The Role and TeamWe are looking for a motivated FedRAMP security engineer who is ready to explore the world of Federal Security (FedRAMP and beyond) and GRC Engineering. This role will have a heavy focus on GRC Engineering and FedRAMP compliance and security automation. This is a technical role that not only develops and implements security solutions but uses the solutions to combat malicious cyber attacks while satisfying FedRAMP compliance requirements. While Medallia FedRAMP is a well established FedRAMP certified CSP this is a growing and rapidly evolving landscape with an ever growing range of technologies, tools and a significant potential to grow within the team.
Responsibilities- Full lifecycle security tool management including selecting, deploying, integrating, maintaining, and twilight security technologies such as SIEM's, Log Management, Vulnerability Management Platforms, AV, etc.
- Security alert and incident management with a focus on alert and threat hunting automation
- Will provide technical support for compliance and security audits and will be the subject matter expert for FedRAMP security controls during audits
- GRC Engineering for compliance automation
- This is a technical hands on position that will have opportunities for coding, scripting and automation as well as continually learning and understanding new technologies
Candidates based in the Tysons vicinity will be prioritized as this role is Hybrid, 3 days per week onsite.
QualificationsMinimum Qualifications
- Eligibility Requirement: Must reside in the U.S. and hold U.S. Citizenship or a Green Card (Lawful Permanent Resident) to meet FedRAMP compliance requirements.
- 5+ years of progressive experience in Security Operations, cloud security, or security systems engineering (managing servers, DB, AWS cloud infrastructure, and core enterprise security tools).
- Demonstrated experience writing Python code to build security utilities, interact with APIs, and drive system automation.
- Proven track record directly administering, configuring, and managing enterprise security toolsets throughout their lifecycle.
Preferred Qualifications
- Deep practical understanding of cybersecurity fundamentals, threat models, and regulatory frameworks (specifically NIST SP 800-53 and FedRAMP Moderate/High standards) and supporting continuous monitoring in FedRAMP environments.
- Direct experience building and maintaining custom Splunk applications
- Proven ability to translate non-technical business and regulatory requirements into scalable technical solutions.
- Independent problem-solving capabilities with exceptional written and verbal cross-team communication skills.
Medallia is committed to equal pay and transparency. The annual base salary range for this position is $128,500- $188,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Medallia considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, candidate's work location, education/training, key skills, internal peer equity, external market data, as well as, market and business considerations when making compensation decisions.
Medallia also offers competitive health and wellness benefits, including but not limited to medical, dental, vision, 401(k), short-term and long-term disability, life and AD&D insurance, statutory leaves, paid parental leave, and paid holidays. Benefits and eligibility may vary by location and role.
#LI-KT1