Overview:
Medallia is the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia Experience Cloud, leads the market in the management of experiences, insights, and actions for candidates, customers, employees, patients, and residents alike.
We believe that every experience is a memory that can last a lifetime. Experiences shape the way people feel about a company. And they greatly influence how likely people are to advocate, contribute, and stay. At Medallia, we are committed to creating a world where organizations are loved by their customers and their employees.
We empower exceptional people to create extraordinary experiences together.
Bring your whole self.
The Role and Team
We are seeking a Product Security Engineer II to help identify, assess, and remediate security risks across our products and engineering environments.
This individual will work closely with Product Security engineers and development teams to perform security reviews, investigate vulnerabilities, operate security tooling, support penetration testing activities, and integrate security controls throughout the software development lifecycle.
The ideal candidate has a strong foundation in application security and software engineering concepts, enjoys hands-on technical investigation, and is motivated to grow their expertise across application, cloud, and AI security.
Responsibilities:
Application & Product Security
-
Perform security reviews of applications, APIs, features, and product changes.
-
Identify common application security vulnerabilities and recommend appropriate remediation.
Participate in threat modeling and architecture security reviews with senior Product Security engineers.
Review application designs and implementation details for security risks.
Partner with developers to validate and remediate identified security issues.
Vulnerability Management
-
Triage vulnerabilities identified through automated security tools, penetration tests, bug bounty reports, and internal security reviews.
Validate findings and help determine severity, exploitability, and remediation priority.
Create and track remediation tickets with engineering teams.
Verify remediation and support vulnerability closure.
Escalate critical or complex security issues to senior Product Security engineers when appropriate.
Security Tooling & Automation
-
Operate and support Product Security tools including:
-
SAST
-
SCA
-
Secrets Detection
-
DAST
-
Container Security
-
Cloud Security
-
ASPM platforms
-
Investigate findings generated through automated security scanning.
-
Help improve scan coverage and reduce false positives.
-
Assist with integrating security tooling into CI/CD and developer workflows.
-
Develop scripts and lightweight automation to improve security operations and reduce repetitive manual work.
-
Penetration Testing & Security Validation
-
Coordinate and support third-party penetration testing activities.
-
Assist with defining test scope and technical requirements.
-
Track findings through remediation and retesting.
-
Perform targeted security validation and testing where appropriate.
-
Support bug bounty triage and vulnerability investigation.
Secure Development Lifecycle
-
Support Product Security activities throughout the SDLC.
-
Help engineering teams understand and address security requirements.
-
Promote adoption of approved security tools, standards, and secure development practices.
-
Participate in security reviews during requirements, development, testing, and release phases.
-
Help maintain Product Security documentation, standards, and runbooks.
AI & Emerging Technology Security
-
Assist with security reviews of GenAI and AI-enabled features.
-
Execute established AI security testing procedures and controls.
-
Support testing for risks such as prompt injection, sensitive data exposure, and unsafe tool invocation.
-
Develop knowledge of emerging security areas including LLMs, AI agents, and MCP integrations.
Collaboration
-
Work closely with Product Security, Engineering, Product, Cloud Security, and other Security teams.
-
Communicate security findings clearly to technical stakeholders.
-
Participate in Product Security on-call and intake processes.
-
Contribute to team documentation, knowledge sharing, and process improvements.
Qualifications:
Minimum Qualifications
-
2–5 years of experience in application security, product security, penetration testing, security engineering, software engineering with a security focus, or related fields.
-
Working knowledge of:
-
OWASP Top 10
-
Web and API security
-
Authentication and authorization concepts
-
Common application vulnerabilities
-
Secure coding principles
-
Experience with one or more application security tools such as SAST, SCA, DAST, secrets detection, or vulnerability management platforms.
-
Basic understanding of cloud and container technologies.
-
Ability to analyze technical security findings and communicate remediation guidance to developers.
-
Familiarity with scripting or programming languages such as Python, Java, JavaScript, Go, or similar.
-
Ability to work independently on defined security tasks while collaborating effectively on complex investigations.
-
Professional working proficiency in written and spoken English.
Preferred Qualifications
-
Experience with AWS or other major cloud platforms.
-
Experience with Kubernetes, containers, microservices, or modern API architectures.
-
Experience with penetration testing or vulnerability research.
-
Familiarity with CI/CD pipelines and DevSecOps practices.
-
Exposure to GenAI, LLM, or AI application security.
-
Experience working directly with software engineering teams.
-
Security certifications or relevant technical training are a plus but not required.
Success Measures
Within the first year, this individual will:
-
Independently execute established Product Security review and vulnerability management processes.
-
Effectively triage and validate security findings.
-
Build strong working relationships with engineering teams.
-
Improve security tooling coverage and operational efficiency.
-
Contribute automation that reduces repetitive Product Security work.
-
Develop deeper expertise in threat modeling, architecture review, cloud security, and AI security.
-
Demonstrate increasing ownership of Product Security reviews and initiatives.
Role Expectations
A Product Security Engineer II is expected to:
-
Take ownership of assigned security reviews and vulnerabilities through completion.
-
Apply established security standards consistently and exercise sound technical judgment.
-
Know when to independently resolve an issue and when to escalate.
-
Provide clear and actionable remediation guidance to developers.
-
Continuously improve technical security skills.
-
Contribute to automation, documentation, and team processes.
-
Grow toward independently handling increasingly complex Product Security initiatives.
At Medallia, we celebrate diversity and recognize the value it brings to our customers and employees. Medallia is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age (40 and over), disability, genetic information, veteran status or military service, or any other status protected by state or local law. Individuals with a disability who need an accommodation to apply please contact us at
[email protected]. For information regarding how Medallia collects and uses personal information, please review our Privacy Policies. Applications will be accepted for 30 days from the date this role was posted or until the role has been filled.