Medallia

Senior Staff Product Security Engineer, AI Security & Security Assurance

Medallia$184K — $245K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in Product Security, Application Security, Security Architecture, or Security Engineering
  • Experience at a Staff or Senior Staff level within technology organizations
  • Expertise in Threat Modeling, Security Architecture Reviews, Application Security, Cloud Security, Secure SDLC, Vulnerability Management, and Secure Design Principles
  • Knowledge of securing modern architectures including APIs, Microservices, Kubernetes, Containers, and Cloud-native platforms
  • Familiarity with security frameworks and standards such as OWASP, NIST, SOC 2, ISO 27001, and PCI DSS
  • Ability to influence engineering organizations and achieve security outcomes without direct authority

Responsibilities

  • Lead AI security reviews for technologies like Generative AI applications and Model Context Protocol integrations
  • Define security requirements for AI-enabled products
  • Evaluate emerging AI technologies and their security risks
  • Establish threat modeling programs across engineering teams
  • Conduct security architecture reviews for high-risk initiatives
  • Drive security assurance activities including assessments and testing strategies
  • Promote secure development standards and practices among engineering teams

Benefits

  • Competitive health and wellness benefits including medical, dental, and vision
  • 401(k) retirement plans
  • Short-term and long-term disability coverage
  • Life and Accidental Death & Dismemberment (AD&D) insurance
  • Paid parental leave and paid holidays
  • Varied benefits and eligibility by location and role
Full Job Description
Overview

The Role and Team

We are seeking a Senior Staff Product Security Engineer to lead Medallia's security strategy and assurance efforts for AI-powered products, agentic systems, next-generation platforms, and emerging technologies.

This individual will serve as the technical leader for AI Security and Security Assurance, partnering with Product, Engineering, Architecture, Data Science, and Security teams to ensure security is embedded into the design, development, and deployment of modern AI-enabled capabilities.

The ideal candidate combines deep expertise in application security, threat modeling, and security architecture with a strong understanding of Generative AI, LLMs, AI agents, and secure system design. They will identify emerging risks, establish scalable security practices, and help define Medallia's long-term approach to securing AI-enabled products and platforms.

Responsibilities

AI Security Lead
  • Serve as the technical authority for security reviews involving:
    • Generative AI applications
    • LLM-powered features
    • AI agents
    • Agentic workflows
    • MCP (Model Context Protocol) integrations
    • AI skills and marketplaces
    • AI coding assistants
    • Bring Your Own Model (BYOM) capabilities
  • Define security requirements and guardrails for AI-enabled products and services.
  • Evaluate emerging AI technologies and assess associated security risks.
  • Partner with engineering and product teams to ensure AI features are secure by design.

Threat Modeling & Security Architecture
  • Lead threat modeling efforts for critical product and platform initiatives.
  • Establish and scale a threat modeling program across engineering organizations.
  • Conduct security architecture reviews for high-risk and strategic initiatives.
  • Develop security reference architectures, design patterns, and guidance for engineering teams.
  • Identify systemic security risks and drive long-term remediation strategies.

Security Assurance
  • Own and evolve Product Security assurance activities including:
    • Security reviews
    • Security assessments
    • AI security reviews
    • Security testing strategies
    • Security requirements and standards
  • Define risk-based approaches for evaluating emerging technologies.
  • Partner with engineering teams to embed security validation throughout the SDLC.

Secure Development & Developer Enablement
  • Establish secure development standards for AI-enabled applications.
  • Drive adoption of secure coding practices across engineering teams.
  • Develop scalable developer guidance and security enablement programs.
  • Evaluate and implement approaches to improve security feedback during development, including AI-assisted security review capabilities.

Security Automation & Innovation
  • Identify opportunities to automate security reviews and reduce manual effort.
  • Partner with security tooling owners to improve developer experience and security coverage.
  • Define metrics that measure effectiveness of AI security and security assurance programs.
  • Evaluate emerging security technologies relevant to AI and modern software development.

Cross-Functional Influence
  • Partner closely with Product, Engineering, Architecture, Data Science, Privacy, Legal, Compliance, and Operations teams.
  • Influence technical direction through expertise and relationship-building.
  • Mentor Staff and Senior Engineers in threat modeling, architecture reviews, and AI security.

Candidates based in the Tysons Corner vicinity will be prioritized as this role is Hybrid, 3 days per week onsite.

Qualifications

Minimum Qualifications
  • 12+ years of experience in Product Security, Application Security, Security Architecture, or Security Engineering.
  • Proven experience operating at Staff or Senior Staff level within a technology organization.
  • Demonstrated expertise in:
    • Threat Modeling
    • Security Architecture Reviews
    • Application Security
    • Cloud Security
    • Secure SDLC
    • Vulnerability Management
    • Secure Design Principles
  • Experience securing modern architectures including:
    • APIs
    • Microservices
    • Kubernetes
    • Containers
    • Cloud-native platforms
  • Strong understanding of security frameworks and standards including:
    • OWASP
    • NIST
    • SOC 2
    • ISO 27001
    • PCI DSS
  • Demonstrated ability to influence engineering organizations and drive security outcomes without direct authority.


Preferred Qualifications
  • Experience securing:
    • Generative AI applications
    • LLM-based products
    • AI agents
    • Agentic workflows
    • MCP integrations
    • Retrieval-Augmented Generation (RAG) systems
  • Familiarity with AI security concepts including:
    • Prompt Injection
    • Indirect Prompt Injection
    • Tool Abuse
    • Agent Authorization
    • Data Leakage
    • Model Abuse
    • AI Threat Modeling
  • Experience developing security guidance for AI-enabled software development.
  • Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent.


Medallia is committed to equal pay and transparency. The annual base salary range for this position is $184,000 - $245,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Medallia considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, candidate's work location, education/training, key skills, internal peer equity, external market data, as well as, market and business considerations when making compensation decisions.

Medallia also offers competitive health and wellness benefits, including but not limited to medical, dental, vision, 401(k), short-term and long-term disability, life and AD&D insurance, statutory leaves, paid parental leave, and paid holidays. Benefits and eligibility may vary by location and role.

About Medallia

Medallia is a software company that provides customer experience management solutions. The company was founded in 2001 by Borge Hald and Amy Pressman and is headquartered in San Francisco, California. Medallia's software allows businesses to collect and analyze customer feedback across multiple channels, including email, social media, and mobile. The company's clients include some of the world's largest brands, such as Hilton, Delta Air Lines, and Mercedes-Benz. Medallia went public in 2019 and is traded on the New York Stock Exchange under the ticker symbol MDLA.
Learn more about Medallia
Size
2,037 employees
Market Cap
$5.3 billion
Industry
Net Income
-$148.6 million
Founded
2001
Revenue
$477.2 million
NASDAQ

Similar Jobs

More Jobs at Medallia

More Information Technology Jobs

Find similar Senior Staff Product Security Engineer, AI Security & Security Assurance jobs: