Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Product Security Engineer (Cloud/C++): Improving the security posture of cloud platforms and OSS by implementing secure features and mitigating vulnerabilities with an accent on threat modeling, assurance, and secure implementation. Focus on triaging complex vulnerabilities like memory overflows, developing security automation, and integrating engineering security tools.
Location: Must be based in the Netherlands (fully remote within the country)
Company
An innovative cloud company leading the market in real-time analytics and AI workloads, recognized on the Forbes Cloud 100 list.
What you will do
- Collaborate with engineering to build secure product features, including key management, passwordless authentication, and network isolation.
- Identify and triage vulnerabilities in ClickHouse Cloud and OSS, including low-level memory issues like heap or buffer overflows.
- Develop and improve security assurance activities such as pentests, fuzzing, and bug bounty programs.
- Implement and manage engineering security tools like Snyk, Semgrep, and GitHub CodeQL.
- Handle information security events and incidents across all products and services.
- Build automation and tooling to scale security processes and mitigate business risks.
Requirements
- Experience performing threat assessments and assurance for distributed systems covering web, API, and client/server assets.
- Strong knowledge of cloud providers (AWS, GCP, Azure), Kubernetes, and Cilium.
- Experience with security tools including SAST/DAST, SCA, SBOM, and OWASP SAMM.
- Significant development experience with the ability to work with C++ code.
- Security-as-code mindset focused on solving problems with automation and scale.
Nice to have
- BS, MS, or PhD in Computer Science or related field.
- Previous contributions to open source projects.
- Cloud-related certifications from AWS, GCP, or Azure.
Culture & Benefits
- Flexible work environment in a globally distributed, remote-friendly company.
- Employer contributions towards healthcare.
- Equity in the company via stock options for every new team member.
- Generous time off and a $500 home office setup budget for remote employees.
- Opportunities for in-person connection at company-wide offsites.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →