Software Engineer 3, Security
Listed on 2026-08-03
-
Software Development
Company Description
Welcome to Our World We’ve been leading the charge in the affiliate industry from day one—establishing performance marketing and paving the way for future innovations. We're known for maintaining one of the largest, most reliable partnership platforms with impeccable, personalized service. Founded in Santa Barbara, California in 1998, CJ (formerly Commission Junction) stands as the most trusted name in performance marketing.
We specialize in building partnerships between top brands and reputable publishers to drive revenue and business growth. CJ’s industry-leading solutions make us the platform of choice for over 3,800 global brands across sectors like retail, travel, finance, technology, and home services. As part of Publicis Groupe, our savvy data capabilities, cutting-edge tech, and strategic expertise facilitate genuine connections, allowing brands to reach consumers wherever they are.
A Quick Peek at Affiliate Marketing Think back to your last online purchase. Did an influencer tip you off about a great product and offer a discount? Or perhaps you relied on a trusted review site to make your decision? Whatever path you took, affiliate publishers likely played a role by influencing, informing, or helping you find the best deal.
CJ connects brands with these publishers, creating valuable resources for shoppers like you.
As a Software Engineer 3 focused on security within Engineering Experience (Eng Exp), you help drive the team's evolution from Dev Ops to Dev Sec Ops . You work with engineering teams across the org to find, prioritize, and close out vulnerabilities in CJ's code and infrastructure, and you help serve as a technical bridge between engineering and the Global Security Office (GSO), auditors, and clients on security topics.
You turn raw findings (Wiz, Veracode, pentest reports) into evidence-backed, actionable guidance. This is a hands-on role: you read and write code, and when you have the context to fix a vulnerability yourself, you do - not just file a ticket and hand it off.
What You ll Do:
- Triage and respond to vulnerabilities identified through tools such as Wiz, Veracode, and penetration tests, and help drive them to resolution
- Analyze infrastructure and codebases to produce evidence-backed answers about real risk - exploitability, reachability, and impact - rather than relaying scanner severity alone
- Help operate the vulnerability queue end to end: intake, prioritization, tracking, and validation of fixes
- Partner with engineers to articulate the actual threat (or lack of one) behind a code or infrastructure finding
- Remediate findings directly when you have the context - whether in Eng Exp's own infrastructure or another team's - and drive remediation through partnership where you don't
- Integrate security checks (SAST/DAST) into Git Lab CI/CD pipelines so issues are caught at build and merge-request time, not only in point-in-time scans
- Contribute to security standards and best practices, and coach teams through adopting them
- Help verify AI-proposed fixes and risk assessments against the actual code, config, and runtime context before they're accepted
- Application security tools:
Veracode, Wiz - SAST/DAST tooling embedded in CI/CD
- Vulnerability management and ticketing systems (Jira or equivalent)
- Cloud environments: AWS, Kubernetes
- Infrastructure as Code:
Terraform and Kubernetes manifests - CI/CD pipelines and developer platforms (Git Lab CI/CD, ArgoCD)
- Programming languages: comfortable reading and fixing code in at least one of Python, Go, or the JVM languages (Java, Scala, Kotlin) - CJ's codebases span all of these
- 3+ years of software or infrastructure engineering experience, with hands-on exposure to application or infrastructure security
- Bachelor's degree or equivalent experience
- Can read code and infrastructure config, not just interpret scanner output
- Understands common vulnerability classes and how to reason about exploitability and impact
- Enough AWS/Kubernetes fluency to have credible technical conversations with the teams that operate them
- Comfortable translating technical findings for non-security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).