
Offensive Security Engineer
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Netherlands.
• Identify security vulnerabilities and gaps within ClickHouse offerings, and manage vulnerabilities reported through bug bounty programs, responsible disclosures, and GitHub Issues.
• Enhance and establish security assurance initiatives, which include penetration testing, vulnerability assessments, bug bounty programs, and fuzzing efforts.
• Strategize and carry out internal red team assessments and penetration tests across both infrastructure and cloud settings.
• Create realistic adversary scenarios to evaluate the effectiveness of detection, response, and control measures.
• Evaluate attack surfaces specific to AI/LLM, including prompt injection, model/data exfiltration, and unsafe agentic tool usage.
• Develop and manage agentic tools for reconnaissance, exploit chaining, attack-path discovery, and LLM-assisted fuzzing.
• Collaborate with detection engineering to confirm detection coverage and assess the time taken to detect and respond to threats.
• Manage information security incidents and events across ClickHouse products and services.
• Create processes, tools, and automation to enhance security operations and mitigate business risks.
• Over 7 years of experience in penetration testing, red teaming, and product security.
• Proven experience in supporting engineering and product implementation across web, API, and client/server systems.
• Practical experience with internal red teaming, penetration testing, and adversary simulation in cloud, network, and application environments.
• Capability to design adversary scenarios grounded in threat intelligence for a multi-tenant cloud data platform.
• Excellent written and verbal communication skills; ability to translate complex attack chains into actionable insights.
• Experience in building or modifying agentic and LLM-assisted offensive security tools.
• Familiarity with AI/LLM-specific vulnerability categories and testing methodologies.
• Comprehensive knowledge of one or more cloud providers such as AWS, GCP, or Azure.
• Experience with Kubernetes and Cilium.
• Proficiency in implementing and managing security tools and processes, including static/dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, and fuzzing tools.
• Security-as-code mindset focusing on automation and scalability.
• BS, MS, or PhD in Computer Science or a related field is considered a plus.
• Open-source contributions, security/cloud certifications, experience with AI security harnesses, internal red-team tooling experience, and offensive security certifications are also considered as bonus points.
• Flexible work environment; ClickHouse has a globally distributed team and supports remote work.
• Employer contributions towards healthcare expenses.
• Equity in the company; stock options available for every new team member.
• Flexible time off policy in the US, with generous entitlements in other countries.
• $500 allowance for remote employees to set up their home office.
• Opportunities for engagement with colleagues at company-wide offsite events.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.