(usa) Staff, Software Engineer, Information Security

Walmart Walmart · Retail · Bentonville, AR

Staff Software Engineer for Walmart's Identity and Access Management (IAM) organization, focusing on Phishing-Resistant MFA (PR-MFA) and certificate-based authentication (CBA). The role involves designing and building scalable and secure enterprise authentication solutions, including registration, lifecycle management, and rollout automation, with a focus on integrating MFA into various platforms and supporting hardware authenticator enrollment.

What you'd actually do

  1. Build and maintain services supporting MFA, PR-MFA, and CBA
  2. Implement registration, recovery, and operational workflows
  3. Support PR-MFA and certificate-based rollout patterns
  4. Integrate MFA into IdP, SSO, VPN, and endpoint platforms
  5. Apply FIDO2/passkey and CBA (PKI, certificates) concepts in production systems

Skills

Required

  • software engineering experience building enterprise-grade services and APIs
  • authentication, authorization, and assurance levels
  • FIDO2 security keys/passkeys
  • Certificate-based authentication (CBA) using PIV / Smart Cards and X.509 certificates
  • Windows, macOS, iOS, and Android platforms
  • Bachelor's degree in a related field and 8+ years experience in software engineering and/or cybersecurity

Nice to have

  • risk-based or adaptive MFA concepts
  • step-up authentication flows
  • common MFA threats (phishing, MFA fatigue)
  • hardware authenticator enrollment and recovery
  • dashboards for rollout and support metrics
  • Certification in Security+, GISF, CISSP, CCSP, or GSEC
  • Master’s degree in computer science, information technology, engineering, information systems, cybersecurity or related area and 2 years’ experience leading information security or cybersecurity projects
  • creating inclusive digital experiences
  • implementing Web Content Accessibility Guidelines (WCAG) 2.2 AA standards
  • assistive technologies
  • integrating digital accessibility seamlessly

What the JD emphasized

  • Phishing-Resistant MFA
  • certificate-based authentication
  • FIDO2 security keys/passkeys
  • PIV / Smart Cards and X.509 certificates