Governance, Risk, and Compliance Engineer
The Governance, Risk, and Compliance (GRC) Engineer at ClickHouse plays a pivotal role in ensuring the company's adherence to various compliance frameworks, thereby fostering trust among its diverse clientele. This position is integral to the GRC team, which is responsible for designing, implementing, and maintaining compliance programs tailored for ClickHouse's database-as-a-service platform utilized across multiple regulated industries. ClickHouse, recognized on the 2025 Forbes Cloud 100 list, is a rapidly growing private cloud company leading the market in real-time analytics, data warehousing, observability, and AI workloads.
In this role, the GRC Engineer collaborates cross-functionally to develop and sustain compliance programs, including but not limited to SOC 2, ISO 27001/27701, PCI-DSS, HIPAA, GDPR, and FedRAMP. Key responsibilities encompass working closely with the Engineering team to review and validate compliance-related product and infrastructure changes, conducting hands-on testing, and developing necessary documentation. The engineer also manages ongoing compliance operations such as employee security onboarding and training, third-party/vendor risk assessments, customer security questionnaires and audits, quarterly access reviews, ASV scans, and risk assessment refreshes. Additionally, the role involves supporting and enhancing access governance programs in partnership with Operations, and coordinating with Marketing, Privacy, and Legal teams to support privacy tooling and data protection initiatives.
Candidates for this position should possess a minimum of 7 years of experience in IT Audit, Governance, Risk & Compliance, and/or Information Security. A bachelor's degree in Computer Science, Information Technology, Information Systems Management, or equivalent practical experience is required. Relevant certifications such as CISA, PCI-P, or CIPP are highly desirable. The ideal candidate will have a strong working knowledge of major security and privacy frameworks, with hands-on experience interpreting and implementing controls in a cloud-based environment. Proficiency in using and administering GRC and security tooling, excellent written and verbal communication skills, and a strong problem-solving mindset are essential. The ability to operate effectively in a fast-paced, high-growth environment and to act as a trusted partner to the business is also crucial.
The typical starting salary for this role in the United States ranges from $131,000 to $205,000 USD, with higher ranges applicable in premium markets. ClickHouse offers a flexible work environment, being a globally distributed and remote-friendly company operating in 20 countries. Additional benefits include employer contributions towards healthcare, equity in the company through stock options, flexible time off in the US with generous entitlement in other countries, a $500 home office setup stipend for remote employees, and opportunities for in-person connection at company-wide offsites.
Joining ClickHouse means becoming part of a dynamic and innovative team that is shaping the future of data utilization. As part of the first 500 employees, new team members will have the opportunity to significantly influence the company's culture and growth trajectory. ClickHouse values motivated individuals who are eager to learn, collaborate, and contribute to building a culture of excellence and innovation.