Threat Detections Engineer II

CLEAR

CLEAR

Austin, TX, USA
Posted on Dec 4, 2025

Have you ever had that green-light feeling? When you hit every green light and the day just feels like magic. CLEAR's mission is to create frictionless experiences where every day has that feeling. With more than 30+ million passionate members and hundreds of partners around the world, CLEAR’s identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or right on your phone, CLEAR connects you to the things that make you, you - unlocking easier, more secure, and more seamless experiences - making them all feel like magic.

We’re looking for a thoughtful and driven Threat Detection Engineer II to help strengthen CLEAR’s cyber defense capabilities. In this role, you’ll turn threat insights into meaningful action by designing, building, and refining the detections that keep our systems secure. You’ll spend your time developing reliable, high-quality detection logic, tuning existing rules to reduce noise, and automating key parts of the detection lifecycle so our teams can respond faster and more effectively.

You’ll partner closely with teammates across Automation, SIEM Logging, and Threat Intelligence, working together to expand visibility and stay ahead of emerging threats. The right candidate is curious, analytical, and comfortable rolling up their sleeves to solve complex problems. If you enjoy understanding how attackers operate and translating that knowledge into practical, scalable defenses, this is a great opportunity to make a direct impact in a fast-paced, collaborative environment.


What you’ll do

  • Design, implement, and tune custom detections that identify malicious or anomalous activity across a wide range of data sources.
  • Translate threat intelligence, incident learnings, and emerging trends into high-impact detection logic.
  • Partner closely with Threat Intelligence, Incident Response, Automation, and other security teams to operationalize new detections, refine response strategies, and improve overall signal fidelity.
  • Continuously assess detection performance by analyzing false positives, coverage gaps, and visibility across critical assets.
  • Support and expand automation efforts across the detection lifecycle—including development, validation, deployment, and routine maintenance.
  • Document detection logic, workflows, and data sources clearly and consistently to support repeatability and scale.
  • Map detection coverage to frameworks like MITRE ATT&CK and contribute to reducing measurable gaps over time.

What you’re great at:

  • Building, tuning, and validating detections in SIEM or cloud-native environments, with a strong understanding of networking, identity, endpoint telemetry, and modern attack techniques.
  • Spotting patterns across network, endpoint, identity, and cloud data—and using them to uncover meaningful signals in noisy environments.
  • Writing clear, scalable detection logic using rule languages, scripting, automation frameworks, and Detection-as-Code practices (e.g., GitHub workflows).
  • Collaborating across security functions and communicating effectively to align detection outcomes with broader defense and business objectives.
  • Staying curious, adaptable, and detail-oriented in a fast-moving threat landscape—constantly testing small improvements in tooling, process, and automation to drive program maturity.
  • Bringing hands-on experience with tools such as Google Chronicle, YARA/YARA-L, BigQuery, SOAR platforms, and scripting languages like Python.
  • Drawing on 3–5 years of experience in security operations or detection engineering; familiarity with frameworks like MITRE ATT&CK and Sigma; and leveraging relevant certifications (e.g., CISSP, Sec+) when helpful, though not required.

How You'll be Rewarded:

At CLEAR we help YOU move forward - because when you’re at your best, we’re at our best. You’ll work with talented team members who are motivated by our mission of making experiences safer and easier. In our offices, you’ll enjoy benefits like meals and snacks. We invest in your well-being and learning & development with our stipend and reimbursement programs.

We offer holistic total rewards, including comprehensive healthcare plans, family building benefits (fertility and adoption/surrogacy support), flexible time off, free OneMedical memberships for you and your dependents, and a 401(k) retirement plan with employer match.

Salaries will vary depending on various factors which include, but are not limited to location, education, skills, experience and performance. CLEAR’s total compensation package for employees and other rewards may include Restricted Stock Units.

CLEAR provides reasonable accommodation to qualified individuals with disabilities or protected needs. Please let us know if you require a reasonable accommodation to apply for a job or perform your job. Examples of reasonable accommodation include, but are not limited to, time off, extra breaks, making a change to the application process or work procedures, policy exceptions, providing documents in an alternative format, live captioning or using a sign language interpreter, or using specialized equipment.

#LI-Onsite