Software Engineering 3, Security
CJ · Chicago, IL · 1 wk ago
HybridEngineering$87k/yrFull-time
About the role
A Software Engineer 3 focused on security within Engineering Experience (EngExp), you help drive the team's evolution from DevOps to DevSecOps. You work with engineering teams across the org to find, prioritize, and close out vulnerabilities in CJ's code and infrastructure, and you help serve as a technical bridge between engineering and the Global Security Office (GSO), auditors, and clients on security topics.
Responsibilities
- Triage and respond to vulnerabilities identified through tools such as Wiz, Veracode, and penetration tests, and help drive them to resolution
- Analyze infrastructure and codebases to produce evidence-backed answers about real risk - exploitability, reachability, and impact - rather than relaying scanner severity alone
- Operate the vulnerability queue end to end: intake, prioritization, tracking, and validation of fixes
- Partner with engineers to articulate the actual threat (or lack of one) behind a code or infrastructure finding
- Remediate findings directly when you have the context - whether in EngExp's own infrastructure or another team's - and drive remediation through partnership where you don't
- Integrate security checks (SAST/DAST) into GitLab CI/CD pipelines so issues are caught at build and merge-request time, not only in point-in-time scans
- Contribute to security standards and best practices, and coach teams through adopting them
- Help verify AI-proposed fixes and risk assessments against the actual code, config, and runtime context before they're accepted
Qualifications
- 3+ years of software or infrastructure engineering experience, with hands-on exposure to application or infrastructure security
- Bachelor's degree or equivalent experience
- Can read code and infrastructure config, not just interpret scanner output
- Understands common vulnerability classes and how to reason about exploitability and impact
- Enough AWS/Kubernetes fluency to have credible technical conversations with the teams that operate them
- Comfortable translating technical findings for non-security stakeholders and driving fixes through influence rather than authority
Nice to have
- Experience wiring automated security scanning into CI/CD pipelines
- Familiarity with threat modeling and secure-by-design review
- Interest in emerging threats, including AI systems, and willingness to learn fast
What Success Looks Like
Engineering teams understand why a finding matters (or doesn't) instead of closing tickets to clear a queue
Audits and client security reviews go smoothly because evidence and answers are ready, not scrambled together
Security becomes a normal part of how teams build, not a gate bolted on at the end