Senior Incident Response Engineer; Purple Team
Listed on 2026-02-21
-
IT/Tech
Cybersecurity
Position Summary
The Senior Incident Response Engineer (Purple Team) will operate within a purple‑team driven program, focused on assumed‑breach and post‑access adversary activity to strengthen detection and response capabilities. This role leads threat‑actor driven campaigns that measure real‑world defensive effectiveness and drive continuous improvement across production environments. Working closely with SOC, Detection Engineering, and risk stakeholders, the engineer translates campaign outcomes into actionable enhancements, validates remediation through retesting, and helps mature response processes.
The role also collaborates with peers and advances scalable, measurable security practices aligned with organizational and industry standards.
About the team
At Walmart, we believe it is essential to keep innovating while safeguarding our data. Our team ensures that Walmart maintains a secure operating environment and the trust of our customers, associates, and stakeholders. We bring together a variety of services and capabilities to help prevent fraud, detect threats, and manage digital risk and access. In addition to mitigating attack risk, we foster in our team members a secure and reliable working ethics.
The RAMPART team delivers assumed‑breach, post‑access adversary emulation through short, repeatable campaigns that drive measurable improvement. RAMPART partners with defensive teams and business stakeholders to strengthen detection, containment, and resilience.
What you’ll do
- Execute a variety of campaigns (assume breach, fraud, Adversarial AI, Atomic, transparent / collaborative)
- Develop, curate, and leverage offensive security TTPs and threat intelligence
- Manage and configure campaign infrastructure
- Provide ongoing consulting to defense teams as they design and implement responses to campaign findings
What you’ll bring
- Knowledge of fundamental computing concepts – flexibility to learn and adapt to new languages, systems, and technologies.
- A collaborative approach to campaign preparation, execution and debriefing; professional and empathetic communication.
- An understanding of AI technologies.
- Proficiency in vulnerability assessment, penetration testing, and threat modeling to identify and remediate security weaknesses.
- Experience managing stakeholder engagement and communicating technical findings effectively.
At Walmart, we offer competitive pay as well as performance‑based bonus awards and other great benefits for a happier mind, body, and wallet. Health benefits include medical, vision and dental coverage. Financial benefits include 401(k), stock purchase and company‑paid life insurance. Paid time off benefits include PTO (including sick leave), parental leave, family care leave, bereavement, jury duty, and voting. Other benefits include short‑term and long‑term disability, company discounts, Military Leave Pay, adoption and surrogacy expense reimbursement, and more.
You will also receive PTO and/or PPTO that can be used for vacation, sick leave, holidays, or other purposes. The amount you receive depends on your job classification and length of employment. It will meet or exceed the requirements of paid sick leave laws, where applicable. For information about PTO, see Live Better U is a Walmart‑paid education benefit program for full‑time and part‑time associates in Walmart and Sam’s Club facilities.
Programs range from high school completion to bachelor’s degrees, including English Language Learning and short‑form certificates. Tuition, books, and fees are completely paid for by Walmart.
Option 1:
Bachelor's degree in computer science, information technology, engineering, information systems, cybersecurity, or related area and 3 years’ experience in incident response or related area at a technology, retail, or data‑driven company.
Option 2: 5 years’ experience in incident response or related area at a technology, retail, or data‑driven company.
Preferred QualificationsCertifications in Security+, Network+, GISF, GSEC, CISSP, CCSP, or GCIH;
Master’s degree in Computer Science, Information Technology, Engineering, Information Systems, Cybersecurity, or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).