> Markdown version of [/jobs/ext/264230-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/264230-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** PLAUD INC. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Cursor (Graphical User Interface Elements), Identity and Access Management, Intrusion Detection and Prevention, Security Information and Event Management, Large Language Models, Mitre Att&ck, CIS Benchmarks, Terraform, GPT, Security Orchestration, Automation & Response - **Published:** May 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=611f13cbcf9ad901 ## About the Role Do you have experience in Security engineering?, * 5+ years of hands-on security engineering experience with demonstrable depth in at least one of: cloud security (AWS/GCP, CSPM, IAM, IaC) or security operations (SIEM, IR, SOAR, detection engineering) - and working fluency in the other. * Proven ability to build security infrastructure from zero: tool selection, baseline configuration, and policy definition without inheriting a mature program or existing runbook. * Strong working knowledge of MITRE ATT&CK, CIS Benchmarks (L1/L2), cloud-native security tooling (AWS Security Hub, GCP SCC, or equivalent CSPM), and log source integration across cloud and endpoint layers. * Familiarity with SOC 2 TII control requirements - specifically CC6 (logical access), CC7 (monitoring & detection), and the operational evidence standards expected by a third-party auditor. * Routinely uses LLMs as part of daily security workflow - alert summarization, detection rule generation, SOAR playbook drafting, or IaC policy automation. Will demo last-2-weeks AI usage during interview. ## Description * You will own both the detection & response layer and the cloud infrastructure security foundation at Plaud - two domains that must operate in lockstep to deliver SOC 2 Type II audit readiness by Q4 2026. * Cloud & Infrastructure Security - Remediate credential exposure across AWS/GCP production environments, deploy and tune CSPM across all accounts, embed IaC security gates (Checkov/Terraform) into CI/CD, and implement Zero Standing Privileges via JIT/CIEM. * SIEM Build & Detection Engineering - Deploy the SIEM platform and author 30+ MITRE ATT&CK-mapped detection rules spanning cloud telemetry, endpoint, and SaaS - with ongoing tuning to reduce false positives and maintain coverage fidelity. * Incident Response - Own the IR lifecycle end-to-end: develop playbooks across a minimum of 4 incident categories, lead cross-functional response for P1/P2 events, and drive MTTD to 60 minutes. * SOC 2 TII Operational Evidence - Produce and maintain the continuous evidence package required for audit - log retention, alert records, control review cadences, and written control narratives for Cloud Security and SecOps domains. * Security Reporting & Risk Governance - Publish monthly security reports to leadership, deliver H1 risk governance reports, and maintain vulnerability SLA compliance 90% with clear remediation tracking., * High-Impact Environment Work in a fast-moving, product-driven environment where your ideas directly shape the future of AI productivity. * Cutting-Edge AI Tools for Productivity Access to best-in-class AI tools, including Cursor, GPT models, Gemini, Claude, and other frontier AI systems to maximize engineering and execution efficiency. * Best-in-Class Equipment Choice of top-spec laptops, high-performance workstation setups, and cutting-edge Plaud devices for all new hires. * Team & Culture Annual company offsites, team events, and a culture that values craftsmanship, ownership, and velocity. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Speak, Code, Deploy: Transforming Developer Experience with Voice Commands](https://www.wearedevelopers.com/videos/1159-speak-code-deploy-transforming-developer-experience-with-voice-commands) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)