Staff, Software Engineer, Information Security

Walmart Walmart · Retail · Dallas, TX

Staff Software Engineer, Information Security at Walmart, focusing on open-source license compliance, security automation, and vulnerability management for embedded software platforms. Requires strong C/C++ and Python skills, with experience in DevSecOps, AppSec, or Compliance roles.

What you'd actually do

  1. Lead open-source compliance & security: Evaluate proposed libraries (GPL/MPL/MIT/Apache), document obligations, and guide compliant implementation across embedded platforms.
  2. Drive vulnerability management: Integrate and triage results from SAST/DAST/SCA scanners (CodeQL, SonarQube) and oversee remediation across firmware and supporting services.
  3. Automate DevSecOps pipelines: Design and enforce CI/CD security gates, automate audits, and produce software bill of materials (SBOMs) using GitHub/GitLab.
  4. Govern build engineering & artifacts: Standardize reproducible builds (CMake, Clang/LLVM) and manage dependency health checks via JFrog Artifactory/Xray.
  5. Conduct risk assessments: Identify threats, recommend mitigating controls, and champion security best practices through documentation and developer training.

Skills

Required

  • 8+ years in embedded software development (Linux kernel, device/firmware)
  • 2+ years in a security-focused role (DevSecOps/AppSec/Compliance)
  • Strong in C and C++
  • Proficiency in Python or JavaScript for automation and tooling
  • Deep, practical familiarity with open-source licenses (GPL/LGPL/MPL/Apache)
  • SBOM tooling (SPDX/CycloneDX)
  • Hands-on experience with modern CI/CD practices
  • CMake
  • cross-compilers
  • artifact governance
  • Skilled at interpreting and acting upon SAST/DAST/IAST security scan results

Nice to have

  • Security certifications like CISSP/CSSLP are a plus

What the JD emphasized

  • Immigration sponsorship is not available for this role
  • This is a full-time, onsite role at our Dallas, TX office.
  • This position is not eligible for remote work.