SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Product Security Engineer

CLEAR - New York, NY, United States - In-office - posted 2026-07-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 225,000 - 300,000 / annual

CLEAR is building a secure identity platform serving 43+ million members globally, transforming how people live, work, and travel through frictionless identity verification at airports, stadiums, and everyday locations. As a Senior Product Security Engineer on the Product Security team, you will lead and evolve CLEAR's vulnerability management program across cloud infrastructure, endpoints, and applications. You'll operate industry-standard tools (Wiz, Tenable, GitHub Advanced Security) to surface and prioritize security risks, then partner with engineering teams to drive real-world remediation—not just ticket creation. Key responsibilities include: - Monitor and triage findings from multiple scanners, routing issues to the right owners with proper context and priority - Manage a centralized vulnerability management platform that aggregates findings, ensuring consistent normalization, deduplication, and ownership mapping across AWS tags, teams, and services - Establish and maintain risk scoring and SLA models (High/Critical classifications, "Most Wanted" assets) and track overdue findings, SLA adherence, backlog trends, and risky assets/teams - Work directly with code, cloud, and endpoint teams to clarify findings, group related issues, and translate scanner output into concrete remediation plans - Partner with engineering to validate fixes and ensure closure in source tools - Participate in regular triage sessions, prioritize backlogs, and drive high-risk issue resolution - Improve vulnerability management processes through enhancements to connectors, data quality checks, scorecards, runbooks, and documentation Success is measured by cleaner vulnerability data with fewer duplicates, improved remediation outcomes (fewer High/Critical vulnerabilities out of SLA), reduced manual reconciliation across tools, and increased stakeholder trust in VM dashboards as the single source of truth for vulnerability posture. You bring 6+ years of security engineering or product security experience, ideally in cloud-first or SaaS environments. You have hands-on experience with modern vulnerability/exposure management stacks (Wiz, Tenable, Rapid7, GHAS, or similar) and understand end-to-end VM workflows: scanning, triage, risk scoring, ticketing, validation, and reporting. You're comfortable with modern cloud and infrastructure patterns (AWS preferred) and can explain vulnerabilities and risk tradeoffs to both technical engineers and non-technical stakeholders. Experience supporting regulated environments (FedRAMP, PCI, SOC2) and audit preparation is valued.

Similar roles