Senior Product Security Engineer
CommandLinkAbout the role
About Command|Link
Command|Link is a global SaaS Platform providing network, voice services, and IT security solutions, helping corporations consolidate their core infrastructure into a single vendor and layering on a proprietary single pane of glass platform. Command|Link has revolutionized the IT industry by tackling the problems our competitors create. In recognition for our unprecedented innovation and dedication, Command|Link was recognized as the SD-WAN Product of the Year, ITSM Visionary Spotlight, UCaaS Product of the Year, NaaS Product of the Year, Supplier of the Year, and the AT&T Strategic Growth Partner. Command|Link has built the only IT platform for scale that solves ISP vendor sprawl and IT headaches. We make it easy for our customers to get more done, maximize uptime and improve the bottom line.
Learn more about us here!
This is a remote position open to candidates residing in the following states: Alabama, Arizona, Arkansas, Florida, Georgia, Indiana, Kansas, Kentucky, Louisiana, Maryland, Michigan, Mississippi, Missouri, Nevada, New Hampshire, North Carolina, Ohio, Oklahoma, South Carolina, Tennessee, Texas, Utah, Virginia, Wisconsin
About your new role:
We are not looking for a security checkbox-filler. We are looking for a senior security engineer who is ready to take deep ownership of our product security posture by elevating our practices, formalizing programs, and driving measurable outcomes across a fast-moving engineering organization.
You will operate at the intersection of engineering and security, partnering directly with engineering leaders and product teams to embed security into every layer of our SDLC. You'll own our vulnerability management posture, drive secrets hygiene and credential lifecycle practices across the organization and drive our threat modeling framework deeper into how we design and ship software. Your work will protect the infrastructure of thousands of enterprise customers who depend on Command|Link every day.
This role requires someone who can lead without authority, establish credibility with engineering teams, drive measurable outcomes, and build the institutional muscle that scales as the company grows.
Key Responsibilities:
Vulnerability Management Program:
- Own and advance Command|Link's vulnerability management program end-to-end, from tooling and deployment through SLA definition and enforcement.
- Define and drive quarterly vulnerability targets, including the goal of zero critical vulnerabilities outstanding across all engineering teams each quarter.
- Partner with engineering leads to integrate vulnerability scanning into CI/CD pipelines and create visibility dashboards that hold teams accountable.
- Triage, prioritize, and track remediation of findings across our cloud infrastructure, application layer, and third-party dependencies.
Secrets Hygiene & Credential Lifecycle:
- Own and drive our company-wide secrets management program, maintaining and enforcing clear standards for how credentials are created, stored, rotated, and retired.
- Partner with engineering teams to meet regular credential rotation targets and enforce consistent hygiene practices across the organization.
- Champion the adoption of dynamic secrets management and modern identity-based access patterns as the default over long-lived static credentials.
- Implement controls and processes to maintain ongoing visibility into credential health and reduce the risk surface associated with credential mismanagement.
Threat Modeling Program:
- Lead and deepen our threat modeling framework, ensuring security evaluation is woven into the SDLC well before features reach production.
- Develop threat modeling templates, playbooks, and training materials that enable engineering teams to self-serve on security reviews for new features and services.
- Conduct threat models for high-risk features, new service designs, and major architecture changes, producing actionable remediation guidance.
- Ensure security requirements derived from threat models are tracked as first-class engineering deliverables.
Security Champion & Culture:
- Act as the inte
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s