Role Overview
CLEAR is seeking a Threat Detection Analyst III to join our SOC team to help strengthen our ability to detect, investigate, and respond to evolving security threats. In this role, you’ll lead complex investigations, improve CLEAR’s threat detection and response capabilities, and serve as a trusted security partner while helping develop the analysts and program around you.
About Clear
CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel.
Key Responsibilities
- Lead complex investigations of security events across corporate networks, endpoints, data centers, cloud environments, and other critical systems, driving incidents from initial analysis through escalation and remediation
- Develop, tune, and optimize threat detection logic across SIEM, EDR, and other security platforms, proactively identifying coverage gaps, reducing false positives, and improving the fidelity of security alerts
- Partner with Engineering, Infrastructure, and other teams to investigate threats, identify root causes, communicate risk, and drive timely remediation and improvements to CLEAR’s security posture
- Apply threat intelligence, data, automation, and AI-enabled tools to identify emerging attack patterns, accelerate investigations, improve detection workflows, and strengthen decision-making while applying sound security judgment
- Serve as a subject matter expert and escalation point for other analysts, mentoring junior team members, sharing knowledge, and helping establish scalable processes, playbooks, and standards for threat detection and analysis
- Continuously evaluate CLEAR’s detection coverage against the evolving threat landscape and frameworks such as MITRE ATT&CK, identifying opportunities to improve visibility and proactively defend against emerging threats
- Lead improvements to Security Operations workflows, standard operating procedures, documentation, and tooling to increase the quality, consistency, and efficiency of threat analysis and incident response
- Clearly communicate technical findings, risk, and recommended actions to technical and non-technical stakeholders, tailoring the level of detail to the audience
Requirements & Eligibility
- 8+ years of cybersecurity experience, including 5+ years in security operations, threat detection, incident response, or a related discipline
- Deep knowledge of SIEM, EDR, and security monitoring technologies, with demonstrated experience investigating complex events and developing, tuning, and optimizing detection logic
- Applying threat intelligence and frameworks such as MITRE ATT&CK, NIST CSF, or ISO 27001 to identify adversary behavior, evaluate detection coverage, and strengthen security controls
- Using data, automation, scripting, and AI-enabled security tools to improve threat detection and investigation workflows while applying strong analytical judgment to validate findings and make informed decisions
- Solving complex security problems independently, communicating findings clearly, building trusted cross-functional relationships, and mentoring other analysts
Required Skills & Tech
SIEMEDRMITRE ATT&CKNIST CSFISO 27001Security OperationsThreat DetectionIncident ResponseScripting