Optimum
Senior Product Security Engineer - Devices
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Optimum
Optimum Communications, Inc. is a prominent telecommunications company based in the U.S., serving approximately 4.5 million residential and business customers across 21 states, as well as in Canada, Puerto Rico, and the Virgin Islands. Headquartered in Long Island City, New York, Optimum is the fourth-largest cable provider in the country and operates as a Fortune 500 entity. The company offers a comprehensive range of services through its Altice One platform, which combines broadband internet, television, VoIP phone, and streaming applications. Optimum provides high-speed internet options, cable TV services, and mobile solutions, including VoIP and enterprise telephony. Additionally, it delivers business solutions such as managed Wi-Fi, collaboration tools, and advanced data services. Optimum also engages in advertising and media through audience-based multiscreen ads and data analytics. The company has transitioned from traditional copper-cable systems to modern fiber-optic networks, enhancing its service capabilities.
Security at Optimum
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Optimum's Product Security organization aims to help the company move faster securely, supporting developers in shipping secure code.
- They operate as an enabling team, conducting threat modeling and risk assessments.
- Key goals include automating security processes and fostering a security-first culture.
Security Team
Optimum's Product Security organization is led by Chris Stevens, VP Product Security. The team describes itself as engineers who enable other teams. While the exact reporting line and overall team size are not publicly available, there were at least two active job postings for Senior Product Security Engineers as of January 12, 2026. Common skills and tools mentioned in job postings include commercial and open-source security testing tools (SAST, DAST, SCA, fuzzing), experience securing CI/CD pipelines, Infrastructure-as-Code (IaC) tools like Terraform, and experience with Google Cloud Platform (GCP).
Key Initiatives
Optimum's AppSec initiatives include integrating security and secure-by-default guardrails into the product lifecycle and automating security processes from the developer workstation to the cloud, reflecting a 'Shift Left' approach. Their vulnerability management process involves rigorous security testing and reviews using commercial and open-source tools like SAST, DAST, SCA, and fuzzing. Secure SDLC artifacts include conducting threat modeling and risk assessments, and fostering a security-first culture with developer enablement. There is no public evidence of a formal Security Champions program or details on vulnerability triage SLAs, ticketing ownership, or MTTR. No recent AppSec-specific initiatives from the last six months were publicly found.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.