> Markdown version of [/jobs/ext/1101282-telecommute-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/1101282-telecommute-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TELECOMMUTE Staff Product Security Engineer - **Company:** PTC Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $105,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Databases, Continuous Integration, Mobile Application Software, Python (Programming Language), OAuth, OpenID, Open Web Application Security, Openid Connect, Salesforce.Com, Software Engineering, TypeScript, Apex Code, Google Cloud, Salesforce Lightning, Software Security, Infrastructure as Code (IaC), Cloudformation, GWAPT, Information Technology, Terraform, Devsecops, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Dynamic Application Security Testing - **Published:** June 9, 2026 - **Apply:** https://www.dice.com/job-detail/171e2428-a751-41ba-b0e5-5aa89efa5172 ## About the Role * based in the US required to meet ITAR Compliance and regulatory requirements. * Bachelor's degree in computer science, Information Security, Engineering, or an equivalent combination of practical experience. * 5+ years of experience in Application Security, Product Security, or Software Security Engineering. * Strong knowledge of Secure Software Development Lifecycle (SSDLC) practices. * Hands-on experience with threat modeling, secure design reviews, and application security assessments. * In-depth understanding of OWASP Top 10 and OWASP API Top 10. * Experience using SAST, DAST, SCA, and secrets scanning tools and integrating them in CI/CD. * Proficiency in at least one programming language: Java, Python, JavaScript/TypeScript, or Go. * Experience securing mobile applications, including offline data and sync workflows. * Secure REST and event-driven APIs used by customers, partners, and internal services. * Exposure to AI/ML security, responsible AI practices, or model risk management. * Strong understanding of cloud platforms (AWS, Azure, or Google Cloud Platform). * Strong written and verbal communication skills with the ability to partner effectively with engineering and product teams. Nice to Have * Experience securing Salesforce-based applications (Apex, Lightning, Salesforce security model). * Experience integrating security controls into CI/CD pipelines (DevSecOps). * Familiarity with container and Kubernetes security. * Knowledge of OAuth 2.0, OpenID Connect (OIDC), JWT, and identity/security patterns. * Experience with Infrastructure as Code (IaC) security (Terraform, CloudFormation, ARM). * Experience working in regulated or compliance-driven environments. * Familiarity with ISO 27001, SOC 2, NIST, or FedRAMP frameworks. * Security certifications such as GWAPT, OSWE, CSSLP, CISSP, or CCSP., If you share our passion for problem-solving through innovation, you'll likely become just as passionate about the PTC experience as we are. Are you ready to explore your next career move with us? ## Description You'll be responsible for helping secure PTC by providing cyber security expertise in the analysis, assessment, development, and evaluation of security solutions and architectures to secure our SaaS applications, containers, operating systems, databases, and networks. Additionally, the Security Engineer assists in the development of cyber security requirements, conducts security risk assessments, evaluates security services and technologies, and reviews and documents information security policies and procedures as well as provides monitoring and oversight for alerts in this environment. Our SaaS Security Team is small but growing. So, we all do what it takes and use all the skills in our personal arsenals to continue to evolve PTC's SaaS Security posture. Our environment is fast, friendly, and dynamic. Day-To-Day: * Serves as a subject matter expert (SME) on Information Security. * Identify and implement new security technologies and best practices. * Review security test results from vulnerability scans, penetration testing for true positives and propose appropriate remediation measures or mitigation controls. * Reduce time-to-detect and time-to-remediate by driving the automation of applied threat intelligence and sensor enrichment. * Guide and influence multi-disciplinary teams in implementing and operating Cyber Security controls. * Consults with internal teams on engineering designs and development of cloud-based systems to ensure security is built-in. * Learns with agility; empowered to update and enhance current security practices, tooling, and documentation. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)