Product Security Engineer

2 weeks ago


Canada ClickHouse Full time

Get AI-powered advice on this job and more exclusive features. About ClickHouse Established in 2009, ClickHouse leads the industry with its open-source column-oriented database system, driven by the vision of becoming the fastest OLAP database globally. The company enables real-time analytical reports through SQL queries, emphasizing speed in managing escalating data volumes. Enterprises globally rely on ClickHouse Cloud, available through open-source or on AWS, GCP, Azure, and Alibaba. About The Team The Security Team provides key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. The team is looking for an experienced, hands-on security practitioner to drive the adoption of modern security processes and tooling, with a focus on supporting engineering and product teams to improve the security posture of our platforms and services. Note: This position can be fully remote anywhere in Canada or the United States. What you will do Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation. Recent work includes secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation. Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS; triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, and GitHub Issues covering web, API and server–client assets including low level memory issues like heap or buffer overflows. Improve and develop security assurance activities — pentests, vulnerability assessments, bug bounty programs, fuzzing. Drive implementation and usage of engineering security tools — static and dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL). Nurture the engineering–security relationship, identify and implement process and technology improvements. Handle information security events and incidents across ClickHouse products and services. Develop processes, tooling and automation to scale security processes and mitigate risks to the business. What you bring along Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets. Strong knowledge of and experience with one or more cloud service providers (e.g., AWS, GCP, Azure), Kubernetes, Cilium. Experience implementing and operating engineering security tools and processes (e.g., static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools). Significant development and automation experience, ability to work with C++ code. Security as code mindset, with focus on solving problems with automation and scale in mind. Bonus Points BS, MS, or PhD in Computer Science or related field. Previous contributions to open source projects. Security or cloud related certifications (AWS, GCP, Azure). Compensation For roles based in the United States, the typical starting salary range for this position is listed above. In certain locations (e.g., Los Angeles, CA; the San Francisco Bay Area, CA; Seattle, WA; the New York City Metro Area), a premium market range may apply. These salary ranges reflect what we reasonably and in good faith believe to be the minimum and maximum pay for this role at the time of posting. The actual compensation may be higher or lower, and ranges may be subject to future adjustments. An individual’s placement within the range will depend on factors including education, qualifications, certifications, experience, skills, location, performance, and business needs. If you have questions about compensation as a candidate, please contact Perks Flexible work environment – ClickHouse is a globally distributed company and remote-friendly. We currently operate in 20 countries. Healthcare – Employer contributions towards your healthcare. Equity in the company – Stock options for new team members. Time off – Flexible time off in the US, generous entitlement in other countries. A $500 home office setup if you’re a remote employee. Global Gatherings – Opportunities to engage with colleagues at company-wide offsites. Culture We all shape it. As part of our first 500 employees, you will be instrumental in shaping our culture. Learn more about our values, blog posts, and follow us on LinkedIn to see what’s happening at ClickHouse. Equal Opportunity & Privacy ClickHouse provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any type based on factors such as race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Please see here for our Privacy Statement. Seniority level Mid-Senior level Employment type Full-time Job function Information Technology Industries: Technology, Information and Internet, Software Development, and IT Services and IT Consulting #J-18808-Ljbffr



  • , , Canada Alpaca Full time

    Overview Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our recent Series C funding round has brought total investment to over $170 million, fueling our ambitious vision. Alpaca serves hundreds of financial institutions across 40 countries with our...


  • , , Canada ClickHouse Full time

    Product Security Engineer Join to apply for the Product Security Engineer role at ClickHouse . About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast‑growing private cloud companies. With over 2,000 customers and an ARR that has more than quadrupled in the past year, ClickHouse leads the market in...


  • , , Canada ClickHouse Full time

    About ClickHouse Established in 2009, ClickHouse leads the industry with its open-source column-oriented database system, driven by the vision of becoming the fastest OLAP database globally. The company empowers users to generate real-time analytical reports through SQL queries, emphasizing speed in managing escalating data volumes. Enterprises globally,...


  • , , Canada GitLab Full time

    Join to apply for the Manager, Product Security Engineering role at GitLab . GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute,...


  • , , Canada Redis Full time

    Join to apply for the Senior Product Security Engineer role at Redis Who We Are We're Redis. We built the product that runs the fast apps our world runs on. (If you checked the weather, used your credit card, or looked at your flight status online today, you’re welcome.) At Redis, you’ll work with the fastest, simplest technology in the...


  • Vancouver, British Columbia, VCG, Canada D3 Security Management Systems Full time $65,000 - $100,000 per year

    Cyber Security EngineerLocation: Greater Vancouver area candidates onlyThe Opportunity:D3 Security is transforming SecOps with Morpheus, our AI-driven Autonomous Security Operations Center (ASOC) platform. Morpheus automates Tier 1–3 analyst work with unmatched precision, processing millions of alerts in real time and empowering security teams to respond...


  • , , Canada Redis Full time

    A leading tech company is seeking a Senior Product Security Engineer to drive application security innovations. In this role, you will protect software products using your skills in code analysis, vulnerability assessment, and security frameworks. Collaboration with engineering teams will be key to implementing security measures throughout the development...


  • , , Canada GitLab Full time

    A multinational technology company in Canada is seeking a Manager, Product Security Engineering. This role combines leadership in software engineering with security domain expertise to deliver security capabilities in GitLab's platform. The ideal candidate will have 3+ years of experience in software engineering management and a strong understanding of...


  • , BC, Canada AdaptiveMobile Security Full time

    Role Overview As a key player in the Customer Support team, you will work under the Customer Support Manager, troubleshooting complex technical issues, and collaborating closely with engineering and service delivery teams. You’ll combine technical expertise with excellent customer service, making you a vital part of our support operations. A degree in...


  • , , Canada Quora Full time

    Staff Product Security Software Engineer (Remote) ( Quora is a privately held, "remote-first" company . This position can be performed remotely from multiple countries around the world. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by country.)About QuoraQuora’s mission is to grow and share the world’s...