Medallia

Senior Staff Product Security Engineer, AI Security & Security Assurance

Medallia
Apply
2 days ago
McLean, VA, USAStaff+
H1B sponsor

Base Salary

$184k - $245k/yr

Responsibilities

  • Serve as the technical authority for security reviews of generative AI applications, LLM-powered features, AI agents, agentic workflows, MCP integrations, AI skills and marketplaces, AI coding assistants, and BYOM capabilities.
  • Define security requirements and guardrails for AI-enabled products and services and assess emerging AI technology risks.
  • Lead threat modeling and security architecture reviews for critical, high-risk, and strategic product and platform initiatives.
  • Establish security reference architectures, design patterns, secure development standards, and developer security enablement programs.
  • Own and evolve product security assurance activities, including security reviews, assessments, AI security reviews, testing strategies, requirements, and standards.
  • Automate security reviews, improve security tooling and developer experience, and define metrics for AI security and assurance programs.
  • Partner with Product, Engineering, Architecture, Data Science, Privacy, Legal, Compliance, and Operations teams to influence security outcomes.
  • Mentor Staff and Senior Engineers in threat modeling, architecture reviews, and AI security.

Requirements

  • 12+ years of experience in Product Security, Application Security, Security Architecture, or Security Engineering.
  • Proven experience operating at Staff or Senior Staff level within a technology organization.
  • Expertise in threat modeling, security architecture reviews, application security, cloud security, secure SDLC, vulnerability management, and secure design principles.
  • Experience securing APIs, microservices, Kubernetes, containers, and cloud-native platforms.
  • Strong understanding of OWASP, NIST, SOC 2, ISO 27001, and PCI DSS.
  • Ability to influence engineering organizations and drive security outcomes without direct authority.
  • Preferred experience securing generative AI applications, LLM-based products, AI agents, agentic workflows, MCP integrations, and RAG systems.
  • Familiarity with prompt injection, indirect prompt injection, tool abuse, agent authorization, data leakage, model abuse, and AI threat modeling.
  • Experience developing security guidance for AI-enabled software development.
  • Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent are preferred.

Benefits

  • Hybrid work arrangement with three days per week onsite; candidates near Tysons Corner are prioritized.
  • Medical, dental, and vision benefits.
  • 401(k), short-term and long-term disability, life and AD&D insurance.
  • Statutory leaves, paid parental leave, and paid holidays.
  • Benefits and eligibility may vary by location and role.

Tech Stack

Categories

Medallia

About Medallia

5,001-10,000 employees

Medallia builds enterprise SaaS for experience management, turning customer, employee, and patient feedback and behavioral signals into insights and actions via Medallia Experience Cloud. The company sells subscriptions and services to large organizations, offering surveys, text analytics, social listening, and workflow integrations. Founded in 2001 and headquartered in McLean, Virginia, Medallia is privately held under Thoma Bravo after being taken private from the NYSE.

Contact me