CLEAR - Corporate · New York, NY

Salary
$225,000–$300,000from the description
Posted
Jul 1, 2026
Location
New York, NY
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

This role sits within a product security team and centers on running a vulnerability management program across cloud infrastructure, endpoints, and applications. Day-to-day work involves operating scanning tools, normalizing and deduplicating findings into a centralized platform, maintaining risk-scoring and SLA models, and collaborating with engineering teams to move vulnerabilities through to validated remediation. It suits an experienced security engineer comfortable with cloud-first environments and regulated compliance contexts.

Senior level · 6+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time

Must have (1)
Wiz, Tenable, Rapid7 or GHAS
Nice to have (2)
AWSJira

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 680 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 510–1,050

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (5)

The posted compensation range ($225,000–$300,000) explicitly combines base salary AND new hire equity (RSUs), so it is not a pure cash figure.

The JD is tagged '#LI-Onsite', confirming this is an in-person role. CLEAR's headquarters is in New York, NY, so the CBSA is set accordingly; no specific city is stated in the posting itself.

The one hard-gated tool requirement is 'at least one modern vulnerability or exposure management stack (e.g., Wiz, Tenable, Rapid7, GHAS, or similar)' — the JD explicitly names these as interchangeable examples, so Wiz is listed as the primary with the others as alternatives. Tenable, GHAS, and AWS appear prominently in the role's day-to-day work but are listed as examples or preferred context rather than independent hard gates, so they are marked preferred.

Regulated-environment experience (FedRAMP, PCI, SOC2) is listed under the requirements section but names no specific tool or technology — it is a domain knowledge requirement captured in the overall years minimum context rather than a named skill.

Jira is mentioned only in operational narrative (not a requirements section), so it is marked preferred.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗