# Offensive Security Engineer

**Company:** [Clickhouse](https://hotfix.jobs/companies/clickhouse)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 7+ years
**Skills:** Penetration Testing, Red Teaming, Product Security, Threat Modeling, Adversary Simulation, Cloud Security, AWS, GCP, Azure, Kubernetes, Cilium, Fuzzing, Llm Security, Python, Owasp Samm
**Posted:** 2026-08-03

> Conducts penetration testing, red-team assessments, vulnerability research, and AI/LLM security testing across ClickHouse products, infrastructure, and cloud environments. Requires 7+ years of offensive and product-security experience plus hands-on expertise with cloud platforms, Kubernetes, Cilium, and security automation.

## Job Description

## Responsibilities
- Identify security gaps and vulnerabilities across ClickHouse offerings, and triage vulnerabilities reported through bug bounty programs, responsible disclosure, and GitHub Issues, covering web, API, server-client assets, and low-level memory issues such as heap or buffer overflows.
- Improve and develop security assurance activities, including penetration tests, vulnerability assessments, bug bounty programs, and fuzzing.
- Plan and execute internal red-team assessments and penetration tests against ClickHouse infrastructure and cloud environments.
- Design realistic adversary scenarios to test detection, response, and control effectiveness.
- Assess AI/LLM-specific attack surfaces across ClickHouse AI-powered features and internal AI tooling, including prompt injection, model or data exfiltration, and unsafe agentic tool use.
- Build and operate agentic tooling for reconnaissance, exploit chaining, and attack-path discovery.
- Apply LLM-assisted fuzzing to accelerate vulnerability discovery across products and infrastructure.
- Partner with detection engineering to validate and improve detection coverage during red-team exercises, measuring and reporting control effectiveness and time to detect and respond.
- Handle information-security events and incidents across ClickHouse products and services.
- Develop processes, tooling, and automation to scale security processes and mitigate business risk.

## Requirements
- 7+ years of experience in penetration testing, red teaming, and product security.
- Experience supporting engineering and product implementation through threat assessments, assurance activities, advisory work, and, where applicable, implementation across distributed systems.
- Hands-on experience with internal red teaming, penetration testing, and adversary simulation across cloud, network, and application environments.
- Ability to design adversary scenarios grounded in real threat intelligence, including ransomware operators, supply-chain attackers, and insider threats.
- Strong written and verbal communication skills, with the ability to translate attack chains into actionable findings for engineering and leadership.
- Experience building or adapting agentic and LLM-assisted tooling for offensive-security use cases, with judgment about when AI improves an engagement.
- Familiarity with AI/LLM-specific vulnerability classes and testing methodologies.
- Strong knowledge of and experience with one or more cloud service providers, Kubernetes, and Cilium.
- Experience implementing and operating engineering-security tools and processes, including static and dynamic code analysis, software composition analysis, SBOMs, OWASP SAMM, and client and network fuzzing tools.
- A security-as-code mindset, focused on automation and scale.

## Nice-to-haves
- BS, MS, or PhD in Computer Science or a related field.
- Contributions to open-source projects.
- Security or cloud certifications, such as AWS, GCP, or Azure certifications.
- Experience using AI security harnesses for penetration testing.
- Experience building or operating internal red-team tooling and infrastructure from scratch.
- Offensive-security certifications such as OSCP, OSCE, OSEP, or OSWE.

## Compensation and benefits
- Flexible work environment at a globally distributed, remote-friendly company operating in more than 20 countries.
- Employer healthcare contributions.
- Stock options for new team members.
- Flexible time off in the US and generous entitlement in other countries.
- $500 home-office setup benefit for remote employees.
- Opportunities to participate in company-wide offsites.

## Similar jobs

- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Security Engineer - Product](https://hotfix.jobs/jobs/d32dc9fa-f31b-4fc4-a7c6-eade39acfb64) - Wiz - Berlin, Germany
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr

**Apply:** https://hotfix.jobs/jobs/a8f8c463-9f49-4d59-a1c9-0a9184fda587
**Canonical:** https://hotfix.jobs/jobs/a8f8c463-9f49-4d59-a1c9-0a9184fda587