Detection and Incident Response Security Engineer

ClickHouse ClickHouse · Data AI · Security

This role focuses on developing processes, tooling, and automation for incident management response and risk mitigation within a security team. It involves collaborating with various departments to identify detection use cases, applying threat modeling, maintaining a security logging platform, and handling security events and incidents across products and services. The ideal candidate has a background in product security, red teaming, penetration testing, or threat modeling, combined with incident detection and response experience, and strong cloud infrastructure security skills.

What you'd actually do

  1. Develop processes, tooling and automation to scale incident management response and mitigate risks to the business
  2. Collaborate with other security functions, engineering, product, support, business operations to identify appropriate detection use cases and automation
  3. Apply a threat modelling centric approach to incident detection and response
  4. Maintain security logging platform
  5. Handle information security events and incidents across the ClickHouse products and services

Skills

Required

  • Background in product security / red teaming / penetration testing / threat modelling
  • Incident detection and response experience
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure)
  • Excellent written and verbal communication skills
  • Experience securing large-scale customer-facing cloud infrastructures
  • Significant development and automation experience
  • Golang
  • Python

Nice to have

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications

What the JD emphasized

  • incident management response
  • detection use cases
  • incident detection and response
  • security logging platform
  • information security events and incidents