PTC is looking for Senior Director - SaaS, Cloud & Product Security (, MA, United States) in United States, MA.
This local job opportunity with ID 3770115888 is live since 2026-08-01 10:50:39.
The Senior Director, SaaS, Cloud & Product Security is a senior security leader responsible for defining and executing the product security strategy across our SaaS platforms, cloud infrastructure, and customer-facing software products. The role partners closely with Engineering, Product Management, SRE/Platform, and GRC/Compliance to embed security into architecture, design, development, deployment, and runtime operations—driving measurable risk reduction while enabling product velocity. This leader builds and scales a high-performing organization that serves as trusted security advisors to product and platform teams, influencing roadmaps and ensuring accountability for remediation of material risks. Responsibilities Set strategy & operating model: Define and execute a multi-year product/security strategy and roadmap across AI, SaaS, cloud, and product lines; establish a durable operating rhythm. Lead the function: Operate, scale, and lead a product security organization (e.g., security architects, product security engineers, security champions enablement, AppSec tooling/program roles), including hiring, coaching, and performance management. Engage directly with customers to support sales cycles: Join customer and prospect calls to speak as the security SME, helping close deals by building trust and addressing concerns while also participating in RFP/RFI responses where product security expertise is needed. Embed security into the SDLC/DevSecOps: Ensure security is integrated into agile delivery through developer security training, design/architecture reviews, threat modeling, security user stories, automated security testing, penetration testing, and audit readiness. Review contracts for security and compliance requirements: Evaluate customer agreements, security addendums, DPAs, and vendor contracts for alignment with internal capabilities and risk thresholds. Partner with Legal, Sales, and GRC to ensure commitments are feasible, enforceable, and do not introduce undue operational or compliance risk. Architecture & design influence: Serve as a senior security advisor to engineering leadership; drive secure-by-design decisions for multi‑tenant SaaS, APIs, identity, encryption, secrets, logging/monitoring, and tenant isolation. Secure SDLC governance & standards: Own or co‑own secure development policies/standards, release security criteria, and definition of done expectations (e.g., required SAST/DAST/SCA gates; pre‑release validation). Supply chain & third‑party security: Define requirements for OSS and third‑party components, including provenance, vulnerability monitoring, and secure acquisition/maintenance practices. Metrics & continuous improvement: Establish measurable outcomes and reporting frameworks to track program effectiveness (risk reduction, coverage, remediation speed, escaped defects, incident trends) and guide investment decisions. Cross‑functional partnership: Partner with product engineering groups as trusted security counterparts across architecture, design, deployment, and runtime operations; influence backlogs and roadmaps without slowing delivery. Customer & regulatory assurance: Support customer security reviews, attestations, and compliance‑driven requirements by translating expectations into practical engineering controls and evidence. Skills and Knowledge AI‑first approach to securing SaaS and cloud‑native architectures (multi‑tenancy, microservices, containers/Kubernetes, service meshes, CI/CD, infrastructure‑as‑code). Strong application & product security fundamentals (secure design, threat modeling, secure coding patterns, API security, authn/authz, cryptography, secrets management). Fluency with secure development frameworks and maturity models (e.g., NIST SSDF practice groups and outcomes; metrics‑driven improvement). Strong stakeholder influence at senior levels—able to navigate ambiguity and drive alignment across Product, Engineering, Platform/SRE, and Compliance. Experience 10 years in security engineering and/or product security, with significant experience in cloud and SaaS environments. 5 years leading managers and/or multiple teams, scaling security programs across multiple products or business units. Demonstrated success embedding security into engineering workflows (agile/DevOps) and improving release quality through automated testing and standard gates. Track record partnering with engineering leadership to influence architecture/roadmaps and drive remediation accountability. Experience supporting customer assurance and compliance obligations tied to secure development expectations (SSDF‑aligned language helpful). Minimum Qualifications Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience. Proven people leadership experience building and scaling security teams. Compensation & Benefits Anticipated annual salary range: $200,000 to $250,000. The role may include a performance‑based bonus and equity opportunities through the Employee Share Purchase Program (ESPP). Employees are eligible for medical, dental, and vision insurance; paid time off and sick leave; tuition reimbursement; 401(k) contributions and employer match; flexible spending accounts; life insurance; disability coverage; and commuter subsidy (for office‑assigned employees). All total rewards and benefits programs are subject to applicable plan eligibility and terms and conditions. Equal Opportunity Employer At PTC, we believe in the power of diverse ideas and perspectives. As a global company that values and respects all identities, cultures, and perspectives, we strive to create an inclusive workplace for ALL through an environment where everyone feels like they belong and are empowered to bring their true, authentic selves to work. Proud to be an Equal Opportunity Employer, we welcome applicants from all backgrounds and hire without regard to race, national origin, religion, age, color, ethnicity, ancestry, marital status, sex (including pregnancy), sexual orientation, gender identity, gender expression, genetic information, disability, veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. J-18808-Ljbffr5c143e31-5e48-4549-b638-05792d185386
read more