Principal SaaS Security Engineer at PTC
Boston, Massachusetts, United States -
Full Time


Start Date

Immediate

Expiry Date

16 Jan, 26

Salary

0.0

Posted On

18 Oct, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

FedRAMP, Security Operations, Security Engineering, Cloud Security, AWS, Incident Response, Vulnerability Scanning, SIEM, Threat Detection, Intrusion Detection, Security Monitoring, Documentation, Communication Skills, Security Certifications, Compliance Frameworks, Defensive Security Tools

Industry

Software Development

Description
Lead the planning, implementation, and reporting of all FedRAMP continuous monitoring (ConMon) activities. Manage and submit monthly ConMon deliverables, including vulnerability scan results, Plan of Action and Milestones (POA&M) updates, and incident reports to the FedRAMP Program Management Office (PMO), agency sponsor, and Internal Stakeholders. Ensure all necessary documentation, such as the System Security Plan (SSP), is kept up-to-date and accurately reflects the current security posture. Evaluate, deploy, and configure security tools and services in a large-scale, public cloud environment (100% AWS) to deliver a FedRAMP Moderate compliant service. Develop and manage defensive security tool rules, alerts, and dashboards to proactively detect threats and anomalies. Ensure all incidents are reported in accordance with FedRAMP Incident Communications Procedures. Implement and manage Intrusion Detection/Prevention Systems (IDPS) and host-based security systems to protect the system boundary and monitor for threats. 7-10 years of hands-on professional experience in security operations, security engineering, or a related field. US Citizen for security clearance requirements for FedRAMP. Experience with US federal compliance frameworks, specifically FedRAMP Moderate, ITAR and NIST SP 800-53 controls. Proven expertise with cloud security services (e.g., AWS IAM, GuardDuty, Security Hub). Extensive experience with SIEM platforms (e.g., SumoLogic, OpenSearch) for log analysis, alerting, and security monitoring. Strong knowledge of threat detection, and incident response methodologies. Experience with vulnerability scanning tools (e.g., Wiz, CrowdStrike), triaging results, and managing remediation. Strong written communication skills, with the ability to articulate technical concepts to both technical and non-technical audiences. Security certifications are a plus (e.g., CISSP, GSEC, CEH). Ability to commute to the Seaport office 1-2 days a week.
Responsibilities
Lead the planning, implementation, and reporting of all FedRAMP continuous monitoring activities. Manage and submit monthly deliverables and ensure all necessary documentation is up-to-date.
Loading...