yandex
clickhouse
Страна
Германия
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
УдалённоПолная занятость

Product Security Engineer

Оценка ИИ

Отличная вакансия в компании-единороге с сильной инженерной культурой, опционами и возможностью удаленной работы из Германии. Высокий потенциал роста и работа с передовыми технологиями (ClickHouse Cloud, AI workloads).


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена необходимостью глубоких знаний в C++, безопасности облачных сред (K8s, AWS/GCP) и умением работать с низкоуровневыми уязвимостями (heap/buffer overflows). Роль требует баланса между навыками разработчика и эксперта по безопасности.

Анализ зарплаты

Медиана85 000 €
Рынок75 000 € – 110 000 €
Оценка ИИ

Предлагаемая позиция в ClickHouse соответствует верхнему сегменту рынка Германии для опытных специалистов по безопасности продукта. Учитывая наличие опционов и статус компании, совокупный доход может значительно превышать средние рыночные показатели.

Сопроводительное письмо

I am writing to express my strong interest in the Product Security Engineer position at ClickHouse. With a deep background in securing distributed systems and a "security as code" mindset, I have spent my career bridging the gap between security requirements and engineering velocity. My experience with threat modeling, Kubernetes security, and automating security assurance tools like Semgrep and CodeQL aligns perfectly with the responsibilities outlined for this role.

What excites me most about ClickHouse is the challenge of securing a high-performance, open-source-based cloud platform. I am particularly impressed by your recent Series D funding and the caliber of customers like Meta and Tesla. I am proficient in C++ and have extensive experience with AWS and GCP, which allows me to not only identify vulnerabilities but also collaborate effectively with developers on secure implementation and remediation. I am eager to bring my expertise in fuzzing and bug bounty management to help scale ClickHouse's security posture.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в clickhouse уже сейчас

Присоединяйтесь к команде ClickHouse и защищайте одну из самых инновационных облачных платформ в мире!

Описание вакансии

About ClickHouse

Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast-growing private cloud companies. With more than 3,000 customers and ARR that has grown over 250 percent year over year, ClickHouse leads the market in real-time analytics, data warehousing, observability, and AI workloads.

The company’s sustained, accelerating momentum was recently validated by a $400M Series D financing round. Over the past three months, customers including Capital One, Lovable, Decagon, Polymarket, and Airwallex have adopted the platform or expanded existing deployments. These customers join an established base of AI innovators and global brands such as Meta, Cursor, Sony, and Tesla.

We’re on a mission to transform how companies use data. Come be a part of our journey!

About the team

The Security Team is responsible for providing key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the adoption of modern security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and services.

Note: This position can be fully remote anywhere in Germany.

What you will do:

  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows
  • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing
  • Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL)
  • Nurture the engineering - security relationship, identify and implement process and technology improvements
  • Handle information security events and incidents across ClickHouse products and services
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business

What you bring along:

  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium
  • Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools)
  • Significant development and automation experience, ability to work with C++ code
  • Security as code mindset, with focus on solving problems with automation and scale in mind

Bonus Points:

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)

Compensation

For roles based in the United States, the typical starting salary range for this position is listed above. In certain locations, such as the San Francisco Bay Area and the New York City Metro Area, a premium market range may apply, as listed.

These salary ranges reflect what we reasonably and in good faith believe to be the minimum and maximum pay for this role at the time of posting. The actual compensation may be higher or lower than the amounts listed, and the ranges may be subject to future adjustments.

An individual’s placement within the range will depend on various factors, including (but not limited to) education, qualifications, certifications, experience, skills, location, performance, and the needs of the business or organization.

If you have any questions or comments about compensation as a candidate, please get in touch with us at paytransparency@clickhouse.com.

Perks

  • Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in 20 countries.
  • Healthcare - Employer contributions towards your healthcare.
  • Equity in the company - Every new team member who joins our company receives stock options.
  • Time off - Flexible time off in the US, generous entitlement in other countries.
  • A $500 Home office setup if you’re a remote employee.
  • Global Gatherings – We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites.

Culture - We All Shape It

As part of our first 500 employees, you will be instrumental in shaping our culture. 

Are you interested in finding out more about our culture?  Learn more about our values here.  Check out ourblog posts or follow us on LinkedIn to find out more about what’s happening at ClickHouse.

Equal Opportunity & Privacy

ClickHouse provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any type based on factors such as race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Please see here for our Privacy Statement.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • AWS
  • Azure
  • C++
  • Threat Modeling
  • Kubernetes
  • Google Cloud Platform
  • Static Analysis
  • Dynamic Analysis
  • SCA
  • Snyk
  • SBOM
  • Cilium
  • Fuzzing
  • Semgrep
  • GitHub CodeQL
  • OWASP SAMM

Возможные вопросы на собеседовании

ClickHouse написан на C++, поэтому важно понимать специфические риски этого языка.

Расскажите о вашем опыте поиска и предотвращения уязвимостей управления памятью (например, переполнения буфера) в проектах на C++.

Роль предполагает активное участие в проектировании новых функций.

Опишите процесс проведения Threat Modeling для новой фичи в облачной инфраструктуре. Какие методологии вы используете?

Вакансия требует опыта работы с современными инструментами анализа кода.

Как бы вы внедрили Semgrep или CodeQL в существующий CI/CD пайплайн, чтобы минимизировать количество ложноположительных срабатываний для разработчиков?

ClickHouse Cloud активно использует Kubernetes и Cilium.

Какие основные векторы атак на Kubernetes вы считаете наиболее критичными для SaaS-платформы и как вы предлагаете их минимизировать?

Вакансия включает работу с Bug Bounty.

Как вы приоритизируете отчеты от исследователей безопасности и как выстраиваете коммуникацию с инженерной командой для оперативного исправления багов?

Похожие вакансии

Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
250 000 ₽ – 450 000 ₽

Эксперт по защите периметра (WAF)

УдалённоРоссия
WAF · Wallarm · Positive Technologies Application Firewall · NGFW · IPS · Vulnerability Assessment · Network Security
+7 навыков
Квазар
до 350 000 ₽

DevOps-инженер/ИБ (devops engineer, information security)

УдалённоРоссия
TCP/IP · DNS · DHCP · HTTPS · SMTP · BGP · OSPF · VLAN · NAT · Zero Trust · RBAC · SIEM · Zabbix · ELK · Wazuh · Grafana · Bash · PowerShell · Python · VMware · Proxmox · Hyper-V · KVM · SoC
+24 навыков
Innostaff
Не указана

Сеньор AppSecOps-инженер

SeniorУдалённоБеларусь
AppSecOps · DevSecOps · SAST · DAST · SCA · CI/CD · Cybersecurity · Kubernetes · Docker
+9 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

clickhouse
Страна
Германия