We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Principal SaaS Security Engineer

PTC
United States, Massachusetts, Boston
121 Seaport Boulevard (Show on map)
Oct 20, 2025
Our world is transforming, and PTC is leading the way.Our software brings the physical and digital worlds together, enabling companies to improve operations, create better products, and empower people in all aspects of their business.

Our people make all the difference in our success. Today, we are a global team of nearly 7,000 and our main objective is to create opportunities for our team members to explore, learn, and grow - all while seeing their ideas come to life and celebrating the differences that make us who we are and the work we do possible.

Principal SaaS Security Engineer-Hybrid-Boston

Onshape is a next-generation, global Software-as-a-Service (SaaS) product development platform that helps businesses of all sizes modernize and accelerate their design and manufacturing processes. The cloud-native platform is the only all-in-one system that combines robust computer-aided design (CAD) with powerful data management and collaboration tools. Onshape helps extended design teams work together faster from any location and helps executives make better decisions with real-time business analytics and unprecedented visibility into their company's operations.

As a Principal SaaS Security Engineer, you will be a subject matter expert responsible for the security operations and continuous monitoring of our commercial and US government cloud environments. The government environment supports customers with ITAR/EAR requirements and is pursuing a FedRAMP Moderate ATO. You will play a critical role in maintaining compliance with NIST SP 800-53 controls, driving incident response, and enhancing our security posture through automation, engineering best practices, and mentoring. This role requires a deep technical background in cloud security and experience with US federal security and compliance frameworks.

Key Responsibilities:

  • Continuous Monitoring and Compliance:
    • Lead the planning, implementation, and reporting of all FedRAMP continuous monitoring (ConMon) activities.
    • Manage and submit monthly ConMon deliverables, including vulnerability scan results, Plan of Action and Milestones (POA&M) updates, and incident reports to the FedRAMP Program Management Office (PMO), agency sponsor, and Internal Stakeholders.
    • Ensure all necessary documentation, such as the System Security Plan (SSP), is kept up-to-date and accurately reflects the current security posture.
  • Security Engineering and Automation:
    • Evaluate, deploy, and configure security tools and services in a large-scale, public cloud environment (100% AWS) to deliver a FedRAMP Moderate compliant service.
    • Develop and manage defensive security tool rules, alerts, and dashboards to proactively detect threats and anomalies.
  • Incident Response:
    • Serve as a senior responder for security incidents within the FedRAMP authorization boundary.
    • Lead incident response efforts, from initial triage and containment to mitigation and recovery.
    • Ensure all incidents are reported in accordance with FedRAMP Incident Communications Procedures.
    • Conduct post-mortem analysis of security incidents to identify root causes, implement defensive measures, and improve the incident response process.
  • Threat and Vulnerability Management:
    • Oversee comprehensive vulnerability management, including authenticated and unauthenticated scanning of systems, databases, containers, and web applications.
    • Track and manage the remediation of vulnerabilities according to FedRAMP timeliness requirements (e.g., High-risk findings within 30 days).
    • Implement and manage Intrusion Detection/Prevention Systems (IDPS) and host-based security systems to protect the system boundary and monitor for threats.
  • Collaboration and Team player:
    • Act as a technical leader, mentoring junior engineers and promoting security best practices across engineering and operations teams.
    • Collaborate with 3PAOs (Third-Party Assessment Organizations) during annual assessments and audit readiness activities.
    • Partner with other technical stakeholders to provide security expertise and ensure solutions align with compliance requirements.

Required Qualifications:

  • 7-10 years of hands-on professional experience in security operations, security engineering, or a related field.
  • US Citizen for security clearance requirements for FedRAMP.
  • Experience with US federal compliance frameworks, specifically FedRAMP Moderate, ITAR and NIST SP 800-53 controls.
  • Proven expertise with cloud security services (e.g., AWS IAM, GuardDuty, Security Hub).
  • Extensive experience with SIEM platforms (e.g., SumoLogic, OpenSearch) for log analysis, alerting, and security monitoring.
  • Strong knowledge of threat detection, and incident response methodologies.
  • Experience with vulnerability scanning tools (e.g., Wiz, CrowdStrike), triaging results, and managing remediation.
  • Strong written communication skills, with the ability to articulate technical concepts to both technical and non-technical audiences.
  • Security certifications are a plus (e.g., CISSP, GSEC, CEH).
  • Ability to commute to the Seaport office 1-2 days a week.

Work Environment:

The candidate may be required to participate in an on-call rotation to respond to security incidents.

The SecOps Engineer position will be a member of the Onshape Technical Operations team. This is a primarily US-based operations, site reliability, compliance, and security team. The team is part of Onshape Engineering and works very closely with other teams in engineering to deliver a reliable, secure service to our customers.

At PTC, we believe in the power of diverse ideas and perspectives. As a global company that values and respects all identities, cultures, and perspectives, we strive to create an inclusive PTC for ALL through an environment where everyone feels like they belong and are empowered to bring their true, authentic selves to work. Proud to be an Equal Opportunity Employer, we welcome applicants from all backgrounds and hire without regard to race, national origin, religion, age, color, ethnicity, ancestry, marital status, sex (including pregnancy), sexual orientation, gender identity, gender expression, genetic information, disability, veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Life at PTC is about more than working with today's most cutting-edge technologies to transform the physical world. It's about showing up as you are and working alongside some of today's most talented industry leaders to transform the world around you.

If you share our passion for problem-solving through innovation, you'll likely become just as passionate about the PTC experience as we are. Are you ready to explore your next career move with us?

We respect the privacy rights of individuals and are committed to handling Personal Information responsibly and in accordance with all applicable privacy and data protection laws. Review our Privacy Policy here."

>
Applied = 0

(web-c549ffc9f-ww2c9)