About The Position

Medallia is seeking a Senior Staff Product Security Engineer to lead the company's security strategy and assurance efforts for AI-powered products, agentic systems, next-generation platforms, and emerging technologies. This individual will be the technical leader for AI Security and Security Assurance, collaborating with Product, Engineering, Architecture, Data Science, and Security teams to ensure security is integrated into the design, development, and deployment of modern AI-enabled capabilities. The role requires deep expertise in application security, threat modeling, and security architecture, combined with a strong understanding of Generative AI, LLMs, AI agents, and secure system design. The engineer will identify emerging risks, establish scalable security practices, and help shape Medallia's long-term strategy for securing AI-enabled products and platforms.

Requirements

  • 12+ years of experience in Product Security, Application Security, Security Architecture, or Security Engineering.
  • Proven experience operating at Staff or Senior Staff level within a technology organization.
  • Demonstrated expertise in Threat Modeling, Security Architecture Reviews, Application Security, Cloud Security, Secure SDLC, Vulnerability Management, and Secure Design Principles.
  • Experience securing modern architectures including APIs, Microservices, Kubernetes, Containers, and Cloud-native platforms.
  • Strong understanding of security frameworks and standards including OWASP, NIST, SOC 2, ISO 27001, and PCI DSS.
  • Demonstrated ability to influence engineering organizations and drive security outcomes without direct authority.

Nice To Haves

  • Experience securing Generative AI applications, LLM-based products, AI agents, Agentic workflows, MCP integrations, Retrieval-Augmented Generation (RAG) systems.
  • Familiarity with AI security concepts including Prompt Injection, Indirect Prompt Injection, Tool Abuse, Agent Authorization, Data Leakage, Model Abuse, and AI Threat Modeling.
  • Experience developing security guidance for AI-enabled software development.
  • Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent.

Responsibilities

  • Serve as the technical authority for security reviews involving Generative AI applications, LLM-powered features, AI agents, Agentic workflows, MCP (Model Context Protocol) integrations, AI skills and marketplaces, AI coding assistants, and Bring Your Own Model (BYOM) capabilities.
  • Define security requirements and guardrails for AI-enabled products and services.
  • Evaluate emerging AI technologies and assess associated security risks.
  • Partner with engineering and product teams to ensure AI features are secure by design.
  • Lead threat modeling efforts for critical product and platform initiatives.
  • Establish and scale a threat modeling program across engineering organizations.
  • Conduct security architecture reviews for high-risk and strategic initiatives.
  • Develop security reference architectures, design patterns, and guidance for engineering teams.
  • Identify systemic security risks and drive long-term remediation strategies.
  • Own and evolve Product Security assurance activities including security reviews, security assessments, AI security reviews, security testing strategies, and security requirements and standards.
  • Define risk-based approaches for evaluating emerging technologies.
  • Partner with engineering teams to embed security validation throughout the SDLC.
  • Establish secure development standards for AI-enabled applications.
  • Drive adoption of secure coding practices across engineering teams.
  • Develop scalable developer guidance and security enablement programs.
  • Evaluate and implement approaches to improve security feedback during development, including AI-assisted security review capabilities.
  • Identify opportunities to automate security reviews and reduce manual effort.
  • Partner with security tooling owners to improve developer experience and security coverage.
  • Define metrics that measure effectiveness of AI security and security assurance programs.
  • Evaluate emerging security technologies relevant to AI and modern software development.
  • Partner closely with Product, Engineering, Architecture, Data Science, Privacy, Legal, Compliance, and Operations teams.
  • Influence technical direction through expertise and relationship-building.
  • Mentor Staff and Senior Engineers in threat modeling, architecture reviews, and AI security.

Benefits

  • Competitive health and wellness benefits, including medical, dental, vision.
  • 401(k).
  • Short-term and long-term disability.
  • Life and AD&D insurance.
  • Statutory leaves.
  • Paid parental leave.
  • Paid holidays.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service