waypointjobs

Medallia, Inc.

Senior Staff Product Security Engineer, AI Security & Security Assurance

mclean, VA

Check who can apply and the requirements below before continuing.

About this opportunity

Medallia, Inc. lists this Senior Staff Product Security Engineer, AI Security & Security Assurance opportunity in mclean, Virginia. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Overview

Medallia is the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia Experience Cloud, leads the market in the management of experiences, insights, and actions for candidates, customers, employees, patients, and residents alike.

We believe that every experience is a memory that can last a lifetime. Experiences shape the way people feel about a company. And they greatly influence how likely people are to advocate, contribute, and stay. At Medallia, we are committed to creating a world where organizations are loved by their customers and their employees.

We empower exceptional people to create extraordinary experiences together.

Bring your whole self.

The Role and Team

We are seeking a Senior Staff Product Security Engineer to lead Medallia's security strategy and assurance efforts for AI-powered products, agentic systems, next-generation platforms, and emerging technologies.

This individual will serve as the technical leader for AI Security and Security Assurance, partnering with Product, Engineering, Architecture, Data Science, and Security teams to ensure security is embedded into the design, development, and deployment of modern AI-enabled capabilities.

The ideal candidate combines deep expertise in application security, threat modeling, and security architecture with a strong understanding of Generative AI, LLMs, AI agents, and secure system design. They will identify emerging risks, establish scalable security practices, and help define Medallia's long-term approach to securing AI-enabled products and platforms.

Responsibilities

AI Security Lead

Serve as the technical authority for security reviews involving: Generative AI applications

LLM-powered features

AI agents

Agentic workflows

MCP (Model Context Protocol) integrations

AI skills and marketplaces

AI coding assistants

Bring Your Own Model (BYOM) capabilities

Define security requirements and guardrails for AI-enabled products and services.

Evaluate emerging AI technologies and assess associated security risks.

Partner with engineering and product teams to ensure AI features are secure by design.

Threat Modeling & Security Architecture

Lead threat modeling efforts for critical product and platform initiatives.

Establish and scale a threat modeling program across engineering organizations.

Conduct security architecture reviews for high-risk and strategic initiatives.

Develop security reference architectures, design patterns, and guidance for engineering teams.

Identify systemic security risks and drive long-term remediation strategies.

Security Assurance

Own and evolve Product Security assurance activities including: Security reviews

Security assessments

AI security reviews

Security testing strategies

Security requirements and standards

Define risk‑based approaches for evaluating emerging technologies.

Partner with engineering teams to embed security validation throughout the SDLC.

Secure Development & Developer Enablement

Establish secure development standards for AI-enabled applications.

Drive adoption of secure coding practices across engineering teams.

Develop scalable developer guidance and security enablement programs.

Evaluate and implement approaches to improve security feedback during development, including AI‑assisted security review capabilities.

Security Automation & Innovation

Identify opportunities to automate security reviews and reduce manual effort.

Partner with security tooling owners to improve developer experience and security coverage.

Define metrics that measure effectiveness of AI security and security assurance programs.

Evaluate emerging security technologies relevant to AI and modern software development.

Cross‑Functional Influence

Partner closely with Product, Engineering, Architecture, Data Science, Privacy, Legal, Compliance, and Operations teams.

Influence technical direction through expertise and relationship‑building.

Mentor Staff and Senior Engineers in threat modeling, architecture reviews, and AI security.

Candidates based in the Tysons Corner vicinity will be prioritized as this role is Hybrid, 3 days per week onsite.

Qualifications

Minimum Qualifications

12+ years of experience in Product Security, Application Security, Security Architecture, or Security Engineering.

Proven experience operating at Staff or Senior Staff level within a technology organization.

Demonstrated expertise in: Threat Modeling

Security Architecture Reviews

Application Security

Cloud Security

Secure SDLC

Vulnerability Management

Secure Design Principles

Experience securing modern architectures including: APIs

Microservices

Kubernetes

Containers

Cloud‑native platforms

Strong understanding of security frameworks and standards including: OWASP

NIST

SOC 2

ISO 27001

PCI DSS

Demonstrated ability to influence engineering organizations and drive security outcomes without direct authority.

Preferred Qualifications

Experience securing: Generative AI applications

LLM‑based products

AI agents

Agentic workflows

MCP integrations

Retrieval‑Augmented Generation (RAG) systems

Familiarity with AI security concepts including: Prompt Injection

Indirect Prompt Injection

Tool Abuse

Agent Authorization

Data Leakage

Model Abuse

AI Threat Modeling

Experience developing security guidance for AI‑enabled software development.

Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent.

Medallia is committed to equal pay and transparency. The annual base salary range for this position is $184,000 - $245,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Medallia considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, candidate's work location, education/training, key skills, internal peer equity, external market data, as well as, market and business considerations when making compensation decisions.

Medallia also offers competitive health and wellness benefits, including but not limited to medical, dental, vision, 401(k), short-term and long-term disability, life and AD&D insurance, statutory leaves, paid parental leave, and paid holidays. Benefits and eligibility may vary by location and role.

At Medallia, we celebrate diversity and recognize the value it brings to our customers and employees. Medallia is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age (40 and over), disability, genetic information, veteran status or military service, or any other status protected by state or local law. Individuals with a disability who need an accommodation to apply please contact us at For information regarding how Medallia collects and uses personal information, please review our Privacy Policies. Applications will be accepted for 30 days from the date this role was posted or until the role has been filled.

#J-18808-Ljbffr

Worksite address

mclean, VA, 22107, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Govcio LLC

WhatJobs

Senior Systems Engineer (NSGS)

alexandria, VA

$145,000.00 /Yr

Overview: GovCIO is seeking a Senior Systems Engineer to support mission-critical IT programs for the U.S. Coast Guard (USCG). This position wil…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Cyber / DevOps Systems Engineer (Ft. Bragg)

fort liberty, NC

$130,000.00 /Yr

Overview: GovCIO is currently hiring for a Senior Cyber Security / DevOps Systems Engineer to engineer, automate, secure, and optimize full-stack…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Site W/Classified Support Engineer

herndon, VA

$100,000.00 /Yr

Overview: GovCIO is currently hiring for aGovCIO is currently hiring for an Site W/Classified Support Engineer.  for an upcoming award. This p…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Cloud Platform Engineer

fort meade, MD

$217,000.00 /Yr

Overview: GovCIO is currently hiring for a Cloud Platform Engineer  to create tools and environments that improve developer productivity. This po…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

CSOC Classified Support Engineer

colorado springs, CO

$140,000.00 /Yr

Overview: GovCIO is currently hiring for a Senior CSOC Support Engineer in Colorado Springs, CO. This position is onsite.  Responsibilities: P…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Senior CSOC Support Engineer

colorado springs, CO

$145,000.00 /Yr

Overview: GovCIO is currently hiring for a Senior CSOC Support Engineer in Colorado Springs, CO.  Responsibilities: Provides technical and man…

Last received from source 2026-10-07View job