Principal Product Manager, Compliance & Security
New
C
ClickHouseCloud Infrastructure
Location: United StatesFull-TimePrincipal
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years
- Required Skills
- Product ManagementCompliance
Requirements
- 8+ years of product management experience, including building cloud infrastructure, platform, security, or enterprise SaaS products.
- Deep understanding of FedRAMP certification requirements and operating compliant multi-tenant cloud services.
- Strong technical understanding of modern cloud architectures across AWS, Azure, and GCP.
- Expertise in security domains including IAM, network isolation, private connectivity, encryption, key management (KMS/BYOK), and audit logging.
- Familiarity with global data residency and sovereignty requirements, including GDPR and regional frameworks.
- Proven ability to lead complex cross-functional initiatives involving engineering, security, compliance, legal, and GTM teams.
- Strong written and verbal communication skills with the ability to influence technical and executive audiences.
- Familiarity with US Government Security and Risk Frameworks (DOD IL, RMF).
- Experience with sovereign clouds, government cloud regions, and regulated industry offerings.
- Background in databases, data platforms, or infrastructure software.
- Experience commercializing open-source technologies for enterprise and government customers.
- Familiarity with FIPS 140-2/140-3 validation and government procurement.
Responsibilities
- Define and execute the multi-year roadmap for achieving ClickHouse for Government certifications (FEDRAMP, DOD-IL, StateRAMP, CJIS, etc).
- Partner with Security, Engineering, Compliance, Legal, GTM and Operations teams to ensure ClickHouse Cloud meets frameworks like SOC 2, ISO 27001/27701, HIPAA, and PCI DSS.
- Translate complex regulatory and security requirements into scalable product capabilities across IAM, encryption, key management, and audit logging.
- Drive product requirements for FIPS-compliant cryptographic modules and government-specific deployment models.
- Establish long-term strategy for enterprise security capabilities supporting regulated industries.
- Own product strategy and roadmap for sovereign cloud offerings, including European Sovereign Cloud and Kingdom of Saudi Arabia deployments.
- Deliver long-term Five-Eyes Sovereign Cloud Deployments.
- Define product capabilities addressing data residency, personnel access controls, and operational sovereignty.
View Full Description & ApplyYou'll be redirected to the employer's site