Threat Detection Analyst III
- Company
- CLEAR
- Location
- New York, NY
- Work type
- Full Time
- Posted
- 2026-10-05
Job description
What you'll do:
Lead complex investigations of security events across corporate networks, endpoints, data centers, cloud environments, and other critical systems, driving incidents from initial analysis through escalation and remediation
Develop, tune, and optimize threat detection logic across SIEM, EDR, and other security platforms, proactively identifying coverage gaps, reducing false positives, and improving the fidelity of security alerts
Partner with Engineering, Infrastructure, and other teams to investigate threats, identify root causes, communicate risk, and drive timely remediation and improvements to CLEAR’s security posture
Apply threat intelligence, data, automation, and AI-enabled tools to identify emerging attack patterns, accelerate investigations, improve detection workflows, and strengthen decision-making while applying sound security judgment
Serve as a subject matter expert and escalation point for other analysts, mentoring junior team members, sharing knowledge, and helping establish scalable processes, playbooks, and standards for threat detection and analysis
Continuously evaluate CLEAR’s detection coverage against the evolving threat landscape and frameworks such as MITRE ATT&CK, identifying opportunities to improve visibility and proactively defend against emerging threats
Lead improvements to Security Operations workflows, standard operating procedures, documentation, and tooling to increase the quality, consistency, and efficiency of threat analysis and incident response
Clearly communicate technical findings, risk, and recommended actions to technical and non-technical stakeholders, tailoring the level of detail to the audience
Participate in the Security Operations on-call rotation and respond to critical security events and incidents outside of standard working hours, as needed
How you'll measure success:
High-quality, accurate investigations that lead to timely containment, remediation, and actionable security improvements
Measurable improvements in Security Operations workflows, detection logic, automation, and analyst efficiency
Increased team capability through effective mentorship, knowledge sharing, documentation, and scalable operating practices
Improved detection coverage, alert fidelity, and time to identify and respond to security threats
What you're great at:
8+ years of cybersecurity experience, including 5+ years in security operations, threat detection, incident response, or a related discipline
Deep knowledge of SIEM, EDR, and security monitoring technologies, with demonstrated experience investigating complex events and developing, tuning, and optimizing detection logic
Applying threat intelligence and frameworks such as MITRE ATT&CK, NIST CSF, or ISO 27001 to identify adversary behavior, evaluate detection coverage, and strengthen security controls
Using data, automation, scripting, and AI-enabled security tools to improve threat detection and investigation workflows while applying strong analytical judgment to validate findings and make informed decisions
Solving complex security problems independently, communicating findings clearly, building trusted cross-functional relationships, and mentoring other analysts
Certifications such as GCIH, GCIA, OSCP are a plus
Experience working across teams and functions to deliver on strategic, program-level goals