Product Security Engineer
ClickHouse
seniorpermanentsecurityengineering-management United States 55 days ago via LinkedIn
169,150 - 225,000 USD/annual
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Product SecurityThreat ModelingSecurity AssuranceVulnerability ManagementBug BountyFuzzingStatic Code AnalysisDynamic Code AnalysisKubernetesAWS
About the role
Role Overview
Product Security Engineer at ClickHouse. Join the Security Team to improve the security posture of ClickHouse Cloud and open-source offerings by partnering with engineering and product teams on secure design, assurance, tooling, and incident response.
Responsibilities
- Collaborate with engineering and product on building and improving product features with a focus on:
- Threat modeling
- Security assurance and secure implementation
- Examples: secure key management, passwordless authentication, M2M authentication, sandboxing, and compute/network/storage isolation
- Identify and triage security gaps and vulnerabilities across ClickHouse Cloud and OSS
- Handle reports from bug bounty, responsible disclosure, and GitHub Issues (web, API, server-client assets)
- Address low-level memory issues such as heap/buffer overflows
- Improve and run security assurance activities, including:
- Pentests, vulnerability assessments, bug bounty programs, and fuzzing
- Drive adoption and usage of engineering security tools:
- Static/dynamic code analysis
- Dependency checks
- Code licensing compliance
- Working knowledge of Snyk, Semgrep, and GitHub CodeQL
- Strengthen engineering-security collaboration via process and technology improvements
- Handle information security events and incidents across ClickHouse products and services
- Build processes, tooling, and automation to scale security and mitigate business risks
Requirements
- Experience supporting engineering and product implementation through threat assessments, security assurance, and advisory (and sometimes implementation)
- Strong knowledge/experience with one or more cloud providers (AWS, GCP, Azure) plus Kubernetes
- Experience with security tooling/processes such as:
- Static/dynamic code analysis
- Software composition analysis
- SBOM
- OWASP SAMM
- Client and network fuzzing tools
- Significant development and automation experience; C++ development preferred
- Security as code mindset focused on automation and scaling
Bonus Points
- BS/MS/PhD in Computer Science or related field
- Prior open-source security contributions
- Security or cloud certifications (AWS/GCP/Azure)
Compensation
- United States typical starting salary range: $169,150 – $191,250 USD
- Premium markets (e.g., San Francisco Bay Area, NYC Metro): $169,150 – $225,000 USD
About ClickHouse
ClickHouse is a fast-growing cloud company focused on real-time analytics, data warehousing, observability, and AI workloads. It serves thousands of customers and provides a platform widely adopted by both established brands and AI innovators. The company is backed by recent Series D funding and aims to transform how companies use data.
Scraped 7/30/2026