Plume
Senior Security Engineer
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Plume
Plume Design, Inc. is a Software-as-a-Service (SaaS) company based in Palo Alto, California. Founded in 2014, it specializes in adaptive, self-optimizing WiFi services and smart home network management solutions for Communications Service Providers (CSPs) and their subscribers, including households and small businesses. Plume's cloud-delivered platform enhances WiFi performance and network control using artificial intelligence and cloud data. The company offers a range of subscription-based digital services, including Adaptive WiFi, HomePass for managing home WiFi access, and WorkPass for remote work solutions. Plume's proprietary framework, OpenSync, allows CSPs to deliver WiFi services through compatible hardware, ensuring broad deployment options. With over 400 CSP partners worldwide, including major telecommunications companies, Plume focuses on scalable, cloud-based service delivery that adapts to user needs. The company is also dedicated to social responsibility, supporting education initiatives and fostering engineering talent.
Security at Plume
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Plume integrates security into its product development lifecycle and conducts security assessments during release.
- The company has invested in compliance, holding ISO27001 and ISO27701 certifications.
- Plume also maintains a public Vulnerability Disclosure Policy, offering a VDP form and an infosec contact, and commits to acknowledging reports within five business days.
Security Team
Plume's public leadership includes Dan Herscovici (President and CEO), Chris Griffiths (CTO), and Shari Piré (Chief Legal & Privacy Officer). While Plume is actively hiring for security roles, no public page explicitly names a Head of AppSec or CISO-level security leader. Information regarding the AppSec team's organizational reporting line is not publicly available.
Key Initiatives
Plume integrates security into its product development lifecycle, performing security assessments during release. The company operates a public Vulnerability Disclosure Policy (VDP) with a commitment to acknowledge reports within five business days. A senior security role indicates responsibilities including vulnerability program ownership and triage coordination. However, explicit details on a Security Champions program or specific SLAs/MTTR for vulnerability remediation are not publicly available.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.