Staff, Application Security Engineer - Product Security

Walmart Walmart · Retail · Bentonville, AR +1

Staff Application Security Engineer focused on integrating security automation and governance into developer workflows. The role involves defining and validating secure architecture, configuration standards, and enterprise control logic to ensure scalable and audit-ready security validation across applications. Responsibilities include threat modeling, penetration testing, evaluating security tooling, and mapping controls to compliance frameworks.

What you'd actually do

  1. Leverage your proven experience, passion, and enthusiasm partnering with technology and business stakeholders to integrate security early in the product lifecycle.
  2. Define and govern secure architecture patterns, configuration standards, and enterprise control logic to ensure consistent and scalable security validation across applications.
  3. Design and validate automated control logic that produces defensible, risk-aligned validation outcomes.
  4. Evaluate and operationalize SAST, SCA, and related security tooling outputs to ensure accurate risk detection and reduce misconfiguration exposure.
  5. Map security controls to applicable compliance frameworks and ensure validation outcomes generate reliable audit evidence.

Skills

Required

  • Application Security
  • Security Automation
  • Security Governance
  • Secure Architecture
  • Threat Modeling
  • Penetration Testing
  • SAST
  • SCA
  • Compliance Frameworks
  • Risk Management

Nice to have

  • OWASP risks
  • secure coding patterns
  • enterprise environments
  • audit evidence
  • misconfiguration risk
  • false positive/negative reduction

What the JD emphasized

  • proven experience partnering with technology and business stakeholders to integrate security early in the product lifecycle
  • deep expertise in OWASP risks, secure coding patterns, and threat modeling
  • strong experience governing secure architecture and defining configuration baselines across enterprise environments
  • demonstrated proficiency designing and validating security controls, mapping them to compliance frameworks, and producing defensible audit evidence
  • experience operationalizing SAST and SCA tooling outputs, assessing misconfiguration risk, and minimizing false positive and false negative validation outcomes