Staff, Software Engineer, Information Security

Walmart Walmart · Retail · Bentonville, AR +1

Staff Software Engineer focused on information security, designing and building secure, resilient services and AI-driven workflows for enterprise security automation and compliance. The role involves architecting secure APIs, backend systems, and integrations, developing telemetry pipelines, and incorporating AI-driven workflows with safeguards for secure coding and compliance validation.

What you'd actually do

  1. Architect, design and operate secure APIs along with frameworks for service-to-service or Agentic communications.
  2. Architect scalable, highly available backend systems that process and validate security measures and control data.
  3. Build resilient integrations across security tooling ecosystems (scanners, CI/CD, internal APIs).
  4. Develop telemetry pipelines that helps preserve audit integrity and traceability.
  5. Build APIs and aggregate data originating from telemetry signals and sensors, in a scalable backend database

Skills

Required

  • Java or Python
  • MVC and async frameworks
  • SQL (Azure SQL, PostgreSQL)
  • NSQL technologies (Cassandra or MongoDB)
  • Containerization of applications and services
  • microservices
  • REST APIs
  • resilient and at scale services
  • threat modeling
  • secure data handling principles
  • CI/CD pipelines
  • container orchestration platforms like Kubernetes
  • information security domains
  • application security
  • static security scanning
  • Software composition analysis
  • vulnerabilities
  • threats
  • exploits

Nice to have

  • triaging and fixing bugs in a microservice, n tier architecture and in big data platforms
  • creating Agents, MCP servers, APIs, and infrastructure components
  • big data technologies such as Big Query, Kafka, Apache Spark, Elastic Search and Data Streaming
  • creating frameworks, components and reusable assets
  • multi region deployments, HA, autoscaling, blue green deployments, secure SDLC for products and services, performance measures at every tier, data security and access control measures
  • Agentic IDEs like Cursor or Windsurf
  • architecting, designing Agents and building MCP servers
  • agentic validation for security controls presence
  • integrating with various security tools such as SAST, ASPM, and container scanners

What the JD emphasized

  • AI-driven workflows
  • Agentic communications
  • security automation
  • compliance validations
  • secure coding
  • secure data handling
  • Agentic IDEs
  • security controls presence
  • security guardrails

Other signals

  • AI-driven workflows
  • Agentic communications
  • security automation
  • compliance validations