Verified today
Principal Product Security Engineer
About the role
PTC seeks a Principal Product Security Engineer to safeguard products across the full SDLC in Pune, India. This role combines hands-on application penetration testing with architectural judgment and secure design guidance. The engineer leads complex security assessments for web apps, APIs, and AI-driven solutions while shaping product security strategy. Work is on-site.
What you’ll do
- Lead and execute in-depth manual application penetration testing across web applications, APIs, and LLM/AI enabled applications.
- Perform security testing aligned with OWASP standards and identify complex attack paths and business-logic flaws.
- Conduct secure code reviews to identify implementation flaws and support remediation efforts.
- Support security integration across the SDLC, including CI/CD pipelines and DevSecOps workflows.
- Partner with R&D teams to mature secure coding standards and shift-left practices.
- Research evolving threats, attack techniques, and defensive strategies, including AI/LLM security risks.
What you’ll bring
- Bachelor’s degree in CS, Software Engineering, Cybersecurity, or equivalent practical experience.
- 7+ years of experience in Product, Application, or Software Security Engineering.
- Extensive hands-on experience conducting manual application penetration testing.
- Strong understanding of secure software development lifecycle (SSDLC) principles.
- Deep knowledge of OWASP Top 10, API Top 10, LLM/AI Top 10, CWE, and CVSS.
- Proficiency in at least one programming language such as Python, Java, JavaScript/TypeScript, Go, or C/C++.
Skills
Education
Bachelor’s degree in computer science, Software Engineering, Cybersecurity, or equivalent practical experience.