Offensive Security Engineer
Conducts penetration testing, red-team assessments, vulnerability research, and AI/LLM security testing across ClickHouse products, infrastructure, and cloud environments. Requires 7+ years of offensive and product-security experience plus hands-on expertise with cloud platforms, Kubernetes, Cilium, and security automation.
About the job
Responsibilities
- Identify security gaps and vulnerabilities across ClickHouse offerings, and triage vulnerabilities reported through bug bounty programs, responsible disclosure, and GitHub Issues, covering web, API, server-client assets, and low-level memory issues such as heap or buffer overflows.
- Improve and develop security assurance activities, including penetration tests, vulnerability assessments, bug bounty programs, and fuzzing.
- Plan and execute internal red-team assessments and penetration tests against ClickHouse infrastructure and cloud environments.
- Design realistic adversary scenarios to test detection, response, and control effectiveness.
- Assess AI/LLM-specific attack surfaces across ClickHouse AI-powered features and internal AI tooling, including prompt injection, model or data exfiltration, and unsafe agentic tool use.
- Build and operate agentic tooling for reconnaissance, exploit chaining, and attack-path discovery.
- Apply LLM-assisted fuzzing to accelerate vulnerability discovery across products and infrastructure.
- Partner with detection engineering to validate and improve detection coverage during red-team exercises, measuring and reporting control effectiveness and time to detect and respond.
- Handle information-security events and incidents across ClickHouse products and services.
- Develop processes, tooling, and automation to scale security processes and mitigate business risk.
Requirements
- 7+ years of experience in penetration testing, red teaming, and product security.
- Experience supporting engineering and product implementation through threat assessments, assurance activities, advisory work, and, where applicable, implementation across distributed systems.
- Hands-on experience with internal red teaming, penetration testing, and adversary simulation across cloud, network, and application environments.
- Ability to design adversary scenarios grounded in real threat intelligence, including ransomware operators, supply-chain attackers, and insider threats.
- Strong written and verbal communication skills, with the ability to translate attack chains into actionable findings for engineering and leadership.
- Experience building or adapting agentic and LLM-assisted tooling for offensive-security use cases, with judgment about when AI improves an engagement.
- Familiarity with AI/LLM-specific vulnerability classes and testing methodologies.
- Strong knowledge of and experience with one or more cloud service providers, Kubernetes, and Cilium.
- Experience implementing and operating engineering-security tools and processes, including static and dynamic code analysis, software composition analysis, SBOMs, OWASP SAMM, and client and network fuzzing tools.
- A security-as-code mindset, focused on automation and scale.
Nice-to-haves
- BS, MS, or PhD in Computer Science or a related field.
- Contributions to open-source projects.
- Security or cloud certifications, such as AWS, GCP, or Azure certifications.
- Experience using AI security harnesses for penetration testing.
- Experience building or operating internal red-team tooling and infrastructure from scratch.
- Offensive-security certifications such as OSCP, OSCE, OSEP, or OSWE.
Compensation and benefits
- Flexible work environment at a globally distributed, remote-friendly company operating in more than 20 countries.
- Employer healthcare contributions.
- Stock options for new team members.
- Flexible time off in the US and generous entitlement in other countries.
- $500 home-office setup benefit for remote employees.
- Opportunities to participate in company-wide offsites.
Skills
Penetration Testing, Red Teaming, Product Security, Threat Modeling, Adversary Simulation, Cloud Security, AWS, GCP, Azure, Kubernetes, Cilium, Fuzzing, Llm Security, Python, Owasp Samm
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.