Jobiglo

No results.

Senior Product Security Engineer

clickhouse · The Netherlands

New Remote
Remote Senior 🇬🇧 English
C++ AWS GCP Azure Kubernetes Cilium Snyk Semgrep GitHub CodeQL dynamic code analysis software composition analysis SBOM OWASP SAMM fuzzing threat modeling secure key management passwordless authentication m2m authentication sandboxing isolation vulnerability assessment bug bounty

Job description

About the role

The Security Team at ClickHouse is looking for a senior, hands‑on security practitioner to help improve the security posture of its cloud and open‑source platforms. You will work closely with engineering and product teams to embed security into product design and implementation, while also driving security tooling and processes.

Key responsibilities

  • Collaborate with engineering to perform threat modeling, secure key management, passwordless and m2m authentication, sandboxing, and isolation of compute, network and storage.
  • Identify and triage security gaps and vulnerabilities in ClickHouse Cloud and OSS, including bug‑bounty reports, responsible disclosure, and low‑level memory issues.
  • Develop and run security assurance activities such as penetration tests, vulnerability assessments, fuzzing, and bug‑bounty programs.
  • Drive adoption of security tooling (static/dynamic analysis, dependency checks, code licensing compliance) using Snyk, Semgrep, GitHub CodeQL, etc.
  • Handle information‑security incidents across ClickHouse products and build automation to scale security processes.

Required profile

  • Proven experience supporting engineering teams with threat assessments, security assurance, and secure implementation for web, API, and client‑server assets.
  • Strong knowledge of at least one major cloud provider (AWS, GCP, Azure) and container orchestration (Kubernetes, Cilium).
  • Hands‑on experience implementing and operating security tooling such as static/dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, and fuzzing tools.

Required skills

  • C++ programming
  • Cloud platforms: AWS, GCP, Azure
  • Kubernetes and Cilium
  • Security tooling: Snyk, Semgrep, GitHub CodeQL, static and dynamic analysis
  • Software composition analysis, SBOM, OWASP SAMM
  • Fuzzing, penetration testing, vulnerability assessment
  • Threat modeling, secure key management, passwordless and m2m authentication, sandboxing, isolation

What we offer

  • Fully remote work within the Netherlands
  • Healthcare contributions and $500 home‑office setup for remote employees
  • Equity through stock options
  • Flexible time‑off policy and generous vacation entitlement
  • Global gatherings and a culture‑shaping environment

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec clickhouse.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:ashby

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the Netherlands.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 5 hours ago

Expires 1 month from now

5 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

clickhouse

The Netherlands