Qualifications - Mehrjährige Erfahrung in der Full-Stack-Softwareentwicklung - Sehr gute Kenntnisse in Java und Spring Boot - Fundierte Erfahrung mit React, JavaScript und TypeScript - Erfahrung mit OpenShift, Kubernetes oder vergleichbaren Containerplattformen - Kenntnisse in der Analyse und Behebung von Software-Schwachstellen - Verständnis für Secure Coding, Dependency Management und Application Security - IAM-Erfahrung ist von Vorteil, jedoch keine zwingende Voraussetzung - Selbstständige, kommunikative und lösungsorientierte Arbeitsweise - Deutschkenntnisse sind bevorzugt; sehr gute Englischkenntnisse sind ebenfalls möglich Company Description PROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.

Switzerland
RainFocus logo

Cybersecurity Engineer

RainFocus

Manage your virtual, in-person, and hybrid events seamlessly with the world’s only insight-driven platform.

Full TimeRemoteTeam 201-500Since 2013H1B Sponsor

• Safeguard organization's digital assets and ensure information systems' confidentiality, integrity, and availability. • Identify and mitigate security vulnerabilities. • Monitor security incidents. • Contribute to developing security policies and procedures.

Utah
Packetlabs logo

Ethical Hacker – OT Security

Packetlabs

Ready to strengthen your security posture?

Full TimeRemoteTeam 51-200Since 2011H1B No Sponsor

• Perform holistic tabletop reviews covering both technical and non-technical risk across OT environments • Analyze for areas of negative impact, high risk, and single points of failure (SPOF) within sensitive, legacy networks • Identify vulnerabilities and weaknesses across Operational Technology environments, including Industrial Control Systems (ICS), SCADA, and field devices • Assess legacy and sensitive networks where conventional testing methods carry unacceptable operational risk • Support OT clients with security program improvements, identifying which critical controls are needed • Contribute to the maturity of Packetlabs' OT testing methodology and practice • Help raise the standard of OT security work across the firm

Texas
$80K - $120K / year