Skip to main content
ClickHouse

Senior Product Security Engineer

RemoteNetherlands only
Published
Role
Security
Experience
Senior
Company size
Startup
Salary not disclosed
Check eligibility

Open to NL only. Set where you work from to check your eligibility.

No BS summary

Senior hands-on product security engineer in the Netherlands. Needs security work across distributed web/API/client-server systems, cloud providers, Kubernetes/Cilium, engineering security tooling, and ability to work with C++ code.

Core skills

KubernetesC++Product security

Required skills

AWS/GCP/AzureCiliumStatic code analysisDynamic code analysisSoftware composition analysisSBOMOWASP SAMMClient fuzzing toolsNetwork fuzzing tools

Optional skills

AWSGCPAzure

What you'll do

  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation.
  • Work on secure key management, passwordless authentication, m2m authentication, sandboxing, and compute/network/storage isolation.
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS.
  • Triage vulnerabilities reported via bug bounty, responsible disclosure, and GitHub Issues across web, API, server-client assets, and low-level memory issues like heap or buffer overflows.
  • Improve and develop security assurance activities including pentests, vulnerability assessments, bug bounty programs, and fuzzing.
  • Drive implementation and usage of engineering security tools including static and dynamic code analysis, dependency checks, and code licensing compliance.
  • Nurture the engineering-security relationship.
  • Identify and implement process and technology improvements.
  • Handle information security events and incidents across ClickHouse products and services.
  • Develop processes, tooling, and automation to scale security processes and mitigate business risks.

What they require

  • Experienced, hands-on security practitioner.
  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory, and sometimes implementation work across distributed systems covering web, API, and client/server assets.
  • Strong knowledge of and experience with one or more cloud service providers such as AWS, GCP, or Azure.
  • Strong knowledge of and experience with Kubernetes and Cilium.
  • Experience implementing and operating engineering security tools and processes such as static/dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools.
  • Significant development and automation experience.
  • Ability to work with C++ code.
  • Security as code mindset, with focus on solving problems with automation and scale in mind.
  • Preferred: BS, MS, or PhD in Computer Science or related field.
  • Preferred: Previous contributions to open source projects.
  • Preferred: Security or cloud related certifications.

Benefits

  • Flexible work environment.
  • Globally distributed and remote-friendly company operating in over 20 countries.
  • Employer contributions towards healthcare.
  • Equity in the company through stock options for every new team member.
  • Flexible time off in the US and generous entitlement in other countries.
  • $500 home office setup for remote employees.
  • Global gatherings and company-wide offsites.
  • Opportunity to shape company culture as part of a rapidly scaling startup.

open-source Column-oriented DBMS (columnar database management system) for online analytical processing (OLAP)

Cloud ComputingStartupclickhouse.com

Details

Apply routeGreenhouse
Salary not disclosed