Skip to main content
ClickHouse

Offensive Security Engineer

RemoteEMEA
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to Anywhere in EMEA. Set where you work from to check your eligibility.

Core skills

pentestingred teamingfuzzing

Required skills

AWS/GCP/AzureKubernetesCilium

Optional skills

OSCPOSCEOSEPOSWE

What you'll do

  • Identify security gaps and vulnerabilities in all ClickHouse offerings triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows
  • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing
  • Plan and execute internal red team assessments and penetration tests against ClickHouse infrastructure, cloud environments, designing realistic adversary scenarios to test detection, response and control effectiveness
  • Assess AI/LLM-specific attack surface across ClickHouse's own AI-powered features and internal AI tooling, including prompt injection, model/data exfiltration, and unsafe agentic tool-use patterns
  • Build and operate agentic tooling for reconnaissance, exploit-chaining and attack-path discovery, and apply LLM-assisted fuzzing to accelerate vulnerability discovery across ClickHouse's products and infrastructure

What they require

  • 7+ years of experience in pentesting, red teaming and product security
  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
  • Hands-on experience conducting offensive security engagements - internal red teaming, penetration testing and adversary simulation - across cloud, network and application environments
  • Ability to design adversary scenarios grounded in real threat intelligence (e.g. ransomware operators, supply chain attackers, insider threat) tailored to ClickHouse's risk profile as a multi-tenant cloud data platform
  • Strong written and verbal communication skills, with ability to translate attack chains into clear, actionable findings for engineering and leadership

Benefits

  • Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in over 25 countries.
  • Employer contributions towards your healthcare.
  • Every new team member who joins our company receives stock options.
  • Flexible time off in the US, generous entitlement in other countries.
  • A USD$500 Home office setup if you’re a remote employee.

open-source Column-oriented DBMS (columnar database management system) for online analytical processing (OLAP)

Cloud ComputingStartupclickhouse.com
Salary not disclosed