Manager, Information Security

ClickHouse ClickHouse · Data AI · United States · Product Management

Product Manager for Information Security focusing on regulated cloud offerings, certifications, and specialized regional deployments. This role requires defining and executing roadmaps for government certifications (e.g., FedRAMP, DOD-IL), ensuring compliance with various security frameworks (SOC 2, ISO 27001, HIPAA, etc.), and driving product requirements for security capabilities like IAM, encryption, and audit logging. The role also involves owning the strategy for sovereign cloud offerings and addressing data residency and operational sovereignty requirements.

What you'd actually do

  1. Define and execute the multi-year roadmap for achieving ClickHouse for Government certifications (FEDRAMP, DOD-IL, StateRAMP, CJIS, etc)
  2. Partner closely with Security, Engineering, Compliance, Legal, GTM and Operations teams to ensure ClickHouse Cloud meets the requirements of frameworks including SOC 2, ISO 27001/27701, HIPAA, PCI DSS, and government-specific standards (FIPS, Common Criteria / Protection Profile, NIST SP800-171, CMMC, Sec 508/VPAT, DISA STIG).
  3. Translate complex regulatory and security requirements into scalable product capabilities across identity and access management (IAM), encryption, key management, audit logging, access controls, and operational security.
  4. Own the product strategy and roadmap for sovereign cloud offerings, including the European Sovereign Cloud (ESC), Kingdom of Saudi Arabia (KSA), and future sovereign cloud regions.
  5. Own and deliver long-term Five-Eyes Sovereign Cloud Deployments

Skills

Required

  • Product management experience
  • Cloud infrastructure, platform, security, or enterprise SaaS product experience
  • FedRAMP certification requirements
  • Compliant multi-tenant cloud services
  • Modern cloud architectures (AWS, Azure, GCP)
  • Security domains (IAM, network isolation, encryption, key management, audit logging, access controls)
  • Global data residency and sovereignty requirements
  • Cross-functional initiative leadership
  • Written and verbal communication skills

Nice to have

  • US Government Security and Risk Frameworks (FEDRAMP, DOD IL, RMF, etc)
  • Sovereign clouds, government cloud regions, and regulated industry offerings
  • Databases, data platforms, analytics, or infrastructure software
  • Commercializing open-source technologies
  • FIPS 140-2/140-3 validation requirements
  • Government procurement processes
  • Federal, defense, intelligence, or public-sector customer experience
  • Security clearance

What the JD emphasized

  • 8+ years of product management experience
  • Deep understanding of FedRAMP certification requirements
  • Strong technical understanding of modern cloud architectures
  • Experience with security domains including IAM, network isolation, private connectivity, encryption, key management systems (KMS/BYOK), audit logging, and access controls.
  • Familiarity with global data residency and sovereignty requirements