SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ClickHouse, a Forbes Cloud 100 company and leader in real-time analytics and data warehousing, is seeking an experienced Offensive Security Engineer to join its Security Team. The role focuses on identifying and triaging security vulnerabilities across ClickHouse's multi-tenant cloud platform, including web, API, and server-client assets, with particular attention to memory-safety issues like heap and buffer overflows.
Key responsibilities include conducting internal red team assessments and penetration tests against ClickHouse infrastructure and cloud environments, designing realistic adversary scenarios grounded in threat intelligence relevant to data platforms. You will assess AI/LLM-specific attack surfaces, including prompt injection, model exfiltration, and unsafe agentic patterns. The role involves building and operating agentic tooling for reconnaissance, exploit-chaining, and attack-path discovery, leveraging LLM-assisted fuzzing to accelerate vulnerability discovery.
You will partner with detection engineering to validate detection coverage during red team exercises, measure control effectiveness, and report on time-to-detect and response metrics. Additional responsibilities include handling information security incidents, developing processes and automation to scale security operations, and improving security assurance activities through pentests, vulnerability assessments, and bug bounty program management.
The ideal candidate brings 7+ years of hands-on offensive security experience in pentesting, red teaming, and product security. You should have demonstrated expertise conducting red team exercises and penetration tests across cloud, network, and application environments. Strong experience with threat assessment, distributed systems security, and the ability to translate complex attack chains into actionable findings for engineering and leadership is essential. Experience building or adapting agentic and LLM-assisted tooling for offensive security, familiarity with AI/LLM vulnerability classes, and strong cloud platform knowledge (AWS, GCP, Azure, Kubernetes, Cilium) are highly valued. A security-as-code mindset with focus on automation and scalability is expected.