Senior Product Security Engineer, Vulnerability Management

Clearfield, Inc.$225K — $300K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security engineering, vulnerability management, or security operations, preferably in cloud-first environments.
  • Hands-on experience with vulnerability management tools like Wiz, Tenable, Rapid7, or GHAS.
  • Comprehensive understanding of vulnerability management workflows including scanning, triage, ticketing, and reporting.
  • Familiarity with modern cloud services (AWS preferred) and infrastructure patterns.
  • Strong communication skills for translating technical findings to diverse audiences.
  • Experience in regulated environments such as FedRAMP, PCI, or SOC2.

Responsibilities

  • Monitor and triage findings from multiple vulnerability scanners, ensuring proper routing and prioritization.
  • Manage a centralized vulnerability management platform for consistent reporting and normalization of findings.
  • Oversee risk scoring and SLA models, ensuring overdue findings and top risks are tracked effectively.
  • Collaborate with technical teams to clarify findings and create actionable remediation plans.
  • Work with engineering to facilitate the deployment of fixes and resolve high-risk vulnerabilities.
  • Participate in triage sessions to prioritize backlog items and ensure issues are addressed promptly.
  • Contribute improvements to VM processes, tools, and documentation for operational efficiency.

Benefits

  • Catered lunches and fully stocked kitchens to promote workplace well-being.
  • Flexible time off and a wellness stipend to support employee health.
  • Family-building benefits including adoption and fertility support.
  • Free OneMedical memberships for employees and dependents.
  • A CLEAR Plus membership to enhance personal well-being.
  • 401(k) retirement plan with employer match for future financial security.
  • Stipends and reimbursement programs for ongoing learning and development.
Full Job Description
As a Senior Product Security Engineer, Vulnerability Management on our Product Security team you'll help run and evolve CLEAR's vulnerability management program across cloud, infrastructure, endpoints, and applications. You'll operate the tools that surface risk (like Wiz, Tenable, and Github), turn findings into clear, actionable work, and partner with engineering teams to drive down real-world risk. Not just tickets.

What you'll do:
  • Monitor and triage findings from Wiz, Tenable, GHAS, and other scanners, ensuring issues are routed to the right owners with the right context and priority.
  • Manage on our centralized VM platform that aggregates findings across Wiz, Tenable, GHAS, and other sources and ensure consistent normalization, deduplication, and ownership mapping (e.g., by AWS tags, teams, or services) so we have a single, trustworthy view of risk.
  • Manage CLEAR's risk scoring and SLA models (High/Critical, "Most Wanted" assets, ETC) within the VM platform and make sure we are tracking overdue findings, SLA adherence, backlog trends, and top risky assets/teams
  • Work directly with code, cloud, and endpoint teams to clarify findings, group related issues, and translate scanner output into concrete remediation plans that fit their roadmaps.
  • Partner with engineering to get fixes shipped
  • Participate in regular triage / review sessions, help prioritize backlog items, and follow through to ensure high-risk issues are validated and closed in the source tools (not just Jira).
  • Contribute to VM process and tool improvements with enhancements to connectors, data quality checks, scorecards, runbooks, and how-to guides so vulnerability management processes are repeatable and easy to onboard to.

How you'll measure success:
  • Cleaner, more accurate vulnerability data with fewer duplicates and orphaned tickets; consistent mapping between scanner findings, Jira issues, and asset/ownership data across Wiz, Tenable, and other tools.
  • Improved remediation outcomes with a reduction in High/Critical vulnerabilities out of SLA, especially on top-risk assets and services, and visible burn-down in dashboards and scorecards.
  • Operational efficiency and predictability with less manual reconciliation across tools and spreadsheets; more of the VM workflow (triage, routing, validation, reporting) running through standard playbooks and automation.
  • Trust in reporting as Security, Engineering, and Compliance stakeholders rely on VM dashboards as the single source of truth for vulnerability posture, SLAs, and exceptions.

What you're great at:
  • 6+ years of experience in security engineering, vulnerability management, or security operations, ideally in a cloud-first or SaaS environment.
  • Hands-on experience working with at least one modern vulnerability or exposure management stack (e.g., Wiz, Tenable, Rapid7, GHAS, or similar).
  • Understanding of end-to-end VM workflows: scanning, triage, risk scoring, ticketing, validation, and reporting.
  • Working knowledge of modern cloud and infrastructure patterns (AWS preferred), including how services, hosts, containers, and repos map to real teams and products.
  • Strong written and verbal communication skills; can explain vulnerabilities, risk tradeoffs, and SLAs to both deeply technical engineers and non-technical stakeholders.
  • Experience supporting regulated environments (e.g., FedRAMP, PCI, SOC2) and preparing vulnerability-related evidence for audits.

How You'll be Rewarded:

At CLEAR, we help YOU move forward - because when you're at your best, we're at our best. You'll work with talented team members motivated by our mission of making experiences safer and easier. Our offices are bright and energetic with an open concept and plenty of conference rooms and casual co-working spaces. We also offer catered lunches every day and have fully stocked kitchens. Outside of the office, we invest in your well-being and learning & development with stipends and reimbursement programs.

We offer holistic total rewards, including comprehensive healthcare plans, family-building benefits (fertility and adoption/surrogacy support), flexible time off, annual wellness stipend, free OneMedical memberships for you and your dependents, a CLEAR Plus membership, and a 401(k) retirement plan with employer match. The total compensation range for this role is $225,000 -$300,000, depending on levels of skills and experience.

This range represents the combined base salary and new hire equity package (in Restricted Stock Units) for this position at CLEAR. Additionally, this role will be eligible for refresh equity grants as part of our ongoing compensation program. Actual compensation will vary based on factors including, but not limited to, location, education, skills, experience, and performance. All stock based compensation will be subject to the terms and conditions of applicable agreements.

#LI-Onsite

About Clearfield, Inc.

Clearfield, Inc. is a US-based company that designs, manufactures, and distributes fiber optic management products. The company's products are used in the telecommunications industry to manage fiber optic cables and connections. Clearfield's products include fiber distribution hubs, optical components, and cabinets. The company was founded in 1979 and is headquartered in Brooklyn Park, Minnesota. Clearfield has a global presence with offices in the United States, Canada, and China.
Learn more about Clearfield, Inc.
Size
250 employees
Market Cap
$1.4 billion
Industry
Net Income
$9.9 million
5 Year Trend
+29.6%
Revenue
$100.7 million
NASDAQ

Similar Jobs

More Jobs at Clearfield, Inc.

More Information Technology Jobs

Find similar Senior Product Security Engineer, Vulnerability Management jobs: