Provide technical guidance on application, API, cloud, platform, and AI security. * Serve as a security partner for major engineering initiatives from design through production. Secure Development ...
Provide technical guidance on application, API, cloud, platform, and AI security. * Serve as a security partner for major engineering initiatives from design through production. Secure Development ...
Engineer II, Cybersecurity - Application Security
Richmond, VA · On-site
$80K - $120K/yr
The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best ...
Engineer II, Cybersecurity - Application Security
Richmond, VA · On-site
$80K - $120K/yr
The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best ...
Engineer II, Cybersecurity - Application Security
Richmond, VA · On-site
$54.25 - $72.50/hr
The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best ...
Engineer II, Cybersecurity - Application Security
Richmond, VA · On-site
$54.25 - $72.50/hr
The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best ...
Provide technical guidance on application, API, cloud, platform, and AI security. * Serve as a security partner for major engineering initiatives from design through production. Secure Development ...
Provide technical guidance on application, API, cloud, platform, and AI security. * Serve as a security partner for major engineering initiatives from design through production. Secure Development ...
Senior Security Engineer
Arlington, VA · On-site +1
$140K - $180K/yr
Strong candidates will have deep hands-on experience across security engineering, cloud, Linux, networking, automation, and application security, with a desire to learn and work with emerging ...
Senior Security Engineer
Arlington, VA · On-site +1
$140K - $180K/yr
Strong candidates will have deep hands-on experience across security engineering, cloud, Linux, networking, automation, and application security, with a desire to learn and work with emerging ...
Security Engineer - Remote
Reston, VA · Remote
Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the ... Work with DevOps teams to securely harden Linux based machines and cloudinfrastructure Basic ...
Security Engineer - Remote
Reston, VA · Remote
Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the ... Work with DevOps teams to securely harden Linux based machines and cloudinfrastructure Basic ...
System Security Engineer
Reston, VA · On-site
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Reston, VA · On-site
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Reston, VA · On-site
$120 - $150/hr
... Application Security Engineer, Identity and Access Management Engine, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Reston, VA · On-site
$120 - $150/hr
... Application Security Engineer, Identity and Access Management Engine, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Tysons, VA · On-site
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Tysons, VA · On-site
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the ... Work with DevOps teams to securely harden Linux based machines and cloudinfrastructure Basic ...
Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the ... Work with DevOps teams to securely harden Linux based machines and cloudinfrastructure Basic ...
System Security Engineer
Chantilly, VA · On-site
$110 - $160/hr
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Chantilly, VA · On-site
$110 - $160/hr
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Chantilly, VA · On-site
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
System Security Engineer
Chantilly, VA · On-site
... Application Security Engineer, Identity and Access Management Engineer, Threat Detection Engineer, Vulnerability Management Engineer, Risk Assessment Engineer, Compliance Security Engineer, Incident ...
Engineer II, Cybersecurity - Application Security
Richmond, VA · On-site
$80.60 - $120.90/hr
The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best ...
Engineer II, Cybersecurity - Application Security
Richmond, VA · On-site
$80.60 - $120.90/hr
The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best ...
Cloud Security Engineer
Arlington, VA · On-site
$140K - $170K/yr
We're looking for a security engineer who understands vulnerability management as an end-to-end ... Partner with platform, cloud, and application teams to drive sustainable remediation outcomes
Cloud Security Engineer
Arlington, VA · On-site
$140K - $170K/yr
We're looking for a security engineer who understands vulnerability management as an end-to-end ... Partner with platform, cloud, and application teams to drive sustainable remediation outcomes
... application security, threat hunting, and threat intelligence. Key job responsibilities ... internship) experience - Bachelor's degree in a STEM field (Science, Technology, Engineering ...
... application security, threat hunting, and threat intelligence. Key job responsibilities ... internship) experience - Bachelor's degree in a STEM field (Science, Technology, Engineering ...
Application security standards and processes * Accreditation and Authorization (A&A), including ... Coordination with engineering team to implement security requirements * Agile / Scrum
Application security standards and processes * Accreditation and Authorization (A&A), including ... Coordination with engineering team to implement security requirements * Agile / Scrum
Information Systems Security Engineer (ISSE)
Herndon, VA · On-site
$140K - $190K/yr
Possess a working knowledge of administrating servers, system and application security threats and ... Demonstrate writing of your own project in scripting/programming (use of Shell scripting, Python ...
Quick apply
Information Systems Security Engineer (ISSE)
Herndon, VA · On-site
$140K - $190K/yr
Possess a working knowledge of administrating servers, system and application security threats and ... Demonstrate writing of your own project in scripting/programming (use of Shell scripting, Python ...
Security Engineer - IV
Reston, VA · On-site
Our client is currently seeking a Security Engineer - IV [ Additional Description ] ****Working ... Devise mitigation techniques for application and system owners. Follow up on resolution of ...
Security Engineer - IV
Reston, VA · On-site
Our client is currently seeking a Security Engineer - IV [ Additional Description ] ****Working ... Devise mitigation techniques for application and system owners. Follow up on resolution of ...
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMEN[...]
Arlington, VA · On-site
$130 - $160/hr
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME POSITION OVERVIEW The Zero Trust ... Leverage AI‑assisted analysis tools, automation platforms, and prompt engineering techniques to ...
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMEN[...]
Arlington, VA · On-site
$130 - $160/hr
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME POSITION OVERVIEW The Zero Trust ... Leverage AI‑assisted analysis tools, automation platforms, and prompt engineering techniques to ...
Support the assessment, design, and implementation of application security for Oracle Cloud ERP, ... Work you'll do As a Security Engineer II on the Cyber Enterprise Security team, you will be ...
Support the assessment, design, and implementation of application security for Oracle Cloud ERP, ... Work you'll do As a Security Engineer II on the Cyber Enterprise Security team, you will be ...
Internship Application Security Engineer information
What does an internship application security engineer do?
What types of projects and tasks can I expect to work on as an internship application security engineer?
What are the key skills and qualifications needed to thrive as an internship application security engineer, and why are they important?
What are the most commonly searched types of Application Security Engineer jobs in Virginia?
The most popular types of Application Security Engineer jobs in Virginia are:
What are popular job titles related to Internship Application Security Engineer jobs in Virginia?
For Internship Application Security Engineer jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Internship Application Security Engineer jobs in Virginia look for?
The top searched job categories for Internship Application Security Engineer jobs in Virginia are:
What cities in Virginia are hiring for Internship Application Security Engineer jobs?
Cities in Virginia with the most Internship Application Security Engineer job openings:

Other
Medical, Dental, Vision, Life, Retirement
This job post has expired today. Applications are no longer accepted.
Job description
Medallia is the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia Experience Cloud, leads the market in the management of experiences, insights, and actions for candidates, customers, employees, patients, and residents alike.
We believe that every experience is a memory that can last a lifetime. Experiences shape the way people feel about a company. And they greatly influence how likely people are to advocate, contribute, and stay. At Medallia, we are committed to creating a world where organizations are loved by their customers and their employees.
We empower exceptional people to create extraordinary experiences together.
Bring your whole self.
The Role and Team
We are seeking an experienced Staff Product Security Engineer to help drive security across our products and platforms. This individual will serve as a senior technical contributor within Product Security, partnering closely with Engineering, Product, Architecture, and other Security teams to identify risks, design practical security solutions, and embed security throughout the software development lifecycle.
The ideal candidate combines strong hands-on application and product security expertise with the ability to independently lead complex security initiatives. They will help establish scalable security patterns, improve security automation, guide engineering teams through complex security decisions, and mentor other security engineers.
This is a highly technical individual contributor role with significant cross-functional influence.
Responsibilities
Product Security Engineering
- Lead security reviews for complex products, features, services, and architectures.
- Perform threat modeling and identify security risks early in the product development lifecycle.
- Partner with engineering teams to design practical mitigations and secure architecture patterns.
- Provide technical guidance on application, API, cloud, platform, and AI security.
- Serve as a security partner for major engineering initiatives from design through production.
Secure Development Lifecycle
- Help evolve and scale Product Security controls throughout the SDLC.
- Embed security into developer workflows through automated and developer-friendly security controls.
- Develop reusable security standards, patterns, guidelines, and reference architectures.
- Identify opportunities to shift security reviews earlier into requirements, design, and development.
- Drive adoption of secure-by-default engineering practices.
Vulnerability & Risk Management
- Analyze and prioritize vulnerabilities based on exploitability, reachability, business impact, and customer risk.
- Partner with engineering teams to develop effective remediation strategies.
- Lead investigation of complex or high-impact product security vulnerabilities.
- Identify systemic vulnerability patterns and drive broader remediation rather than addressing findings individually.
- Provide technical input for risk acceptance and security exception decisions.
Security Automation & Tooling
- Help design, implement, and optimize security capabilities including:
- SAST
- SCA
- Secrets Detection
- DAST
- Container and Cloud Security
- ASPM platforms
- AI-assisted security reviews
- Automate repetitive security activities and reduce reliance on manual reviews.
- Improve developer experience by integrating security controls directly into engineering workflows.
- Develop meaningful metrics for security coverage, adoption, prevention, and remediation.
AI & Emerging Technology Security
- Perform security reviews of GenAI and AI-enabled products.
- Assess risks associated with LLMs, AI agents, MCP integrations, tool invocation, and emerging AI architectures.
- Help develop security standards and reusable patterns for AI-enabled applications.
- Partner with engineering teams to integrate security controls into AI development workflows.
Cross-Functional Leadership
- Independently lead Product Security initiatives involving multiple engineering teams.
- Build strong partnerships with Engineering, Product, Architecture, Privacy, Compliance, and Security teams.
- Influence technical decisions through security expertise and practical recommendations.
- Mentor Product Security Engineers and help strengthen technical capabilities across the team.
- Represent Product Security in architecture reviews, technical discussions, and customer security engagements.
Candidates based in the Tysons Corner vicinity will be prioritized as this role is Hybrid, 3 days per week onsite.
Qualifications
Minimum Qualifications
- 8+ years of experience in application security, product security, security engineering, or related fields.
- Strong hands-on experience with:
- Application Security
- Secure Software Development Lifecycle (SSDLC)
- Threat Modeling
- Security Architecture Reviews
- Vulnerability Management
- Secure Coding Practices
- Experience securing modern application architectures including APIs, microservices, Kubernetes, containers, and cloud-native services.
- Experience with public cloud environments, preferably AWS.
- Experience with application security tooling such as SAST, SCA, secrets detection, DAST, and ASPM platforms.
- Strong understanding of common application security risks and frameworks, including OWASP.
- Ability to independently investigate complex security issues and develop practical remediation strategies.
- Demonstrated ability to influence engineering teams without direct authority.
- Strong written and verbal communication skills.
- Professional working proficiency in written and spoken English.
Preferred
- Experience securing AI/ML systems, GenAI applications, LLMs, AI agents, or MCP-based architectures.
- Experience developing security automation or integrating security controls into CI/CD and developer workflows.
- Experience with cloud and container security technologies.
- Familiarity with NIST, SOC 2, ISO 27001, PCI DSS, or similar frameworks.
- Experience supporting customer security reviews or security escalations.
- Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent.
Success Measures
Within the first year, this individual will:
- Independently lead complex Product Security initiatives.
- Improve security coverage and automation across engineering workflows.
- Establish reusable security patterns adopted by multiple engineering teams.
- Identify and address systemic security risks rather than individual vulnerabilities alone.
- Improve developer adoption of Product Security controls.
- Provide effective technical mentorship to other security engineers.
- Become a trusted security partner to Engineering and Product teams.
Leadership Expectations
- A Staff Product Security Engineer is expected to:
- Own complex security problems from identification through resolution.
- Think beyond individual findings and identify systemic solutions.
- Influence technical decisions across multiple teams.
- Balance security risk, engineering complexity, and business needs.
- Provide strong technical mentorship to other engineers.
- Operate independently while knowing when broader leadership alignment is required.
- Create scalable solutions that reduce security friction for engineering teams.
Medallia is committed to equal pay and transparency. The annual base salary range for this position is $154,000 - $205,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Medallia considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, candidate's work location, education/training, key skills, internal peer equity, external market data, as well as, market and business considerations when making compensation decisions.
Medallia also offers competitive health and wellness benefits, including but not limited to medical, dental, vision, 401(k), short-term and long-term disability, life and AD&D insurance, statutory leaves, paid parental leave, and paid holidays. Benefits and eligibility may vary by location and role.
At Medallia, we celebrate diversity and recognize the value it brings to our customers and employees. Medallia is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age (40 and over), disability, genetic information, veteran status or military service, or any other status protected by state or local law. Individuals with a disability who need an accommodation to apply please contact us at ApplicantAccessibility@medallia.com. For information regarding how Medallia collects and uses personal information, please review our Privacy Policies. Applications will be accepted for 30 days from the date this role was posted or until the role has been filled.
About Medallia
Sourced by ZipRecruiter
Industry
It services
Company size
1,001 - 5,000 Employees
Headquarters location
San Mateo, CA, US
Year founded
2001