Security-Focused Software Engineer (DevSecOps)

Socket.dev

Agoura Hills (CA)

Hybrid

USD 88,540 - 135,632

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CJ is seeking a Software Engineer 3 focused on security within Engineering Experience. You’ll drive the team’s evolution from DevOps to DevSecOps, triage vulnerabilities from Wiz, Veracode, and pen tests, and act as a technical bridge between engineering, the Global Security Office, auditors and clients.

This is a hands-on role: you read and fix code, embed security checks into GitLab CI/CD, and contribute to security standards.

Qualifications

  • 3+ years of software or infrastructure engineering experience, with hands-on exposure to application or infrastructure security
  • Bachelor's degree or equivalent experience
  • Can read code and infrastructure config, not just interpret scanner output
  • Understands common vulnerability classes and how to reason about exploitability and impact
  • Enough AWS/Kubernetes fluency to have credible technical conversations with the teams that operate them
  • Comfortable translating technical findings for non-security stakeholders and driving fixes through influence rather than authority

Responsibilities

  • Triage and respond to vulnerabilities identified through tools such as Wiz, Veracode, and penetration tests, and help drive them to resolution
  • Analyze infrastructure and codebases to produce evidence-backed answers about real risk - exploitability, reachability, and impact - rather than relaying scanner severity alone
  • Help operate the vulnerability queue end to end: intake, prioritization, tracking, and validation of fixes
  • Partner with engineers to articulate the actual threat (or lack of one) behind a code or infrastructure finding
  • Remediate findings directly when you have the context - whether in EngExp's own infrastructure or another team's - and drive remediation through partnership where you don't
  • Integrate security checks (SAST/DAST) into GitLab CI/CD pipelines so issues are caught at build and merge-request time, not only in point-in-time scans
  • Contribute to security standards and best practices, and coach teams through adopting them
  • Help verify AI-proposed fixes and risk assessments against the actual code, config, and runtime context before they're accepted

Skills

Security experience
Code reading ability
AWS/Kubernetes fluency

Education

Bachelor's degree or equivalent

Tools

AWS
Kubernetes
Terraform
GitLab CI/CD

Job description

CJ is seeking a Software Engineer 3 focused on security within Engineering Experience. You’ll drive the team’s evolution from DevOps to DevSecOps, triage vulnerabilities from Wiz, Veracode, and pen tests, and act as a technical bridge between engineering, the Global Security Office, auditors and clients.

This is a hands-on role: you read and fix code, embed security checks into GitLab CI/CD, and contribute to security standards.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security-Focused Software Engineer 3 (DevSecOps)
Security-Focused Software Engineer 3 (DevSecOps)

CJ • Atlanta (GA)

Hybrid
USD 89,000 - 136,000
401K matching
Medical, dental, vision coverage
Flexible time off
+3
Software Engineer 3: DevSecOps Security (Hybrid)
Software Engineer 3: DevSecOps Security (Hybrid)

Commission Junction LLC • Agoura Hills (CA)

Hybrid
USD 89,000 - 136,000
Hybrid work arrangements
Flexible time off
Paid holidays
+3
Senior Software Engineer - Security & DevSecOps (Hybrid)
Senior Software Engineer - Security & DevSecOps (Hybrid)

UNAVAILABLE • Simi Hills (CA)

Hybrid
USD 87,210 - 125,265
401K matching
Medical, dental, vision coverage
Hybrid work arrangements
+2
Software Engineer 3 - Hybrid Security & DevSecOps
Software Engineer 3 - Hybrid Security & DevSecOps

CJ • Needham (MA)

Hybrid
USD 89,000 - 136,000
401K matching
Hybrid work arrangements
Paid holidays
+1
Software Engineer 3 - Security & DevSecOps (Hybrid)
Software Engineer 3 - Security & DevSecOps (Hybrid)

CJ • Chicago (IL)

Hybrid
USD 89,000 - 136,000
Hybrid work arrangements
Flexible time off
Paid holidays
+4
Security‑Focused Software Engineer 3 (Hybrid)
Security‑Focused Software Engineer 3 (Hybrid)

CJ • Agoura Hills (CA)

Hybrid
USD 88,000 - 136,000
Flexible time off
Paid holidays
Team-building events
+8
DevSecOps Engineer – Information Security
DevSecOps Engineer – Information Security

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 170,000
Security Software Engineer
Security Software Engineer

Eccalon, LLC • Hanover (MD)

On-site
USD 110,000 - 140,000
DevSecOps Engineer
DevSecOps Engineer

myBridge Corporation • Denver (CO)

On-site
USD 90,000 - 120,000