5-7 years of hands-on security experience in application, cloud, and enterprise security
Strong incident detection and response expertise
Proficiency with cloud platforms such as AWS, GCP, or Azure
Solid background in product security, red teaming, or penetration testing
Extensive programming and automation skills, preferably in Golang and Python
Excellent verbal and written communication abilities
Responsibilities
Develop and automate processes for scalable incident management
Collaborate with various teams to define detection use cases
Implement a threat modeling approach to enhance detection capabilities
Maintain and improve security logging systems
Stay informed on emerging threats and vulnerabilities
Manage security incidents within ClickHouse products and services
Benefits
Flexible remote work environment
Healthcare contributions from the employer
Stock options for all new employees
Flexible time off policies
$500 budget for home office setup for remote roles
Opportunities for in-person connections at global company offsites
Full Job Description
The Security Team is responsible for providing key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the adoption of modern security processes and tooling, with focus on supporting our detection and incident response capabilities.
What you will do:
Develop processes, tooling and automation to scale incident management response and mitigate risks to the business
Collaborate with other security functions, engineering, product, support, business operations to identify appropriate detection use cases and automation
Apply a threat modeling centric approach to incident detection and response
Maintain security logging platform
Stay up to date with the latest threats, attack vectors to improve our detection mechanisms and attack surface management
Handle information security events and incidents across the ClickHouse products and services
What you bring along:
Background in product security / red teaming / penetration testing / threat modeling, combined with incident detection and response experience
Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure)
Significant development and automation experience; preference for Golang and Python
Bonus Points:
BS, MS, or PhD in Computer Science or related field
Previous contributions to open source projects
Security or cloud related certifications (AWS, GCP, Azure)
The typical starting salary for this role in the US is
$169,150-$191,250 USD
The typical starting salary for this role in US Premium Markets is
$169,150-$225,000 USD
Compensation
For roles based in the United States, the typical starting salary range for this position is listed above. In certain locations, such as the San Francisco Bay Area and the New York City Metro Area, a premium market range may apply, as listed.
These salary ranges reflect what we reasonably and in good faith believe to be the minimum and maximum pay for this role at the time of posting. The actual compensation may be higher or lower than the amounts listed, and the ranges may be subject to future adjustments.
An individual's placement within the range will depend on various factors, including (but not limited to) education, qualifications, certifications, experience, skills, location, performance, and the needs of the business or organization.
If you have any questions or comments about compensation as a candidate, please get in touch with us at [redacted]. Perks
Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in over 20 countries.
Healthcare - Employer contributions towards your healthcare.
Equity in the company - Every new team member who joins our company receives stock options.
Time off - Flexible time off in the US, generous entitlement in other countries.
A $500 Home office setup if you're a remote employee.
Global Gatherings - We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites.