Software Engineer 3, Security
About CJ Engineering
At CJ, we are passionate about software engineering. We build exciting software, with quality and maintainability in mind. We believe in common sense, simplicity, and efficiency. We practice critical thinking, challenge each other no matter the title, and believe in the wisdom of the team. That makes us Engineers and not just developers.
Here are some of the principles that set CJ engineers apart:
- Engineering autonomy: Here, business decisions are made by business people, and technical decisions are made by technical people.
- Full stack: Expect to be involved and to gain competence in every aspect of software engineering, from frontend, to database, to requirements analysis, to testing, to helping choose technologies.
- Clean, Maintainable code: Code is read more often than it is written, so we put in the effort to write it well in the first place.
- Pairing: The highest quality code is produced by close collaboration, so we pair by default.
- TDD: Quality is baked into our process through Test Driven Development.
- Ownership: Engineers own the full lifecycle of what they build—from design and implementation to deployment, monitoring, production support, and on-call rotations. If we build it, we support it.
- Operational Excellence: We embrace Infrastructure as Code, CI/CD, automation, and observability to build reliable systems and deliver software safely, efficiently, and at scale.
- We believe in Agile values, and incremental development. We constantly experiment, retrospect, and adjust.
- We are committed to finding out how AI can amplify our productivity. We view AI as a force multiplier, not a replacement for good engineering.
As a Software Engineer 3 focused on security within Engineering Experience (EngExp), you help drive the team's evolution from DevOps to DevSecOps. You work with engineering teams across the org to find, prioritize, and close out vulnerabilities in CJ's code and infrastructure, and you help serve as a technical bridge between engineering and the Global Security Office (GSO), auditors, and clients on security topics. You turn raw findings (Wiz, Veracode, pentest reports) into evidence-backed, actionable guidance. This is a hands-on role: you read and write code, and when you have the context to fix a vulnerability yourself, you do - not just file a ticket and hand it off.
Responsibilities
- Triage and respond to vulnerabilities identified through tools such as Wiz, Veracode, and penetration tests, and help drive them to resolution
- Analyze infrastructure and codebases to produce evidence-backed answers about real risk - exploitability, reachability, and impact - rather than relaying scanner severity alone
- Help operate the vulnerability queue end to end: intake, prioritization, tracking, and validation of fixes
- Partner with engineers to articulate the actual threat (or lack of one) behind a code or infrastructure finding
- Remediate findings directly when you have the context - whether in EngExp's own infrastructure or another team's - and drive remediation through partnership where you don't
- Integrate security checks (SAST/DAST) into GitLab CI/CD pipelines so issues are caught at build and merge-request time, not only in point-in-time scans
- Contribute to security standards and best practices, and coach teams through adopting them
- Help verify AI-proposed fixes and risk assessments against the actual code, config, and runtime context before they're accepted
Technologies We Use
- Application security tools: Veracode, Wiz
- SAST/DAST tooling embedded in CI/CD
- Vulnerability management and ticketing systems (Jira or equivalent)
- Cloud environments: AWS, Kubernetes
- Infrastructure as Code: Terraform and Kubernetes manifests
- CI/CD pipelines and developer platforms (GitLab CI/CD, ArgoCD)
- Programming languages: comfortable reading and fixing code in at least one of Python, Go, or the JVM languages (Java, Scala, Kotlin) - CJ's codebases span all of these
Qualifications
- 3+ years of software or infrastructure engineering experience, with hands-on exposure to application or infrastructure security
- Bachelor's degree or equivalent experience
- Can read code and infrastructure config, not just interpret scanner output
- Understands common vulnerability classes and how to reason about exploitability and impact
- Enough AWS/Kubernetes fluency to have credible technical conversations with the teams that operate them
- Comfortable translating technical findings for non-security stakeholders and driving fixes through influence rather than authority
Nice To Have
- Experience wiring automated security scanning into CI/CD pipelines
- Familiarity with threat modeling and secure-by-design review
- Interest in emerging threats, including AI systems, and willingness to learn fast
What Success Looks Like
- Engineering teams understand why a finding matters (or doesn't) instead of closing tickets to clear a queue
- Audits and client security reviews go smoothly because evidence and answers are ready, not scrambled together
- Security becomes a normal part of how teams build, not a gate bolted on at the end
Pay
USD $88,540.00 - USD $135,632.00/Annually. Consistent with applicable law, compensation will be determined based on the skills, qualifications, and experience of the applicant along with the requirements of the position.
Schedule
This is a hybrid role requiring 3 days a week in a CJ office location.
Benefits
- Competitive salaries
- 401K matching
- Wellness programs
- Comprehensive medical, dental, and vision coverage
- Flexible time off without the hassle of accrual
- Generous number of paid holidays
- Company-sponsored team-building events
- Employee Referral Program
- Annual recognition awards
- Hybrid work arrangements for optimal work-life balance
- Parental bonding leave
- Backup care options for children and elders
- Employee discount program
- International SOS program for global support
- Business Resource Groups, where employees connect over shared interests to cultivate an engaging, inclusive environment