Greenhouse CLEAR - Medium Logo

Greenhouse CLEAR - Medium

Staff Application Security Engineer

Posted One Month Ago
Be an Early Applicant
Easy Apply
In-Office
New York, NY
Senior level
Easy Apply
In-Office
New York, NY
Senior level
The Staff Application Security Engineer will conduct security assessments, perform penetration tests, and lead the implementation of security practices in the software development lifecycle.
The summary above was generated by AI

We are looking for a Staff Application Security Engineer to join our growing team. In this role, you will have the opportunity to take your penetration and overall application security testing to the next level. Our team performs everything from biometric and Web security testing to remediation, as well as creating automated security products, enabling stakeholders across CLEAR to deliver secure software.

What you'll do:

  • Partner with the company’s Product, Software Engineering, DevOps, and IT teams
  • Perform security risk assessments, manual penetration security testing, automate security testing, threat modeling, and develop/conduct education on secure coding
  • Deliver security products and consult with DevOps, as part of a high-profile security team, supporting automated security testing as part of CLEAR’s next generation CI/CD pipelines
  • Lead internal and external penetration tests across CLEAR’s most critical assets, as well as triage issues with internal stakeholders for remediation
  • Develop functional and non-functional security requirements
  • Conduct security assessments, code reviews, and penetration tests to identify vulnerabilities in applications and software
  • Implement and manage security tools, including SAST, DAST, SCA, and other security automation frameworks

How you'll measure success:

  • Effective implementation of security measures within the software development lifecycle, ensuring security is considered at every stage
  • Implementation of automated security testing tools and processes that streamline security assessments and minimize manual effort
  • Effective partnerships with engineering, DevOps, and product teams to create a security-first culture without hindering development velocity
  • Continuous improvement of application security programs, policies, and frameworks based on evolving threats and industry trends

What you're great at:

  • 7+ years of experience in software development and implementing security into SDLC processes; 3+ years relevant architecture experience with expert level knowledge of application systems design and integration
  • Comprehensive knowledge, experience, & understanding of testing for the OWASP Top 10 or CWE Top 25, including PoCs, automating attacks, and secure code remediation
  • Excellent interpersonal communication skills. Can explain very technical topics to all audiences and break down vulnerabilities to both developers and leadership
  • Strong understanding of Software Security Architecture and Design, SDLC, CI/CD, and the ability to clearly articulate best practices for application security
  • Experience with evaluating, deploying, and managing application security tools (e.g. DAST, SAST, IAST, RASP, WAF) and building strong vendor relationships
  • Familiarity with one or more industry standards and regulations such as PCI, NIST 800-53, FedRAMP and ISO27001
  • Strong programming and scripting experience in Python, BASH, Go, Java, JavaScript or similar
  • Experience using security testing tools such as Burp Suite, Metasploit, OWASP ZAP, nmap, Frida, etc.
  • Experience with mobile platform-specific security, privacy, and permission concepts for iOS & Android mobile platforms as well as mobile technologies such as WebViews, TouchID/FaceID API, etc.

How You'll be Rewarded:

At CLEAR we help YOU move forward - because when you’re at your best, we’re at our best. You’ll work with talented team members who are motivated by our mission of making experiences safer and easier. In our offices, you’ll enjoy benefits like meals and snacks. We invest in your well-being and learning & development with our stipend and reimbursement programs. We offer holistic total rewards, including comprehensive healthcare plans, family building benefits (fertility and adoption/surrogacy support), flexible time off, free OneMedical memberships for you and your dependents, and a 401(k) retirement plan with employer match. 

The base salary range for this role is $210,000 - $240,000, depending on levels of skills and experience.

The base salary range represents the low and high end of CLEAR’s salary range for this position. Salaries will vary depending on various factors which include, but are not limited to location, education, skills, experience and performance. The range listed is just one component of CLEAR’s total compensation package for employees and other rewards may include annual bonuses, commission, Restricted Stock Units.

About CLEAR

Have you ever had that green-light feeling? When you hit every green light and the day just feels like magic. CLEAR's mission is to create frictionless experiences where every day has that feeling. With more than 30+ million passionate members and hundreds of partners around the world, CLEAR’s identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or right on your phone, CLEAR connects you to the things that make you, you - unlocking easier, more secure, and more seamless experiences - making them all feel like magic.

CLEAR provides reasonable accommodation to qualified individuals with disabilities or protected needs. Please let us know if you require a reasonable accommodation to apply for a job or perform your job. Examples of reasonable accommodation include, but are not limited to, time off, extra breaks, making a change to the application process or work procedures, policy exceptions, providing documents in an alternative format, live captioning or using a sign language interpreter, or using specialized equipment.

#LI-Onsite

Top Skills

Bash
Burp Suite
Frida
Go
Java
JavaScript
Metasploit
Nmap
Owasp Zap
Python

Similar Jobs

16 Hours Ago
In-Office
2 Locations
Senior level
Senior level
eCommerce • Food • Sales • Software
The Director of Restaurant Analytics will lead the analytics function, align data priorities with business goals, and oversee multiple analytics teams to drive growth and operational excellence.
Top Skills: Power BIPythonSQLTableau
16 Days Ago
Hybrid
New York, USA
Entry level
Entry level
3D Printing
This is a position for a third job, specific responsibilities were not provided in the description.
24 Days Ago
In-Office
2 Locations
Senior level
Senior level
eCommerce • Food • Sales • Software
Manage sales commission operations, perform data analysis, oversee commission processing, collaborate across departments, and improve processes to optimize sales compensation.
Top Skills: ExcelSalesforceSpiff Sales And Commission Software

What you need to know about the Bengaluru Tech Scene

Dubbed the "Silicon Valley of India," Bengaluru has emerged as the nation's leading hub for information technology and a go-to destination for startups. Home to tech giants like ISRO, Infosys, Wipro and HAL, the city attracts and cultivates a rich pool of tech talent, supported by numerous educational and research institutions including the Indian Institute of Science, Bangalore Institute of Technology, and the International Institute of Information Technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account