Product Security Engineer II
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Al continuar, aceptas nuestros Términos & Política de Privacidad.
Overview
Medallia is the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia Experience Cloud, leads the market in the management of experiences, insights, and actions for candidates, customers, employees, patients, and residents alike.
We believe that every experience is a memory that can last a lifetime. Experiences shape the way people feel about a company. And they greatly influence how likely people are to advocate, contribute, and stay. At Medallia, we are committed to creating a world where organizations are loved by their customers and their employees.
We empower exceptional people to create extraordinary experiences together.
Bring your whole self.
The Role and Team
We are seeking a Product Security Engineer II to help identify, assess, and remediate security risks across our products and engineering environments. This individual will work closely with Product Security engineers and development teams to perform security reviews, investigate vulnerabilities, operate security tooling, support penetration testing activities, and integrate security controls throughout the software development lifecycle.
The ideal candidate has a strong foundation in application security and software engineering concepts, enjoys hands-on technical investigation, and is motivated to grow their expertise across application, cloud, and AI security.
Responsibilities
Application & Product Security
- Perform security reviews of applications, APIs, features, and product changes.
- Identify common application security vulnerabilities and recommend appropriate remediation. Participate in threat modeling and architecture security reviews with senior Product Security engineers. Review application designs and implementation details for security risks. Partner with developers to validate and remediate identified security issues.
Vulnerability Management
- Triage vulnerabilities identified through automated security tools, penetration tests, bug bounty reports, and internal security reviews. Validate findings and help determine severity, exploitability, and remediation priority. Create and track remediation tickets with engineering teams. Verify remediation and support vulnerability closure. Escalate critical or complex security issues to senior Product Security engineers when appropriate.
Security Tooling & Automation
- Operate and support Product Security tools including:
- SAST
- SCA
- Secrets Detection
- DAST
- Container Security
- Cloud Security
- ASPM platforms
- Investigate findings generated through automated security scanning.
- Help improve scan coverage and reduce false positives.
- Assist with integrating security tooling into CI/CD and developer workflows.
- Develop scripts and lightweight automation to improve security operations and reduce repetitive manual work.
- Penetration Testing & Security Validation
- Coordinate and support third-party penetration testing activities.
- Assist with defining test scope and technical requirements.
- Track findings through remediation and retesting.
- Perform targeted security validation and testing where appropriate.
- Support bug bounty triage and vulnerability investigation.
Secure Development Lifecycle
- Support Product Security activities throughout the SDLC.
- Help engineering teams understand and address security requirements.
- Promote adoption of approved security tools, standards, and secure development practices.
- Participate in security reviews during requirements, development, testing, and release phases.
- Help maintain Product Security documentation, standards, and runbooks.
AI & Emerging Technology Security
- Assist with security reviews of GenAI and AI-enabled features.
- Execute established AI security testing procedures and controls.
- Support testing for risks such as prompt injection, sensitive data exposure, and unsafe tool invocation.
- Develop knowledge of emerging security areas including LLMs, AI agents, and MCP integrations.
Collaboration
- Work closely with Product Security, Engineering, Product, Cloud Security, and other Security teams.
- Communicate security findings clearly to technical stakeholders.
- Participate in Product Security on-call and intake processes.
- Contribute to team documentation, knowledge sharing, and process improvements.
Qualifications
Minimum Qualifications
- 2-5 years of experience in application security, product security, penetration testing, security engineering, software engineering with a security focus, or related fields.
- Work