Incident Response Security Engineer

ClickHouse ClickHouse · Data AI · APJ, United States · Security

ClickHouse is seeking an Incident Response Security Engineer to develop processes, tooling, and automation for incident management, collaborate with security and engineering teams, apply threat modeling, maintain the security logging platform, and handle security events across products and services. The role requires experience in product security, red teaming, or threat modeling, combined with incident detection and response, strong cloud provider knowledge (AWS, GCP, Azure), and development/automation skills, preferably in Golang and Python.

What you'd actually do

  1. Develop processes, tooling and automation to scale incident management response and mitigate risks to the business
  2. Collaborate with other security functions, engineering, product, support, business operations to identify appropriate detection use cases and automation
  3. Apply a threat modeling centric approach to incident detection and response
  4. Maintain security logging platform
  5. Stay up to date with the latest threats, attack vectors to improve our detection mechanisms and attack surface management
  6. Handle information security events and incidents across the ClickHouse products and services

Skills

Required

  • product security
  • red teaming
  • penetration testing
  • threat modeling
  • incident detection and response
  • AWS
  • GCP
  • Azure
  • Golang
  • Python

Nice to have

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)

What the JD emphasized

  • incident management response
  • detection use cases
  • threat modeling
  • security logging platform
  • latest threats
  • attack vectors
  • detection mechanisms
  • attack surface management
  • information security events
  • incidents