Security Product Manager Jobs in Virginia
Security Product Manager jobs in Virginia are in strong demand, with concentrated hiring across the defense technology, cybersecurity, and federal IT contracting sectors and openings at every level from associate product manager through senior and principal. The Northern Virginia corridor anchoring Tysons Corner, Reston, and Arlington draws the largest share of hiring, followed by Richmond and the Hampton Roads region, where established employers like Leidos, SAIC, and General Dynamics Information Technology maintain significant product teams. Cybersecurity platform development, zero-trust architecture products, and cleared product management roles represent the most sought-after specialties in the Virginia market. Find a role that fits below and apply directly.
Find Security Product Manager JobsOverview
Showing 5 of 13+ Security Product Manager jobs











We believe that every experience is a memory that can last a lifetime. Experiences shape the way people feel about a company. And they greatly influence how likely people are to advocate, contribute, and stay. At Medallia, we are committed to creating a world where organizations are loved by their customers and their employees.
We empower exceptional people to create extraordinary experiences together.
Bring your whole self.
The Role and Team
-
Serve as the technical authority for security reviews involving:
- Generative AI applications
- LLM-powered features
- AI agents
- Agentic workflows
- MCP (Model Context Protocol) integrations
- AI skills and marketplaces
- AI coding assistants
- Bring Your Own Model (BYOM) capabilities
- Define security requirements and guardrails for AI-enabled products and services.
- Evaluate emerging AI technologies and assess associated security risks.
- Partner with engineering and product teams to ensure AI features are secure by design.
- Lead threat modeling efforts for critical product and platform initiatives.
- Establish and scale a threat modeling program across engineering organizations.
- Conduct security architecture reviews for high-risk and strategic initiatives.
- Develop security reference architectures, design patterns, and guidance for engineering teams.
- Identify systemic security risks and drive long-term remediation strategies.
-
Own and evolve Product Security assurance activities including:
- Security reviews
- Security assessments
- AI security reviews
- Security testing strategies
- Security requirements and standards
- Define risk-based approaches for evaluating emerging technologies.
- Partner with engineering teams to embed security validation throughout the SDLC.
- Establish secure development standards for AI-enabled applications.
- Drive adoption of secure coding practices across engineering teams.
- Develop scalable developer guidance and security enablement programs.
- Evaluate and implement approaches to improve security feedback during development, including AI-assisted security review capabilities.
- Identify opportunities to automate security reviews and reduce manual effort.
- Partner with security tooling owners to improve developer experience and security coverage.
- Define metrics that measure effectiveness of AI security and security assurance programs.
- Evaluate emerging security technologies relevant to AI and modern software development.
- Partner closely with Product, Engineering, Architecture, Data Science, Privacy, Legal, Compliance, and Operations teams.
- Influence technical direction through expertise and relationship-building.
- Mentor Staff and Senior Engineers in threat modeling, architecture reviews, and AI security.
Qualifications:
- 12+ years of experience in Product Security, Application Security, Security Architecture, or Security Engineering.
- Proven experience operating at Staff or Senior Staff level within a technology organization.
-
Demonstrated expertise in:
- Threat Modeling
- Security Architecture Reviews
- Application Security
- Cloud Security
- Secure SDLC
- Vulnerability Management
- Secure Design Principles
-
Experience securing modern architectures including:
- APIs
- Microservices
- Kubernetes
- Containers
- Cloud-native platforms
-
Strong understanding of security frameworks and standards including:
- OWASP
- NIST
- SOC 2
- ISO 27001
- PCI DSS
- Demonstrated ability to influence engineering organizations and drive security outcomes without direct authority.
Preferred Qualifications
-
Experience securing:
- Generative AI applications
- LLM-based products
- AI agents
- Agentic workflows
- MCP integrations
- Retrieval-Augmented Generation (RAG) systems
-
Familiarity with AI security concepts including:
- Prompt Injection
- Indirect Prompt Injection
- Tool Abuse
- Agent Authorization
- Data Leakage
- Model Abuse
- AI Threat Modeling
- Experience developing security guidance for AI-enabled software development.
- Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent.
Medallia is committed to equal pay and transparency. The annual base salary range for this position is $184,000 - $245,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Medallia considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, candidate’s work location, education/training, key skills, internal peer equity, external market data, as well as, market and business considerations when making compensation decisions.
Medallia also offers competitive health and wellness benefits, including but not limited to medical, dental, vision, 401(k), short-term and long-term disability, life and AD&D insurance, statutory leaves, paid parental leave, and paid holidays. Benefits and eligibility may vary by location and role.
At Medallia, we celebrate diversity and recognize the value it brings to our customers and employees. Medallia is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age (40 and over), disability, genetic information, veteran status or military service, or any other status protected by state or local law. Individuals with a disability who need an accommodation to apply please contact us at ApplicantAccessibility@medallia.com. For information regarding how Medallia collects and uses personal information, please review our Privacy Policies. Applications will be accepted for 30 days from the date this role was posted or until the role has been filled.
See All 13 Security Product Manager Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find Security Product Manager JobsSecurity Product Manager Jobs by City in Virginia
Where Virginia roles are concentrated, by current openings.
Security Product Manager Job Market in Virginia
A snapshot from current Virginia openings, updated as new roles post.
Who's Hiring



What Virginia Employers Look For
The qualifications that appear most often in security product manager jobs across Virginia.
- Bachelor's degree in computer science, cybersecurity, or a related technical discipline required
- Demonstrated experience defining and shipping security software or SaaS product roadmaps
- Active DoD security clearance (Secret or Top Secret/SCI) strongly preferred for Virginia roles
- Familiarity with NIST cybersecurity frameworks and FedRAMP compliance requirements
- Proven ability to translate threat intelligence and customer needs into prioritized product backlogs
- Experience collaborating with engineering, compliance, and federal or enterprise sales teams
Security Product Manager Jobs in Virginia: Frequently Asked Questions
How do you become a security product manager in Virginia?
Most Virginia employers expect a bachelor's degree in computer science, information systems, cybersecurity, or a closely related technical field, paired with hands-on product or program management experience in a security context. Because much of Virginia's market is defense and federal contracting, obtaining a DoD security clearance early significantly expands your options. Earning a Certified Information Systems Security Professional (CISSP) credential or a Product Management certification from organizations like the Product School also strengthens your candidacy for senior roles.
Which companies hire security product managers in Virginia?
Employers hiring security product managers in Virginia right now include Medallia, Amazon, and Capital One, based on current listings on Migrate Mate as of September 2026. Virginia's dense concentration of defense contractors and federal IT integrators means many of these openings require or prefer candidates with an active security clearance and experience working within government-adjacent product environments.
Which Virginia cities have the most security product manager jobs?
The cities with the most security product manager openings in Virginia are McLean, Arlington, and Vienna. Northern Virginia dominates because of its proximity to federal agencies, the Department of Defense, and the global headquarters of major defense and cybersecurity contractors, while Richmond and Hampton Roads contribute additional volume through regional tech offices and Navy-aligned program teams.
Are there remote security product manager jobs in Virginia?
Yes, and more than many technical roles, since security product management is primarily a desk-based, collaborative function that doesn't require physical access to hardware or a facility. About 100% of security product manager openings tied to Virginia are remote or hybrid as of September 2026, though roles that require an active clearance or involve classified programs typically mandate on-site or cleared-facility presence in Northern Virginia.
How can I get hired as a security product manager in Virginia with little or no experience?
The most realistic entry path is moving into a security product role from an adjacent position such as cybersecurity analyst, security operations engineer, or junior program coordinator, where you build familiarity with product workflows alongside technical depth. Large Virginia defense contractors including Leidos, SAIC, and Northrop Grumman run associate product manager and rotational early-career programs that actively recruit candidates from these backgrounds. Pursuing a CompTIA Security+ certification and contributing to a documented side project or open-source security tool provides a concrete portfolio edge when competing without direct PM experience.
Where can I find and apply to security product manager jobs in Virginia?
You can find and apply to security product manager jobs in Virginia on Migrate Mate, which lists current Virginia openings updated regularly. Find the roles that fit your background and apply directly to the employers posting them.
See All 13 Security Product Manager Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find Security Product Manager Jobs