Senior Security Automation Engineer

ClickHouse ClickHouse · Data AI · EMEA · Security

Senior Security Automation Engineer to build the underlying automation fabric for security teams, focusing on a Universal Provisioning Engine and custom integration layers for auditors and internal teams. The role aims to eliminate engineering interruption tax, provide real-time risk posture visibility, and ensure continuous compliance.

What you'd actually do

  1. Translate control frameworks into layered control implementations that prevent risks from being exploited and detect possible weaknesses within control design.
  2. Engineer a centralized security telemetry system that programmatically captures control evidence and health in real-time, transitioning from manual snapshots to continuous data streams for an 'always-on' view of our security posture.
  3. Engineer specialized automation that acts as its own continuous audit function to minimize findings and provide real-time insights into our automated control performance.
  4. Partner with our risk management function to build a secure mechanism to generate agentic risk assessments workflows using the data and results from what is collected.
  5. Architect solutions for systems that lack native IGA support (proprietary databases, custom apps, and niche SaaS) to ensure instant account creation and de-provisioning—eliminating tickets, wait-times, and providing maximum observability into the state of Clickhouse identities.

Skills

Required

  • Python, JavaScript (TypeScript highly preferred), or Go
  • Security automation
  • Identity engineering (IAM/IGA)
  • Building scalable and reliable automation ecosystems
  • Compliance automation
  • Continuous control monitoring
  • Understanding of risks associated with change management, logical access, and data integrity

Nice to have

  • TypeScript

What the JD emphasized

  • build the underlying automation fabric
  • Universal Provisioning Engine
  • external auditors
  • internal teams focused on shipping features
  • eliminate the engineering "interruption tax"
  • real-time, data-driven view of our risk posture
  • continuous compliance with zero audit surprises
  • solving the "Last-Mile Gap" in identity provisioning
  • extending compliance tools into our proprietary applications
  • continuously validated with programmatic precision
  • prevent risks from being exploited
  • detect possible weaknesses within control design
  • Shift from reactive monitoring to self-healing security
  • preventing compliance drift before it becomes an audit finding
  • programmatically captures control evidence and health in real-time
  • continuous data streams for an 'always-on' view of our security posture
  • acts as its own continuous audit function
  • minimize findings
  • real-time insights into our automated control performance
  • Extend visibility into our proprietary applications and complex internal workflows
  • continuously validated
  • secure mechanism to generate agentic risk assessments workflows
  • systems that lack native IGA support
  • instant account creation and de-provisioning
  • eliminating tickets, wait-times
  • maximum observability into the state of Clickhouse identities
  • complex, high-trust workflows
  • customer-approved, strictly time-bound, and automatically revoked
  • single, observable permissions inventory
  • gaining 100% visibility into permissions at the authZ level
  • continuously discover and inventory secrets, credentials, and API keys
  • aging and rotation intervals for long lived keys
  • Mitigate audit risks
  • automated de-provisioning
  • build custom, bulletproof automation for compliance
  • Eliminate the "Productivity Anchor"
  • removing manual provisioning workflows
  • security automation and identity engineering (IAM/IGA)
  • build scalable automation
  • building scalable and reliable automation ecosystems
  • compliance automation, continuous control monitoring
  • extending GRC tools
  • risks associated with change management, logical access, and data integrity
  • translate complex security/GRC mandates into automated