> Markdown version of [/jobs/ext/2144571-staff-application-security-engineer-product](https://www.wearedevelopers.com/jobs/ext/2144571-staff-application-security-engineer-product). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff, Application Security Engineer - Product... - **Company:** Wal-Mart Stores, Inc. - **Location:** Bentonville, AR, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Web Accessibility, Application Lifecycle Management, Code Review, Cyber Security, Information Systems, Databases, Data Validation, Data Security, Information Systems Security Architecture Professional, Open Web Application Security, Secure Coding, Web Content Accessibility Guidelines, Software Security, Information Technology, Data Analytics, Static Application Security Testing - **Published:** August 20, 2026 - **Apply:** https://www.juju.com/job/00000000gnxfpf ## About the Role + You have proven experience partnering with technology and business stakeholders to integrate security early in the product lifecycle. + You have deep expertise in OWASP risks, secure coding patterns, and threat modeling, with the ability to define secure-by-default standards and clearly distinguish acceptable risk tradeoffs. + You have strong experience governing secure architecture and defining configuration baselines across enterprise environments (e.g., authorization models, database hardening, input validation frameworks). + You have demonstrated proficiency designing and validating security controls, mapping them to compliance frameworks, and producing defensible audit evidence. + You have experience operationalizing SAST and SCA tooling outputs, assessing misconfiguration risk, and minimizing false positive and false negative validation outcomes. + You have experience aligning technical security decisions with enterprise risk modeling and risk acceptance frameworks. + You enjoy solving complex technical challenges while collaboratively partnering to accelerate priority business initiatives on scale., _Outlined below are the required minimum qualifications for this position. If none are listed, there are no minimum qualifications._ Option 1: Bachelor's degree in computer science, information technology, engineering, information systems, cybersecurity, or related area and 4 years' experience in application security, or related area at a technology, retail, or data-driven company. Option 2: 6 years' experience in application security, or related area at a technology, retail, or data-driven company. Preferred Qualifications... _Outlined below are the optional preferred qualifications for this position. If none are listed, there are no preferred qualifications._ Certification in Security+, GISF, CISSP, CSSP, CASE, or GWEB, Master's degree in Computer Science, Information Technology, Engineering, Information Systems, Cybersecurity, or related area and 2 years' experience leading information security or cybersecurity projects, We value candidates with a background in creating inclusive digital experiences, demonstrating knowledge in implementing Web Content Accessibility Guidelines (WCAG) 2.2 AA standards, assistive technologies, and integrating digital accessibility seamlessly. The ideal candidate would have knowledge of accessibility best practices and join us as we continue to create accessible products and services following Walmart's accessibility standards and guidelines for supporting an inclusive culture. ## Description The Information Security team has the herculean task of assuring that customers can safely shop with peace of mind knowing their data and information will be safe and secure. Solving some of the most unique cybersecurity problems in the industry, our team members share an elevated level of creativity and ingenuity to secure data for the largest retail operation in the world. As part of Product Security, this role plays a critical part in advancing security automation and governance capabilities embedded directly into developer workflows. You will help define, validate, and govern secure architecture, configuration standards, and enterprise control logic across Walmart's application ecosystem-ensuring automated validation decisions are defensible, risk-aligned, scalable, and audit-ready. What you'll do... + Leverage your proven experience, passion, and enthusiasm partnering with technology and business stakeholders to integrate security early in the product lifecycle. + Define and govern secure architecture patterns, configuration standards, and enterprise control logic to ensure consistent and scalable security validation across applications. + Develop deep knowledge of products and platforms to define secure-by-default implementation guidance. + Design and validate automated control logic that produces defensible, risk-aligned validation outcomes. + Display strong expertise in threat modeling, penetration/security testing, and code reviews, and collaboratively partner to accelerate priority business initiatives. + Evaluate and operationalize SAST, SCA, and related security tooling outputs to ensure accurate risk detection and reduce misconfiguration exposure. + Serve as a trusted partner for technology and business stakeholders by securely enabling business initiatives through architecture and configuration reviews. + Map security controls to applicable compliance frameworks and ensure validation outcomes generate reliable audit evidence. + Build strong collaborative partnerships with stakeholders that securely accelerate speed to market for the business. + Provide secure design, development, implementation, sustainment, and governance expertise across the application lifecycle. + Effectively document product security standards, validation logic, and governance decisions. + Develop and evolve metrics to measure the efficacy, accuracy, and coverage of automated product security controls. + Mentor and share knowledge with stakeholders and peers to advance secure engineering maturity. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How Developers Can Focus on Maintaining Satisfaction With Accessibility](https://www.wearedevelopers.com/magazine/109-how-developers-can-focus-on-maintaining-satisfaction-with-accessibility) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)