Full-Time

Product Security Engineer

Confirmed live in the last 24 hours

Clickhouse

Clickhouse

201-500 employees

High-speed column-oriented database management system

Data & Analytics
Enterprise Software

Compensation Overview

$134.1k - $225kAnnually

+ Cash Compensation + Stock Options

Mid

Remote in USA

Candidates must be based in the United States.

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
Microsoft Azure
AWS
C/C++
Google Cloud Platform

You match the following Clickhouse's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium, Crossplane
  • Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools)
  • Significant development and automation experience, ability to work with C++ code preferred
  • Security as code mindset, with focus on solving problems with automation and scale in mind
Responsibilities
  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows
  • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing
  • Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL)
  • Nurture the engineering - security relationship, identify and implement process and technology improvements
  • Handle information security events and incidents across ClickHouse products and services
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business
Desired Qualifications
  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)

ClickHouse provides a high-speed, column-oriented database management system designed for handling large-scale data. Its primary product allows users to process analytical queries quickly by storing data from the same columns together, which is more efficient for Online Analytical Processing (OLAP) compared to traditional row-oriented databases. This approach enables ClickHouse to process most queries at least 100 times faster. The company offers a free, open-source version of its database that can be deployed on local machines or in the cloud, as well as a fully managed service on platforms like Amazon Web Services, Google Cloud Platform, and Microsoft Azure. ClickHouse stands out from competitors by being cost-effective, with clients reporting significant savings after switching to their system. The goal of ClickHouse is to provide an easy-to-use and manageable database solution that meets the needs of developers and businesses working with large datasets.

Company Size

201-500

Company Stage

Series B

Total Funding

$291.8M

Headquarters

San Francisco, California

Founded

2021

Simplify Jobs

Simplify's Take

What believers are saying

  • Partnership with Alibaba Cloud boosts presence in the Chinese market.
  • Acquisition of PeerDB enhances real-time analytics capabilities.
  • Launch of ClickPipes improves data processing efficiency for real-time updates.

What critics are saying

  • Redpanda Serverless poses a competitive threat in real-time data processing.
  • Integration challenges with PeerDB may delay expected benefits.
  • Dependency on Supabase could pose operational risks.

What makes Clickhouse unique

  • ClickHouse's column-oriented design offers superior speed for analytical queries.
  • The open-source model allows flexible deployment across various environments.
  • Integration with Grafana enhances data visualization capabilities.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Unlimited Paid Time Off

Flexible Work Hours

Remote Work Options

Stock Options

Home Office Stipend

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

-1%
Run Portcullis
Dec 16th, 2024
Use cases for Clickhouse's spicy new JSON column type

In October of 2024, Clickhouse announced a powerful new JSON data type that has been causing the community to buzz with excitement and anticipation over the possible use-cases and potential POCs.

Yahoo Finance
Nov 24th, 2024
The Curious Case Of Nebius, The Publicly Traded Ai Infrastructure 'Startup'

Casual observers could be forgiven for wondering where this company had come from, as there had been little in the way of the usual fanfare that surrounds most startups' journey to IPO — no roadshows; no horn tootin'; no confetti-laden ceremonies; nothing, not a peep. That's because Nebius is an unusual beast: a public company, but a startup in just about every sense of the word. The core Nebius business sells GPUs (graphical processing units) "as-a-service" to companies needing "compute" — that is, processing power and resources to carry out computational tasks such as running algorithms and executing machine learning models. Last month, the company debuted a holistic cloud computing platform designed for the "full machine learning lifecycle," spanning data processing, training, fine-tuning, and inference. With the restructuring complete, and Volozh free to run the show from the company's new HQ in the Netherlands, Nasdaq green-lighted Nebius to recommence trading last month. The situation was pretty much unprecedented, though: a public company whose trading was put on pause, only to resume nearly three years later under a new name and entirely different business proposition? In many ways, it would've made sense to have delisted and grown with private capital, the good old-fashioned startup way

ClickHouse
Oct 30th, 2024
Supabase Partnership: Native Postgres Replication to ClickHouse, clickhouse_fdw and more

"ClickHouse is very excited to partner with Supabase to make it easy for customers to use both technologies together.

Business Wire
Jul 30th, 2024
ClickHouse Acquires PeerDB to Boost Real-time Analytics with Postgres CDC Integration

ClickHouse acquires PeerDB to boost real-time analytics with Postgres CDC integration.

Business Wire
Mar 19th, 2024
Redpanda Serverless Delivers Powerful Streaming Data Platform As A Fully Managed Pay-As-You-Go Service

LONDON--(BUSINESS WIRE)--At Kafka Summit London, Redpanda announced the availability of Redpanda Serverless, a fully managed, pay-as-you-go edition of its powerful, cost-effective streaming data platform. Redpanda Serverless empowers developers to get started with streaming data in seconds and to automatically scale the service up or down to match their data workloads. As with all Redpanda products, Redpanda Serverless is fully Apache Kafka® API-compatible, ensuring it works with the complete Kafka ecosystem without requiring changes to application code. “The magic of Redpanda Serverless is its ability to create a globally available cluster in the blink of an eye,” said Redpanda CEO and founder Alex Gallego. “Engineered from the ground up for massive multi-tenancy, speed and performance, Redpanda Serverless is the most cost effective and simplest way to get started with streaming, whether you are a solo dev just getting started or an expert at a large enterprise looking to absorb spikes and scale to zero during downtime.”. With Redpanda Serverless, developers will be able to tap into the Redpanda streaming data ecosystem to build new real-time applications