Talent.com
Principal SaaS Security Engineer

Principal SaaS Security Engineer

PTCBoston, MA, United States
6 days ago
Job type
  • Full-time
Job description

Overview

Principal SaaS Security Engineer - Hybrid - Boston. Onshape is a next-generation, global Software-as-a-Service (SaaS) product development platform. The role focuses on security operations and continuous monitoring of our commercial and US government cloud environments, with emphasis on FedRAMP Moderate, ITAR / EAR requirements, and NIST SP 800-53 controls.

Key Responsibilities

  • Continuous Monitoring and Compliance :
  • Lead the planning, implementation, and reporting of all FedRAMP continuous monitoring (ConMon) activities.
  • Manage and submit monthly ConMon deliverables, including vulnerability scan results, Plan of Action and Milestones (POA&M) updates, and incident reports to the FedRAMP PMO, agency sponsor, and internal stakeholders.
  • Ensure all documentation, such as the System Security Plan (SSP), is kept up-to-date and accurately reflects the current security posture.
  • Security Engineering and Automation :
  • Evaluate, deploy, and configure security tools and services in a large-scale, public cloud environment (100% AWS) to deliver a FedRAMP Moderate compliant service.
  • Develop and manage defensive security tool rules, alerts, and dashboards to proactively detect threats and anomalies.
  • Incident Response :
  • Serve as a senior responder for security incidents within the FedRAMP authorization boundary.
  • Lead incident response efforts, from initial triage and containment to mitigation and recovery.
  • Ensure all incidents are reported in accordance with FedRAMP Incident Communications Procedures.
  • Conduct post-mortem analysis of security incidents to identify root causes, implement defensive measures, and improve the incident response process.
  • Threat and Vulnerability Management :
  • Oversee comprehensive vulnerability management, including authenticated and unauthenticated scanning of systems, databases, containers, and web applications.
  • Track and manage the remediation of vulnerabilities according to FedRAMP timeliness requirements (e.g., High-risk findings within 30 days).
  • Implement and manage Intrusion Detection / Prevention Systems (IDPS) and host-based security systems to protect the system boundary and monitor for threats.
  • Collaboration and Team Player :
  • Act as a technical leader, mentoring junior engineers and promoting security best practices across engineering and operations teams.
  • Collaborate with 3PAOs during annual assessments and audit readiness activities.
  • Partner with other technical stakeholders to provide security expertise and ensure solutions align with compliance requirements.

Required Qualifications

  • 7-10 years of hands-on professional experience in security operations, security engineering, or a related field.
  • US Citizen for security clearance requirements for FedRAMP.
  • Experience with US federal compliance frameworks, specifically FedRAMP Moderate, ITAR and NIST SP 800-53 controls.
  • Proven expertise with cloud security services (e.g., AWS IAM, GuardDuty, Security Hub).
  • Extensive experience with SIEM platforms (e.g., SumoLogic, OpenSearch) for log analysis, alerting, and security monitoring.
  • Strong knowledge of threat detection and incident response methodologies.
  • Experience with vulnerability scanning tools (e.g., Wiz, CrowdStrike), triaging results, and managing remediation.
  • Strong written communication skills, with the ability to articulate technical concepts to both technical and non-technical audiences.
  • Security certifications are a plus (e.g., CISSP, GSEC, CEH).
  • Ability to commute to the Seaport office 1-2 days a week.
  • Work Environment

    The candidate may be required to participate in an on-call rotation to respond to security incidents. The SecOps Engineer position will be a member of the Onshape Technical Operations team within Onshape Engineering, collaborating with other teams to deliver a reliable, secure service. PTC is an Equal Opportunity Employer and values diverse identities, cultures, and perspectives.

    Equal Opportunity and Privacy

    PTC is committed to handling Personal Information responsibly and in accordance with all applicable privacy and data protection laws. Review our Privacy Policy here.

    #J-18808-Ljbffr

    Create a job alert for this search

    Principal Security Engineer • Boston, MA, United States

    Related jobs
    • Promoted
    Senior Security Engineer / IR / Blue Team

    Senior Security Engineer / IR / Blue Team

    7AI, Inc.Boston, MA, United States
    Full-time
    We are seeking a Senior AI Security Engineer to join our team, focusing on defining security workflows and incident response (IR) strategies. Our AI Security Engineers are at the forefront of the Ag...Show moreLast updated: 4 days ago
    • Promoted
    Principal System Security Engineer

    Principal System Security Engineer

    Draper LabsCambridge, MA, United States
    Full-time
    Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA.The 2,000+ employees of Draper tackle important national challenges with a promise of delivering ...Show moreLast updated: 19 days ago
    • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    WilmerHaleBoston, MA, United States
    Full-time
    WilmerHale is a leading, full-service international law firm with 1,000 lawyers located throughout 12 offices in the United States, Europe and Asia. Our lawyers work at the intersection of governmen...Show moreLast updated: 3 days ago
    • Promoted
    Sr. Application Security Engineer

    Sr. Application Security Engineer

    OpenGovBoston, MA, United States
    Full-time
    OpenGov is the leader in AI and ERP solutions for local and state governments in the U.More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov ...Show moreLast updated: 3 days ago
    • Promoted
    Lead Adversarial Security Engineer

    Lead Adversarial Security Engineer

    TrellixBoston, MA, United States
    Full-time
    Lead Adversarial Security Engineer.Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work. Our comprehensive, GenAI-powered platform helps organizations confronte...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer

    Security Engineer

    Givzey, Inc.Boston, MA, United States
    Full-time
    Givzey’s security posture while managing our internal IT infrastructure.This is a hybrid role combining.You’ll be responsible for everything from ensuring SOC 2 / ISO compliance and securing AWS en...Show moreLast updated: 6 days ago
    • Promoted
    Lead Security Engineer, Cloud Infrastructure

    Lead Security Engineer, Cloud Infrastructure

    KlaviyoBoston, MA, United States
    Full-time
    At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair sh...Show moreLast updated: 12 days ago
    • Promoted
    Senior Security Engineer, Cloud Infrastructure

    Senior Security Engineer, Cloud Infrastructure

    KlaviyoBoston, MA, United States
    Full-time
    Senior Security Engineer, Cloud Infrastructure.Senior Security Engineer, Cloud Infrastructure.We’re Klaviyo (pronounced clay-vee‑oh). We empower creators to own their destiny by making first‑party d...Show moreLast updated: 3 days ago
    • Promoted
    Sr. Security Operations Engineer

    Sr. Security Operations Engineer

    OpenGovBoston, MA, United States
    Full-time
    OpenGov is the leader in AI and ERP solutions for local and state governments in the U.More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov ...Show moreLast updated: 3 days ago
    • Promoted
    Principal Security Engineer, Operations

    Principal Security Engineer, Operations

    CarGurusBoston, MA, United States
    Full-time
    At CarGurus (NASDAQ : CARG), our mission is to give people the power to reach their destination.We started as a small team of developers determined to bring trust and transparency to car shopping.Si...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Cloud Security Engineer

    Senior Cloud Security Engineer

    J&J Family of CompaniesDanvers, MA, United States
    Full-time
    At Johnson & Johnson, we believe health is everything.Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments a...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer (Network Architecture) - Multiple levels!

    Security Engineer (Network Architecture) - Multiple levels!

    NoblisBoston, MA, United States
    Full-time +2
    We are looking for highly technical, hands-on professionals with a strong foundation in network architecture, design, and security - individuals who are ready to step up from traditional network en...Show moreLast updated: 30+ days ago
    • Promoted
    Principal Security Engineer

    Principal Security Engineer

    PTCBoston, MA, United States
    Full-time
    Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.PTC-Technical Recruiting Leader | Talent Acquisition Strategist | Global Recruitment Expert | AI...Show moreLast updated: 6 days ago
    • Promoted
    Enterprise Security – Senior Security Engineer

    Enterprise Security – Senior Security Engineer

    Fast SwitchBoston, MA, United States
    Full-time
    Enterprise Security – Senior Security Engineer.Join Fast Switch as an Enterprise Security – Senior Security Engineer and help safeguard our business assets. Enterprise Security – Senior Security Eng...Show moreLast updated: 5 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Eliassen GroupBoston, MA, United States
    Full-time
    We are seeking a skilled and proactive Security Engineer to join our team.This role is critical in ensuring the integrity, confidentiality, and availability of our systems and data.The ideal candid...Show moreLast updated: 12 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    TinesBoston, MA, United States
    Full-time
    Startup equity & extended exercise window.Generous parental leave programs.Flexibility in how and where you work.Phone and home Internet allowance. As a Software Engineer at Tines, Yannick Gloster s...Show moreLast updated: 24 days ago
    • Promoted
    Principal Security Architect

    Principal Security Architect

    InterSystemsBoston, MA, United States
    Full-time
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.We are seeking an experienced and strategic. This role blends deep technical expertise with strategic l...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer I

    Senior Security Engineer I

    CompassBoston, MA, United States
    Full-time
    At Compass, our mission is to help everyone find their place in the world.Founded in 2012, we’re revolutionizing the real‑estate industry with our end‑to‑end platform that empowers residential real...Show moreLast updated: 6 days ago