About The Position

Medallia is seeking an experienced Staff Product Security Engineer to drive security across its products and platforms. This individual will be a senior technical contributor within Product Security, collaborating with Engineering, Product, Architecture, and other Security teams. The role involves identifying risks, designing security solutions, and embedding security throughout the software development lifecycle. The ideal candidate will have strong hands-on application and product security expertise, the ability to lead complex security initiatives, establish scalable security patterns, improve security automation, guide engineering teams, and mentor other security engineers. This is a highly technical individual contributor role with significant cross-functional influence.

Requirements

  • 8+ years of experience in application security, product security, security engineering, or related fields.
  • Strong hands-on experience with Application Security, Secure Software Development Lifecycle (SSDLC), Threat Modeling, Security Architecture Reviews, Vulnerability Management, and Secure Coding Practices.
  • Experience securing modern application architectures including APIs, microservices, Kubernetes, containers, and cloud-native services.
  • Experience with public cloud environments, preferably AWS.
  • Experience with application security tooling such as SAST, SCA, secrets detection, DAST, and ASPM platforms.
  • Strong understanding of common application security risks and frameworks, including OWASP.
  • Ability to independently investigate complex security issues and develop practical remediation strategies.
  • Demonstrated ability to influence engineering teams without direct authority.
  • Strong written and verbal communication skills.
  • Professional working proficiency in written and spoken English.

Nice To Haves

  • Experience securing AI/ML systems, GenAI applications, LLMs, AI agents, or MCP-based architectures.
  • Experience developing security automation or integrating security controls into CI/CD and developer workflows.
  • Experience with cloud and container security technologies.
  • Familiarity with NIST, SOC 2, ISO 27001, PCI DSS, or similar frameworks.
  • Experience supporting customer security reviews or security escalations.
  • Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent.

Responsibilities

  • Lead security reviews for complex products, features, services, and architectures.
  • Perform threat modeling and identify security risks early in the product development lifecycle.
  • Partner with engineering teams to design practical mitigations and secure architecture patterns.
  • Provide technical guidance on application, API, cloud, platform, and AI security.
  • Serve as a security partner for major engineering initiatives from design through production.
  • Help evolve and scale Product Security controls throughout the SDLC.
  • Embed security into developer workflows through automated and developer-friendly security controls.
  • Develop reusable security standards, patterns, guidelines, and reference architectures.
  • Identify opportunities to shift security reviews earlier into requirements, design, and development.
  • Drive adoption of secure-by-default engineering practices.
  • Analyze and prioritize vulnerabilities based on exploitability, reachability, business impact, and customer risk.
  • Partner with engineering teams to develop effective remediation strategies.
  • Lead investigation of complex or high-impact product security vulnerabilities.
  • Identify systemic vulnerability patterns and drive broader remediation rather than addressing findings individually.
  • Provide technical input for risk acceptance and security exception decisions.
  • Help design, implement, and optimize security capabilities including SAST, SCA, Secrets Detection, DAST, Container and Cloud Security, ASPM platforms, and AI-assisted security reviews.
  • Automate repetitive security activities and reduce reliance on manual reviews.
  • Improve developer experience by integrating security controls directly into engineering workflows.
  • Develop meaningful metrics for security coverage, adoption, prevention, and remediation.
  • Perform security reviews of GenAI and AI-enabled products.
  • Assess risks associated with LLMs, AI agents, MCP integrations, tool invocation, and emerging AI architectures.
  • Help develop security standards and reusable patterns for AI-enabled applications.
  • Partner with engineering teams to integrate security controls into AI development workflows.
  • Independently lead Product Security initiatives involving multiple engineering teams.
  • Build strong partnerships with Engineering, Product, Architecture, Privacy, Compliance, and Security teams.
  • Influence technical decisions through security expertise and practical recommendations.
  • Mentor Product Security Engineers and help strengthen technical capabilities across the team.
  • Represent Product Security in architecture reviews, technical discussions, and customer security engagements.

Benefits

  • medical
  • dental
  • vision
  • 401(k)
  • short-term and long-term disability
  • life and AD&D insurance
  • statutory leaves
  • paid parental leave
  • paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service