> Markdown version of [/jobs/ext/1353255-staff-application-security-engineer-product-security](https://www.wearedevelopers.com/jobs/ext/1353255-staff-application-security-engineer-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff, Application Security Engineer - Product Security - **Company:** Wal-Mart Stores, Inc. - **Location:** Herndon, VA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Web Accessibility, Application Lifecycle Management, Code Review, Cyber Security, Information Systems, Databases, Data Validation, Information Systems Security Architecture Professional, Open Web Application Security, Secure Coding, Web Content Accessibility Guidelines, Software Security, Information Technology, Data Analytics, Static Application Security Testing - **Published:** July 20, 2026 - **Apply:** https://www.jofdav.com/jobs/58909620-staff-application-security-engineer-product-security ## About the Role * You have proven experience partnering with technology and business stakeholders to integrate security early in the product lifecycle. * You have deep expertise in OWASP risks, secure coding patterns, and threat modeling, with the ability to define secure-by-default standards and clearly distinguish acceptable risk tradeoffs. * You have strong experience governing secure architecture and defining configuration baselines across enterprise environments (e.g., authorization models, database hardening, input validation frameworks). * You have demonstrated proficiency designing and validating security controls, mapping them to compliance frameworks, and producing defensible audit evidence. * You have experience operationalizing SAST and SCA tooling outputs, assessing misconfiguration risk, and minimizing false positive and false negative validation outcomes. * You have experience aligning technical security decisions with enterprise risk modeling and risk acceptance frameworks. * You enjoy solving complex technical challenges while collaboratively partnering to accelerate priority business initiatives on scale., Outlined below are the required minimum qualifications for this position. If none are listed, there are no minimum qualifications. Option 1: Bachelor's degree in computer science, information technology, engineering, information systems, cybersecurity, or related area and 4 years' experience in application security, or related area at a technology, retail, or data-driven company. Option 2: 6 years' experience in application security, or related area at a technology, retail, or data-driven company. Preferred Qualifications... Outlined below are the optional preferred qualifications for this position. If none are listed, there are no preferred qualifications. Certification in Security+, GISF, CISSP, CSSP, CASE, or GWEB, Master's degree in Computer Science, Information Technology, Engineering, Information Systems, Cybersecurity, or related area and 2 years' experience leading information security or cybersecurity projects, We value candidates with a background in creating inclusive digital experiences, demonstrating knowledge in implementing Web Content Accessibility Guidelines (WCAG) 2.2 AA standards, assistive technologies, and integrating digital accessibility seamlessly. The ideal candidate would have knowledge of accessibility best practices and join us as we continue to create accessible products and services following Walmart's accessibility standards and guidelines for supporting an inclusive culture. ## Description * Leverage your proven experience, passion, and enthusiasm partnering with technology and business stakeholders to integrate security early in the product lifecycle. * Define and govern secure architecture patterns, configuration standards, and enterprise control logic to ensure consistent and scalable security validation across applications. * Develop deep knowledge of products and platforms to define secure-by-default implementation guidance. * Design and validate automated control logic that produces defensible, risk-aligned validation outcomes. * Display strong expertise in threat modeling, penetration/security testing, and code reviews, and collaboratively partner to accelerate priority business initiatives. * Evaluate and operationalize SAST, SCA, and related security tooling outputs to ensure accurate risk detection and reduce misconfiguration exposure. * Serve as a trusted partner for technology and business stakeholders by securely enabling business initiatives through architecture and configuration reviews. * Map security controls to applicable compliance frameworks and ensure validation outcomes generate reliable audit evidence. * Build strong collaborative partnerships with stakeholders that securely accelerate speed to market for the business. * Provide secure design, development, implementation, sustainment, and governance expertise across the application lifecycle. * Effectively document product security standards, validation logic, and governance decisions. * Develop and evolve metrics to measure the efficacy, accuracy, and coverage of automated product security controls. * Mentor and share knowledge with stakeholders and peers to advance secure engineering maturity. * Continually exercise effective communication, writing, and presentation skills., * Supporting Fortune 1's priority business and technology initiatives through scalable, automated security governance * Reducing manual and inconsistent security review processes by embedding secure standards and validation logic directly into engineering workflows * Collaborating and delivering global solutions that enable our customers to Save Money and Live Better ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How Developers Can Focus on Maintaining Satisfaction With Accessibility](https://www.wearedevelopers.com/magazine/109-how-developers-can-focus-on-maintaining-satisfaction-with-accessibility) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)