Security Engineer Visa Sponsorship Jobs in Virginia
Virginia is one of the strongest states for security engineer visa sponsorship, driven by the massive concentration of defense contractors, federal agencies, and cloud infrastructure companies in the Northern Virginia corridor. Major employers like Booz Allen Hamilton, Leidos, SAIC, and Amazon Web Services actively hire and sponsor security engineers across the Arlington, McLean, Reston, and Herndon area.
Find Security Engineer JobsOverview
Showing 5 of 124+ Security Engineer Jobs in Virginia with Visa Sponsorship










See all 124+ Security Engineer Jobs in Virginia with Visa Sponsorship
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Engineer Jobs in Virginia with Visa Sponsorship.
Get Access To All Jobs
INTRODUCTION
Medallia is the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia Experience Cloud, leads the market in the management of experiences, insights, and actions for candidates, customers, employees, patients, and residents alike.
We believe that every experience is a memory that can last a lifetime. Experiences shape the way people feel about a company. And they greatly influence how likely people are to advocate, contribute, and stay. At Medallia, we are committed to creating a world where organizations are loved by their customers and their employees.
We empower exceptional people to create extraordinary experiences together.
THE ROLE AND TEAM
We are seeking a Senior Staff Product Security Engineer to lead Medallia's security strategy and assurance efforts for AI-powered products, agentic systems, next-generation platforms, and emerging technologies. This individual will serve as the technical leader for AI Security and Security Assurance, partnering with Product, Engineering, Architecture, Data Science, and Security teams to ensure security is embedded into the design, development, and deployment of modern AI-enabled capabilities. The ideal candidate combines deep expertise in application security, threat modeling, and security architecture with a strong understanding of Generative AI, LLMs, AI agents, and secure system design. They will identify emerging risks, establish scalable security practices, and help define Medallia's long-term approach to securing AI-enabled products and platforms.
Responsibilities:
AI Security Lead:
Serve as the technical authority for security reviews involving:
- Generative AI applications
- LLM-powered features
- AI agents
- Agentic workflows
- MCP (Model Context Protocol) integrations
- AI skills and marketplaces
- AI coding assistants
- Bring Your Own Model (BYOM) capabilities
Define security requirements and guardrails for AI-enabled products and services.
Evaluate emerging AI technologies and assess associated security risks.
Partner with engineering and product teams to ensure AI features are secure by design.
Threat Modeling & Security Architecture:
Lead threat modeling efforts for critical product and platform initiatives.
Establish and scale a threat modeling program across engineering organizations.
Conduct security architecture reviews for high-risk and strategic initiatives.
Develop security reference architectures, design patterns, and guidance for engineering teams.
Identify systemic security risks and drive long-term remediation strategies.
Security Assurance:
Own and evolve Product Security assurance activities including:
- Security reviews
- Security assessments
- AI security reviews
- Security testing strategies
- Security requirements and standards
Define risk-based approaches for evaluating emerging technologies.
Partner with engineering teams to embed security validation throughout the SDLC.
Secure Development & Developer Enablement:
Establish secure development standards for AI-enabled applications.
Drive adoption of secure coding practices across engineering teams.
Develop scalable developer guidance and security enablement programs.
Evaluate and implement approaches to improve security feedback during development, including AI-assisted security review capabilities.
Security Automation & Innovation:
Identify opportunities to automate security reviews and reduce manual effort.
Partner with security tooling owners to improve developer experience and security coverage.
Define metrics that measure effectiveness of AI security and security assurance programs.
Evaluate emerging security technologies relevant to AI and modern software development.
Cross-Functional Influence:
Partner closely with Product, Engineering, Architecture, Data Science, Privacy, Legal, Compliance, and Operations teams.
Influence technical direction through expertise and relationship-building.
Mentor Staff and Senior Engineers in threat modeling, architecture reviews, and AI security.
Candidates based in the Tysons Corner vicinity will be prioritized as this role is Hybrid, 3 days per week onsite.
MINIMUM QUALIFICATIONS
- 12+ years of experience in Product Security, Application Security, Security Architecture, or Security Engineering.
- Proven experience operating at Staff or Senior Staff level within a technology organization.
- Demonstrated expertise in:
- Threat Modeling
- Security Architecture Reviews
- Application Security
- Cloud Security
- Secure SDLC
- Vulnerability Management
- Secure Design Principles
- Experience securing modern architectures including:
- APIs
- Microservices
- Kubernetes
- Containers
- Cloud-native platforms
- Strong understanding of security frameworks and standards including:
- OWASP
- NIST
- SOC 2
- ISO 27001
- PCI DSS
- Demonstrated ability to influence engineering organizations and drive security outcomes without direct authority.
PREFERRED QUALIFICATIONS
- Experience securing:
- Generative AI applications
- LLM-based products
- AI agents
- Agentic workflows
- MCP integrations
- Retrieval-Augmented Generation (RAG) systems
- Familiarity with AI security concepts including:
- Prompt Injection
- Indirect Prompt Injection
- Tool Abuse
- Agent Authorization
- Data Leakage
- Model Abuse
- AI Threat Modeling
- Experience developing security guidance for AI-enabled software development.
- Security certifications such as CISSP, CSSLP, GIAC, AWS Security Specialty, or equivalent.
COMPENSATION
- The annual base salary range for this position is $184,000 - $245,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Medallia considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, candidate’s work location, education/training, key skills, internal peer equity, external market data, as well as, market and business considerations when making compensation decisions.
Medallia also offers competitive health and wellness benefits, including but not limited to medical, dental, vision, 401(k), short-term and long-term disability, life and AD&D insurance, statutory leaves, paid parental leave, and paid holidays. Benefits and eligibility may vary by location and role.
At Medallia, we celebrate diversity and recognize the value it brings to our customers and employees. Medallia is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age (40 and over), disability, genetic information, veteran status or military service, or any other status protected by state or local law. Individuals with a disability who need an accommodation to apply please contact us at ApplicantAccessibility@medallia.com. For information regarding how Medallia collects and uses personal information, please review our Privacy Policies. Applications will be accepted for 30 days from the date this role was posted or until the role has been filled.
Security Engineer Job Roles in Virginia
See all 124+ Security Engineer Jobs in Virginia
Sign up for free to filter by visa type, set job alerts, and find employers with verified sponsorship history.
Search Security Engineer Jobs in VirginiaSecurity Engineer Jobs in Virginia: Frequently Asked Questions
Which companies sponsor visas for security engineers in Virginia?
Virginia's Northern Virginia corridor hosts some of the most active sponsors for security engineers. Defense and government IT contractors including Booz Allen Hamilton, Leidos, SAIC, and ManTech regularly file H-1B visa petitions for security engineering roles. Amazon Web Services, Capital One, and Northrop Grumman also appear consistently in Department of Labor disclosure data as Virginia-based sponsors for this role category.
Which visa types are most common for security engineer roles in Virginia?
The H-1B is the most common visa for security engineers in Virginia, as the role qualifies as a specialty occupation requiring at least a bachelor's degree in computer science, information security, or a related field. Some candidates also enter through the L-1B intracompany transfer visa if moving within a multinational employer. TN visa status is available for Canadian and Mexican nationals in qualifying engineering classifications.
Which cities in Virginia have the most security engineer sponsorship jobs?
Northern Virginia dominates, with Herndon, Reston, McLean, Arlington, and Tysons forming the core cluster of security engineering sponsorship activity. This region's proximity to federal agencies and the intelligence community drives exceptionally high demand. Richmond has a smaller but growing presence through financial services and state government IT. Outside Northern Virginia, activity drops significantly.
How to find security engineer visa sponsorship jobs in Virginia?
Migrate Mate filters job listings specifically by visa sponsorship availability, so you can search security engineer roles in Virginia without sifting through positions that won't support international candidates. Because Northern Virginia has a high volume of defense and federal IT roles that require security clearances, pay close attention to clearance requirements, as those positions often restrict sponsorship for candidates who cannot obtain clearance.
Are there state-specific factors that affect visa sponsorship for security engineers in Virginia?
Virginia's concentration of federal contractors introduces a complication most other states don't have: many security engineer roles require a U.S. security clearance, which is generally unavailable to foreign nationals on temporary work visas. This narrows the sponsorship pool compared to the total volume of security engineering jobs posted. Roles at commercial tech companies and cloud providers in Northern Virginia are more likely to be clearance-free and open to sponsored candidates.
What is the prevailing wage for sponsored security engineer jobs in Virginia?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.