PTC Logo

PTC

Senior Product Security and Compliance Engineer

Posted 8 Days Ago
Be an Early Applicant
In-Office
Pune, Maharashtra, IND
Senior level
In-Office
Pune, Maharashtra, IND
Senior level
Lead hands‑on application penetration testing and secure code reviews across web, API, SaaS, and LLM/AI products. Integrate security across the SDLC and CI/CD, support DevSecOps tooling, research emerging threats, and drive remediation and security engineering practices across product teams.
The summary above was generated by AI

Our world is transforming, and PTC is leading the way. Our software brings the physical and digital worlds together, enabling companies to improve operations, create better products, and empower people in all aspects of their business. 

Our people make all the difference in our success. Today, we are a global team of nearly 7,000 and our main objective is to create opportunities for our team members to explore, learn, and grow – all while seeing their ideas come to life and celebrating the differences that make us who we are and the work we do possible.  

Job Title: Principal Product Security Engineer

Role Overview

The Principal Product Security Engineer is a senior technical leader responsible for safeguarding the security of products and services across the full Software Development Lifecycle (SDLC), with a strong emphasis on hands‑on application penetration testing. This role combines deep offensive security expertise with architectural judgment, secure design guidance, and cross‑organizational influence.

As a principal‑level engineer, you will lead complex application security assessments across web applications, APIs, SaaS platforms, and emerging technologies (including AI‑driven solutions), while also shaping product security strategy, standards, and engineering practices. You will work closely with R&D, Product Management, Cloud, SaaS, and QA teams to ensure security is built in, not bolted on.

This role is highly technical, execution‑focused, and requires the ability to both find and exploit real‑world vulnerabilities and drive durable remediation outcomes across multiple product lines.

Key Responsibilities

Application Penetration Testing & Offensive Security

  • Lead and execute in‑depth manual application penetration testing across web applications, APIs, and LLM/AI enabled applications.
  • Perform security testing aligned with OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE Top 25, and emerging attack classes.
  • Identify complex attack paths, chained vulnerabilities, and business‑logic flaws beyond automated tool findings.
  • Validate exploitability, determine real risk, and distinguish true positives from noise.
  • Conduct secure code reviews to identify implementation flaws and support remediation.
  • Re‑test fixes and mitigations to confirm effectiveness and risk reduction.

SDLC, DevSecOps & Tooling

  • Support security integration across the SDLC, including CI/CD pipelines and DevSecOps workflows.
  • Support the use of SAST, DAST, SCA, secrets scanning, and container security tools.
  • Support automation efforts to reduce time‑to‑detect and time‑to‑remediate.
  • Partner with R&D teams to mature secure coding standards and shift‑left practices.

Research & Continuous Improvement

  • Research evolving threats, attack techniques, and defensive strategies, including AI/LLM security risks.
  • Stay current on emerging security tooling, frameworks, and industry best practices.
  • Continuously improve testing methodologies, reporting quality, and remediation effectiveness.

Required Qualifications

  • Bachelor’s degree in computer science, Software Engineering, Cybersecurity, or equivalent practical experience.
  • 7+ years of experience in Product Security, Application Security, or Software Security Engineering.
  • Extensive hands‑on experience conducting manual application penetration testing.
  • Strong understanding of secure software development lifecycle (SSDLC) principles.
  • Deep knowledge of OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE, CVSS, and vulnerability prioritization.
  • Proficiency in at least one programming language such as Python, Java, JavaScript/TypeScript, Go, or C/C++.
  • Experience with modern application architectures, APIs, and cloud‑based systems.
  • Ability to clearly communicate security findings and remediation guidance to both technical and non‑technical stakeholders.
  • Experience integrating security controls into CI/CD pipelines.

Preferred / Nice‑to‑Have Qualifications

  • Relevant certifications such as OSCP, GWAPT, OSWE, GPEN, CISSP, CSSLP, or CCSP.





Life at PTC is about more than working with today’s most cutting-edge technologies to transform the physical world. It’s about showing up as you are and working alongside some of today’s most talented industry leaders to transform the world around you. 

If you share our passion for problem-solving through innovation, you’ll likely become just as passionate about the PTC experience as we are. Are you ready to explore your next career move with us?

We respect the privacy rights of individuals and are committed to handling Personal Information responsibly and in accordance with all applicable privacy and data protection laws. Review our Privacy Policy here."

PTC Pune, Mahārāshtra, IND Office

Marisoft - II, Survey No. 15, Vadgaonsheri, Kalyani Nagar, Pune, India

Similar Jobs

54 Minutes Ago
Hybrid
Pune, Maharashtra, IND
Senior level
Senior level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Lead global statutory reporting and a team supporting external audits. Manage US GAAP to local/IFRS bridge files, year-end accounting, SOX controls, auditor relations, and process improvements. Liaise with GBSC, controllership and external advisors to meet audit deadlines and resolve audit issues.
Top Skills: HyperionExcelOracle
55 Minutes Ago
Hybrid
Pune, Maharashtra, IND
Senior level
Senior level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Lead design, implementation, security, and support of large multi-site, multi-vendor network environments. Define upgrade requirements, plan and run global projects, perform monitoring and log audits, recommend improvements, resolve network incidents, and manage vendors while mentoring junior staff.
Top Skills: AristaArubaBgpCheckpointCiscoDatacenter NetworkingF5F5 Load BalancingFirewallsMplsPalo AltoSecurity Encryption TechnologiesSnmpSshTcp/IpVpnWirelessZ-Scaler
56 Minutes Ago
Hybrid
Pune, Maharashtra, IND
Senior level
Senior level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
The Senior Specialist, Transaction Services will manage accounts payable, deliver process automation, ensure compliance with policies, and improve customer experience while leading a collaborative team.
Top Skills: CoupaOracleTableau

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account