Jobs · Marketing · Massachusetts

Vice President - Global Product Security

PTC · Boston, MA · Today
Marketing$272k–$340k/yrFull-time

Our world is transforming, and PTC is leading the way. Our software brings the physical and digital worlds together, enabling companies to improve operations, create better products, and empower people in all aspects of their business. Our people make all the difference in our success. Today, we are a global team of nearly 7,000 and our main objective is to create opportunities for our team members to explore, learn, and grow – all while seeing their ideas come to life and celebrating the differences that make us who we are and the work we do possible.

About the role

PTC is seeking a Vice President – Global Product Security to define and lead the company’s product security strategy across its global portfolio. Reporting to the Chief Product Officer, they will ensure security is embedded throughout the product lifecycle spanning architecture and development through release, deployment, and ongoing vulnerability management. You will partner closely with Product, Engineering, Cloud Operations, Information Security, Legal, and Customer Success to strengthen product security, reduce risk, and maintain customer trust. This leader must combine deep application security expertise with judgment and influence to establish consistent standards across a complex global product organization.

Responsibilities

  • Product Security Strategy and Governance
    • Define and execute a comprehensive product security strategy aligned with PTC’s product, cloud, and AI priorities.
    • Establish security standards, policies, and governance across the product development lifecycle.
    • Embed security into product architecture, engineering practices, release processes, and acquisition integration.
    • Advise the Chief Product Officer and executive leadership on product security risks, priorities, investments, and emerging threats.
    • Establish clear metrics and reporting to measure product security posture, vulnerability trends, remediation performance, and organizational readiness.
  • Application Security
    • Lead the company’s application security program across cloud, SaaS, on-premises, and connected products.
    • Establish secure development standards based on recognized frameworks, including OWASP.
    • Oversee application security testing using software composition analysis, static application security testing, dynamic application security testing, and related tools, including Black Duck.
    • Partner with Engineering to incorporate security testing and automated controls into development and CI/CD workflows.
    • Ensure vulnerabilities are consistently identified, prioritized, remediated, and validated based on severity and customer risk.
    • Guide secure architecture reviews, threat modeling, code reviews, and security design decisions for new and existing products.
  • Vulnerability and Incident Management
    • Lead PTC’s product penetration-testing strategy, including the selection and management of internal and external testing resources.
    • Establish and oversee product vulnerability management and Product Security Incident Response Team processes.
    • Define policies governing responsible disclosure, vulnerability intake, remediation timelines, customer communication, and the publication of Common Vulnerabilities and Exposures.
    • Serve as the senior product security authority during significant vulnerabilities or product-related security incidents.
    • Ensure clear coordination among Product, Engineering, Information Security, Legal, Communications, and Customer Success during security events.
  • AI and Emerging Technology
    • Assess how AI is changing application vulnerability discovery, security testing, attack methods, and remediation.
    • Define appropriate security standards and testing requirements for AI-enabled products and functionality.
    • Evaluate opportunities to use AI to improve vulnerability detection, prioritization, and response.
    • Anticipate emerging product security risks and translate them into practical product and engineering requirements.
  • Leadership and Partnership
    • Build and lead a high-performing product security organization with the expertise and scale required to support PTC’s portfolio.
    • Create clear accountability for product security while strengthening security ownership within Product and Engineering.
    • Partner with customer-facing teams to address product security requirements during strategic sales, renewals, and customer reviews.
    • Represent PTC’s product security strategy with customers, partners, auditors, and other external stakeholders.
    • Promote a culture in which security is treated as a core product requirement and an enabler of customer trust.

Requirements

  • 15+ years of progressive experience in product security, application security, software engineering security, or a related discipline, including 8+ years leading security teams and programs within a global technology company.
  • Experience embedding security into modern software development and CI/CD processes.
  • Ability to translate complex technical risks into clear business implications, priorities, and executive-level recommendations.
  • Proven ability to influence senior product and engineering leaders and drive consistent standards across a global, matrixed organization.
  • Strong judgment, credibility, and communication skills, particularly during high-risk security events.
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related field; an advanced degree or relevant security certifications are preferred.

Skills

  • Required Application Security Expertise
    • Deep familiarity with OWASP standards, including the OWASP Top 10.
    • Broad expertise across application security testing tools and methodologies, including Black Duck, software composition analysis, static application security testing, and dynamic application security testing.
    • Demonstrated experience leading and managing penetration-testing programs.
    • Strong understanding of how AI is changing application vulnerability detection, testing, and remediation.
    • Expertise in application security policies, including responsible disclosure, vulnerability management, remediation requirements, customer communication, and decisions regarding when to publish CVEs.

Pay

The anticipated annual salary range for this position is between $272,000 - $340,000. The salary range reflects a good-faith estimate of compensation at the time of posting. Actual compensation may vary based on a candidate's skills, qualifications, experience, and location.

Benefits

  • Eligible employees can become PTC shareholders through our employee share purchase program (ESPP), which allows for the purchase of discounted PTC stock. Certain roles may also be eligible for participation in our equity programs.
  • Medical, dental, and vision insurance.
  • Paid time off and sick leave.
  • Tuition reimbursement.
  • 401(k) contributions and employer match.
  • Flexible spending accounts.
  • Life insurance and disability coverage.
  • For office-assigned employees, a generous commuter subsidy.

All total rewards and benefits programs are subject to plan eligibility and other terms and conditions.

Similar jobs