# Senior Product Security Engineer

**Company:** [Clickhouse](https://hotfix.jobs/companies/clickhouse)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Threat Modeling, AWS, GCP, Azure, Kubernetes, Cilium, Snyk, Semgrep, Github Codeql, C++, Fuzzing, Sbom, Owasp Samm, Static Code Analysis, Dynamic Code Analysis
**Posted:** 2026-07-29

> Senior Product Security Engineer partnering with engineering and product teams to secure distributed cloud services through threat modeling, vulnerability management, security tooling, incident response, and automation. Requires substantial security engineering, cloud, Kubernetes, and development experience.

## Job Description

## Responsibilities
- Partner with engineering and product teams on threat modeling, security assurance, secure implementation, and security posture improvements for platforms and services.
- Identify and triage vulnerabilities across ClickHouse Cloud and open-source assets, including web, API, client/server, and memory-safety issues such as heap and buffer overflows.
- Improve and operate penetration testing, vulnerability assessment, bug bounty, fuzzing, and responsible disclosure programs.
- Implement and drive adoption of engineering security tooling, including static and dynamic code analysis, dependency checks, and code-licensing compliance.
- Strength the engineering-security relationship and improve security processes and technologies.
- Handle information-security events and incidents across ClickHouse products and services.
- Build scalable security processes, tooling, and automation to mitigate business risk.

## Requirements
- Experience supporting engineering and product implementation through threat assessments, assurance activities, advisory work, and occasional implementation across distributed systems.
- Strong knowledge of one or more cloud providers, Kubernetes, and Cilium.
- Experience implementing and operating engineering security tools and processes, including static/dynamic code analysis, software composition analysis, SBOMs, OWASP SAMM, and client/network fuzzing.
- Significant development and automation experience, including the ability to work with C++ code.
- A security-as-code mindset focused on automation and scale.

## Nice-to-haves
- Bachelor's, master's, or PhD in Computer Science or a related field.
- Open-source contributions.
- AWS, Google Cloud, or Azure security/cloud certifications.

## Compensation and benefits
- Stock options.
- Employer healthcare contributions.
- Flexible time off.
- $500 USD home-office setup allowance for remote employees.
- Opportunities to attend company-wide offsites.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/503a42b8-bd7e-4c56-af60-f4ae9e07d2b5
**Canonical:** https://hotfix.jobs/jobs/503a42b8-bd7e-4c56-af60-f4ae9e07d2b5