Skip to content
ClickhouseClickhouseUnited States

Product Security Engineer

Product Security Engineer collaborating with engineering and product teams on threat modeling, secure implementation, vulnerability triage, and security tooling for ClickHouse Cloud and OSS. Requires experience with distributed systems, cloud platforms, Kubernetes, and automation-focused security practices.

169k – 225k/yr
Remote5+ YOESecurity Engineering

About the role

Responsibilities

  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation (examples: secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation).
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS; triage vulnerabilities reported via bug bounty program, responsible disclosure, GitHub Issues covering web, API, server-client assets including low-level memory issues like heap or buffer overflows.
  • Improve and develop security assurance activities including pentests, vulnerability assessments, bug bounty programs, fuzzing.
  • Drive implementation and usage of engineering security tools such as static/dynamic code analysis, dependency checks, code licensing compliance (Snyk, Semgrep, GitHub CodeQL).
  • Nurture the engineering-security relationship; identify and implement process and technology improvements.
  • Handle information security events and incidents across ClickHouse products and services.
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business.

Requirements

  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory and in some cases implementation work across distributed systems covering web, API, client/server assets.
  • Strong knowledge of and experience with one or more cloud service providers (AWS, GCP, Azure), Kubernetes, Cilium, Crossplane.
  • Experience implementing and operating engineering security tools and processes (static/dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools).
  • Significant development and automation experience; ability to work with C++ code preferred.
  • Security as code mindset, with focus on solving problems with automation and scale in mind.

Nice-to-Haves

  • BS, MS, or PhD in Computer Science or related field.
  • Previous contributions to open source projects.
  • Security or cloud related certifications (AWS, GCP, Azure).

Skills

Threat Modelingsecurity assurancevulnerability triagepentestingfuzzingstatic code analysisdynamic code analysissnyksemgrepcodeqlKubernetesciliumcrossplaneAWSGCP
Clickhouse

Incident Response Security Engineer

ClickhouseUnited States

Handles security incidents, develops detection and response processes, maintains logging platforms, and automates risk mitigation for cloud services. Requires experience in incident response, threat modeling, cloud security, and programming in Golang/Python.

169k – 225k/yrRemoteSecurity Engineering
Cloudflare

Engineering Manager

CloudflareNew York, NY +3

Lead a team building and operating secure distributed systems for secrets, key management, PKI, and workload identity at Cloudflare. Requires strong security implementation experience, distributed systems expertise, and people management skills.

170k – 237k/yrHybrid5+ YOESecurity Engineering
Collective Intelligence Project

Product Security Engineer

Collective Intelligence ProjectSan Francisco, CA

Build and operate an agentic application security program using AI for automated testing, triage, and PR review. Drive end-to-end vulnerability remediation, eliminate vulnerability classes via code changes, and lead threat modeling for a fintech platform handling sensitive financial data. Requires 4+ years appsec experience, hands-on tooling expertise, enthusiasm for LLMs, and Python engineering skills.

170k – 200k/yrHybrid4+ YOESecurity Engineering
Crusoe

Endpoint Security Engineer

CrusoeSan Francisco, CA +2

Security Engineer responsible for endpoint security architecture, MDM administration (Jamf, Intune), compliance enforcement, and automation across macOS, Windows, iOS, and Android devices. Requires 3-6 years MDM experience, OSQuery/CrowdStrike expertise, and a security-first mindset.

170k – 205k/yrOn-site3+ YOESecurity Engineering
Suno

Software Engineer, Trust & Safety

SunoSan Francisco, CA

Suno is seeking a Software Engineer, Trust & Safety to protect its platform and users from abuse, fraud, and harmful content. This role involves building data pipelines, anomaly detection systems, and internal tools to ensure user safety and platform integrity.

170k – 240k/yrOn-site3+ YOESecurity Engineering