Incident Response Security Engineer

ClickHouse ClickHouse · Data AI · APJ, United States · Security

This role focuses on developing processes, tooling, and automation for incident management and response within a security team. It involves maintaining a security logging platform, applying threat modeling, and handling security events across products and services. The role requires experience in product security, red teaming, or penetration testing, combined with incident detection and response.

What you'd actually do

  1. Develop processes, tooling and automation to scale incident management response and mitigate risks to the business
  2. Collaborate with other security functions, engineering, product, support, business operations to identify appropriate detection use cases and automation
  3. Apply a threat modeling centric approach to incident detection and response
  4. Maintain security logging platform
  5. Stay up to date with the latest threats, attack vectors to improve our detection mechanisms and attack surface management
  6. Handle information security events and incidents across the ClickHouse products and services

Skills

Required

  • Background in product security / red teaming / penetration testing / threat modeling, combined with incident detection and response experience
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure)
  • Excellent written and verbal communication skills
  • Experience securing large-scale customer-facing cloud infrastructures
  • Significant development and automation experience; preference for Golang and Python

Nice to have

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)

What the JD emphasized

  • incident management response
  • detection use cases
  • threat modeling
  • security logging platform
  • latest threats
  • attack vectors
  • detection mechanisms
  • attack surface management
  • information security events
  • incidents