Senior Security Automation Engineer
Key details
Job Description
The Security organization at ClickHouse is built around a single mission: build customer trust through resilient, pragmatic security. We are establishing a new, centralized Security Automation capability—a dedicated function responsible for delivering automation work across all product lines and engineering dimensions at ClickHouse, acting as a technical force multiplier for our Security, Identity, and GRC functions.
This capability exists to solve a real problem: as we scale and mature, we must move beyond manual evidence gathering, point-in-time audits, and disconnected identity workflows. We are creating a focused, empowered team that owns security and identity automation end-to-end—from architecture and design through to implementation and delivery.
About the role
We are looking for an experienced Senior Security Automation Engineer to build the underlying automation fabric that allows our Security teams to scale. You will build a Universal Provisioning Engine and custom integration layers that satisfy external auditors while keeping internal teams focused on shipping features.
You will eliminate the engineering "interruption tax," provide leadership with a real-time, data-driven view of our risk posture, and ensure continuous compliance with zero audit surprises. By solving the "Last-Mile Gap" in identity provisioning and extending compliance tools into our proprietary applications, you will ensure our most critical controls are continuously validated with programmatic precision.
What you will do:
Build the Security Telemetry and Risk Fabric
- Control Design: Translate control frameworks into layered control implementations that prevent risks from being exploited and detect possible weaknesses within control design. Shift from reactive monitoring to self-healing security, preventing compliance drift before it becomes an audit finding.
- Security Telemetry: Engineer a centralized security telemetry system that programmatically captures control evidence and health in real-time, transitioning from manual snapshots to continuous data streams for an 'always-on' view of our security posture.
- Custom Assurance Logic: Engineer specialized automation that acts as its own continuous audit function to minimize findings and provide real-time insights into our automated control performance. Extend visibility into our proprietary applications and complex internal workflows, ensuring our most critical controls are continuously validated.
- Agentic Risk Engine: Partner with our risk management function to build a secure mechanism to generate agentic risk assessments workflows using the data and results from what is collected.
Architect Universal Identity and Access Automation
- Universal Provisioning Connectors: Architect solutions for systems that lack native IGA support (proprietary databases, custom apps, and niche SaaS) to ensure instant account creation and de-provisioning—eliminating tickets, wait-times, and providing maximum observability into the state of Clickhouse identities.
- Customer-Approved Access Workflows: Architect the complex, high-trust workflows required for support teams to access customer-specific instances, ensuring actions are customer-approved, strictly time-bound, and automatically revoked via a "Trust-by-Design" model.
- Centralized Security Visibility: Transition "hidden" access managed by disparate business units into a single, observable permissions inventory, gaining 100% visibility into permissions at the authZ level across our full suite of applications.
- Automated Secret Discovery & Inventory: Develop automation to continuously discover and inventory secrets, credentials, and API keys throughout the environment, providing aging and rotation intervals for long lived keys.
- Eliminate "Ghost Accounts": Mitigate audit risks by ensuring automated de-provisioning for local identities, API keys, and persistent permissions across all target systems.
Partner Across Security, Engineering and Product
- Work in tandem with GRC, Finance, and Security to build custom, bulletproof automation for compliance with different audit frameworks.
- Eliminate the "Productivity Anchor" by removing manual provisioning workflows that slow down projects and flood teams with low-value administrative tickets.
What you bring along:
Security & Automation Engineering Depth
- Strong hands-on background in security automation and identity engineering (IAM/IGA).
- Strong proficiency in at least one commonly used programming language to build scalable automation. Experience with Python, JavaScript (TypeScript highly preferred), or Go is required.
- Experience building scalable and reliable automation ecosystems
- Familiarity with compliance automation, continuous control monitoring, and extending GRC tools to meet the granular requirements of a variety of compliance frameworks.
- Understanding of risks associated with change management, logical access, and data integrity.
Execution and Delivery
- Demonstrated ability to translate complex security/GRC mandates into automated workflows and self-healing technical guardrails.
- Strong instincts for eliminating operational friction and the engineering "interruption tax."
- Experience delivering continuous data streams for security posture and risk validation.
Bonus Points:
- BS, MS, or PhD in Computer Science or related field.
- Previous experience at a cloud infrastructure, database, or developer tools company.
- Experience with AI/Agentic risk engines and non-deterministic risk assessments.
Audit details(provenance, verification trail, raw fields)
Core fields
clickhouse:41097fad-01fe-4877-a038-1afde8e18a64Provenance
clickhouseVerification trail
This posting hasn't been probed by our closure verifier yet. Stream C runs on a rolling schedule against postings approaching the close-decision threshold.
See how we measure for definitions, or our corrections log for known issues. Found something wrong? Flag a correction.
