Enable job alerts via email!

Product Security Engineer

ClickHouse

Canada

Remote

CAD 80,000 - 100,000

Full time

2 days ago
Be an early applicant

Job summary

A leading data solution provider is seeking an experienced security practitioner to enhance security processes across platforms and services. This role involves collaboration with engineering teams to address security gaps and improve product features. The ideal candidate will have knowledge of cloud services and a strong automation mindset. This position can be fully remote anywhere in Canada or the United States.

Benefits

Flexible work environment
Employer contributions towards healthcare
Equity in the company
Flexible time off
Home office setup allowance
Global Gatherings

Qualifications

  • Experience supporting engineering and product implementation efforts.
  • Strong knowledge of cloud service providers (e.g., AWS, GCP, Azure).
  • Experience operating engineering security tools and processes.

Responsibilities

  • Collaborate with engineering on product features focused on security.
  • Identify security gaps and vulnerabilities in ClickHouse Cloud.
  • Drive implementation and usage of engineering security tools.

Skills

Threat modeling
Security assurance activities
Cloud service knowledge
C++ coding
Security as code

Education

BS, MS, or PhD in Computer Science or related field

Tools

Snyk
Semgrep
GitHub CodeQL
Job description

Established in 2009, ClickHouse leads the industry with its open-source column-oriented database system, driven by the vision of becoming the fastest OLAP database globally. The company enables real-time analytical reporting through SQL queries, emphasizing speed in managing escalating data volumes. Enterprises globally rely on ClickHouse Cloud, available as open-source or on AWS, GCP, Azure, and Alibaba.

About the team

The Security Team provides key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. We are looking for an experienced, hands-on security practitioner to drive the adoption of modern security processes and tooling, supporting engineering and product teams to improve the security posture of our platforms and services.

Note: This position can be fully remote anywhere in Canada or the United States.

What you will do:

  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation. Recent examples include secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation.
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage vulnerabilities reported via our bug bounty program, responsible disclosure, and GitHub Issues covering web, API and server-client assets including low level memory issues like heap or buffer overflows.
  • Improve and develop security assurance activities – pentests, vulnerability assessments, bug bounty programs, fuzzing.
  • Drive implementation and usage of engineering security tools – static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL).
  • Nurture the engineering-security relationship, identify and implement process and technology improvements.
  • Handle information security events and incidents across ClickHouse products and services.
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business.

What you bring along:

  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as implementation work across distributed systems covering web, API, client/server assets.
  • Strong knowledge of one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium.
  • Experience implementing and operating engineering security tools and processes (e.g. static/dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools).
  • Significant development and automation experience, ability to work with C++ code.
  • Security as code mindset, with focus on solving problems with automation and scale in mind.

Bonus Points:

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)
Compensation

For roles based in the United States, the typical starting salary range for this position is listed above. In certain locations, such as Los Angeles, CA, the San Francisco Bay Area, CA, the Seattle, WA, Area, and the New York City Metro Area, a premium market range may apply, as listed. These salary ranges reflect what we reasonably and in good faith believe to be the minimum and maximum pay for this role at the time of posting. The actual compensation may be higher or lower than the amounts listed, and the ranges may be subject to future adjustments. An individual’s placement within the range will depend on various factors, including (but not limited to) education, qualifications, certifications, experience, skills, location, performance, and the needs of the business or organization.

Benefits
  • Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in 20 countries.
  • Healthcare - Employer contributions towards your healthcare.
  • Equity in the company - Every new team member who joins our company receives stock options.
  • Time off - Flexible time off in the US, generous entitlement in other countries.
  • A $500 Home office setup - for remote employees.
  • Global Gatherings – Opportunities to engage with colleagues at company-wide offsites.
Culture

Culture - We All Shape It

As part of our first 500 employees, you will be instrumental in shaping our culture.

Learn more about our values, blog posts, or follow us on LinkedIn to discover what’s happening at ClickHouse.

Equal Opportunity & Privacy

ClickHouse provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any type based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Please see our Privacy Statement for more information.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.