Product Security Engineer

7 days ago


Canada ClickHouse Full time

About ClickHouse Established in 2009, ClickHouse leads the industry with its open-source column-oriented database system, driven by the vision of becoming the fastest OLAP database globally. The company empowers users to generate real-time analytical reports through SQL queries, emphasizing speed in managing escalating data volumes. Enterprises globally, including Lyft, Sony, IBM, GitLab, Twilio, HubSpot, and many more, rely on ClickHouse Cloud. It is available through open-source or on AWS, GCP, Azure, and Alibaba. About the team The Security Team is responsible for providing key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. Our team is looking for an experienced, hands‑on security practitioner, who will drive the adoption of modern security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and services. Note: This position can be fully remote anywhere in Canada or the United States. What you will do Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server‑client assets including low level memory issues like heap or buffer overflows Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL) Nurture the engineering - security relationship, identify and implement process and technology improvements Handle information security events and incidents across ClickHouse products and services Develop processes, tooling and automation to scale security processes and mitigate risks to the business What you bring along Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools) Significant development and automation experience, ability to work with C++ code Security as code mindset, with focus on solving problems with automation and scale in mind Bonus Points BS, MS, or PhD in Computer Science or related field Previous contributions to open source projects Security or cloud related certifications (AWS, GCP, Azure) Compensation For roles based in the United States , you can find above our typical starting salary ranges for this role, depending on your specific location. The positioning of offers within a certain range depends on various factors, including: candidate experience, qualifications, skills, business requirements and geographical location. If you have any questions or comments about compensation as a candidate, please get in touch with us at Perks Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in 20 countries. Healthcare - Employer contributions towards your healthcare. Equity in the company - Every new team member who joins our company receives stock options. Time off - Flexible time off in the US, generous entitlement in other countries. A $500 Home office setup - if you’re a remote employee. Global Gatherings – We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites. Culture - We All Shape It As part of our first 500 employees, you will be instrumental in shaping our culture. Are you interested in finding out more about our culture? Learn more about our values here. Check out our blog posts or follow us on LinkedIn to find out more about what’s happening at ClickHouse. Equal Opportunity & Privacy ClickHouse provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any type based on factors such as race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Please see here for our Privacy Statement. #J-18808-Ljbffr



  • , , Canada Alpaca Full time

    Overview Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our recent Series C funding round has brought total investment to over $170 million, fueling our ambitious vision. Alpaca serves hundreds of financial institutions across 40 countries with our...


  • , , Canada ClickHouse Full time

    Product Security Engineer Join to apply for the Product Security Engineer role at ClickHouse . About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast‑growing private cloud companies. With over 2,000 customers and an ARR that has more than quadrupled in the past year, ClickHouse leads the market in...


  • , , Canada ClickHouse Full time

    Get AI-powered advice on this job and more exclusive features. About ClickHouse Established in 2009, ClickHouse leads the industry with its open-source column-oriented database system, driven by the vision of becoming the fastest OLAP database globally. The company enables real-time analytical reports through SQL queries, emphasizing speed in managing...


  • , , Canada GitLab Full time

    Join to apply for the Manager, Product Security Engineering role at GitLab . GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute,...


  • , , Canada Redis Full time

    Join to apply for the Senior Product Security Engineer role at Redis Who We Are We're Redis. We built the product that runs the fast apps our world runs on. (If you checked the weather, used your credit card, or looked at your flight status online today, you’re welcome.) At Redis, you’ll work with the fastest, simplest technology in the...


  • Vancouver, British Columbia, VCG, Canada D3 Security Management Systems Full time $65,000 - $100,000 per year

    Cyber Security EngineerLocation: Greater Vancouver area candidates onlyThe Opportunity:D3 Security is transforming SecOps with Morpheus, our AI-driven Autonomous Security Operations Center (ASOC) platform. Morpheus automates Tier 1–3 analyst work with unmatched precision, processing millions of alerts in real time and empowering security teams to respond...


  • , , Canada Redis Full time

    A leading tech company is seeking a Senior Product Security Engineer to drive application security innovations. In this role, you will protect software products using your skills in code analysis, vulnerability assessment, and security frameworks. Collaboration with engineering teams will be key to implementing security measures throughout the development...


  • , , Canada GitLab Full time

    A multinational technology company in Canada is seeking a Manager, Product Security Engineering. This role combines leadership in software engineering with security domain expertise to deliver security capabilities in GitLab's platform. The ideal candidate will have 3+ years of experience in software engineering management and a strong understanding of...


  • , BC, Canada AdaptiveMobile Security Full time

    Role Overview As a key player in the Customer Support team, you will work under the Customer Support Manager, troubleshooting complex technical issues, and collaborating closely with engineering and service delivery teams. You’ll combine technical expertise with excellent customer service, making you a vital part of our support operations. A degree in...


  • , , Canada Quora Full time

    Staff Product Security Software Engineer (Remote) ( Quora is a privately held, "remote-first" company . This position can be performed remotely from multiple countries around the world. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by country.)About QuoraQuora’s mission is to grow and share the world’s...