Detection and Incident Response Security Engineer

ClickHouse ClickHouse · Data AI · Security

This role focuses on developing processes, tooling, and automation for incident response and detection within ClickHouse's security team. It involves collaborating with various teams to identify detection use cases, applying threat modeling, and maintaining the security logging platform. The ideal candidate has a background in product security, red teaming, or penetration testing, combined with incident detection and response experience, and strong cloud infrastructure security skills.

What you'd actually do

  1. Develop processes, tooling and automation to scale incident management response and mitigate risks to the business
  2. Collaborate with other security functions, engineering, product, support, business operations to identify appropriate detection use cases and automation
  3. Apply a threat modelling centric approach to incident detection and response
  4. Maintain security logging platform
  5. Handle information security events and incidents across the ClickHouse products and services

Skills

Required

  • Background in product security / red teaming / penetration testing / threat modelling, combined with incident detection and response experience
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure)
  • Significant development and automation experience; preference for Golang and Python

Nice to have

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications

What the JD emphasized

  • detection and incident response
  • threat modelling