# Product Security Engineer

**Company:** [Clickhouse](https://hotfix.jobs/companies/clickhouse)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $169k – $225k/yr
**Experience:** 5+ years
**Skills:** Threat Modeling, security assurance, vulnerability triage, pentesting, fuzzing, static code analysis, dynamic code analysis, snyk, semgrep, codeql, Kubernetes, cilium, crossplane, AWS, GCP
**Posted:** 2026-07-29

> Product Security Engineer collaborating with engineering and product teams on threat modeling, secure implementation, vulnerability triage, and security tooling for ClickHouse Cloud and OSS. Requires experience with distributed systems, cloud platforms, Kubernetes, and automation-focused security practices.

## Job Description

## Responsibilities
- Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation (examples: secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation).
- Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS; triage vulnerabilities reported via bug bounty program, responsible disclosure, GitHub Issues covering web, API, server-client assets including low-level memory issues like heap or buffer overflows.
- Improve and develop security assurance activities including pentests, vulnerability assessments, bug bounty programs, fuzzing.
- Drive implementation and usage of engineering security tools such as static/dynamic code analysis, dependency checks, code licensing compliance (Snyk, Semgrep, GitHub CodeQL).
- Nurture the engineering-security relationship; identify and implement process and technology improvements.
- Handle information security events and incidents across ClickHouse products and services.
- Develop processes, tooling and automation to scale security processes and mitigate risks to the business.

## Requirements
- Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory and in some cases implementation work across distributed systems covering web, API, client/server assets.
- Strong knowledge of and experience with one or more cloud service providers (AWS, GCP, Azure), Kubernetes, Cilium, Crossplane.
- Experience implementing and operating engineering security tools and processes (static/dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools).
- Significant development and automation experience; ability to work with C++ code preferred.
- Security as code mindset, with focus on solving problems with automation and scale in mind.

## Nice-to-Haves
- BS, MS, or PhD in Computer Science or related field.
- Previous contributions to open source projects.
- Security or cloud related certifications (AWS, GCP, Azure).

## Similar roles

- [Incident Response Security Engineer](https://hotfix.jobs/jobs/d002a19f-a1ab-4434-977e-b1a71be0e1c8) - Clickhouse - Remote - $169k – $225k/yr
- [Engineering Manager](https://hotfix.jobs/jobs/23acf595-d20c-4fc2-a05d-23131fce504c) - Cloudflare - New York, NY - $170k – $237k/yr
- [Product Security Engineer](https://hotfix.jobs/jobs/04dc8629-c86c-4c38-a6ac-226ed3e7a745) - Collective Intelligence Project - San Francisco, CA - $170k – $200k/yr
- [Endpoint Security Engineer](https://hotfix.jobs/jobs/e9f904e5-b1d3-4a26-b61e-06c5e375ab90) - Crusoe - San Francisco, CA - $170k – $205k/yr
- [Software Engineer, Trust & Safety](https://hotfix.jobs/jobs/7d005694-1f26-43da-8d18-cb58960d2d1e) - Suno - San Francisco, CA - $170k – $240k/yr

**Apply:** https://hotfix.jobs/jobs/0b9f98a1-7c34-4991-84ff-bc021c9a0bc7
**Canonical:** https://hotfix.jobs/jobs/0b9f98a1-7c34-4991-84ff-bc021c9a0bc7