Welcome to Our World Weve been leading the charge in the affiliate industry from day oneestablishing performance marketing and paving the way for future innovations. Were known for maintaining one of the largest most reliable partnership platforms with impeccable personalized service.
Founded in Santa Barbara California in 1998 CJ (formerly Commission Junction) stands as the most trusted name in performance marketing. We specialize in building partnerships between top brands and reputable publishers to drive revenue and business growth. CJs industry-leading solutions make us the platform of choice for over 3800 global brands across sectors like retail travel finance technology and home services. As part of Publicis Groupe our savvy data capabilities cutting-edge tech and strategic expertise facilitate genuine connections allowing brands to reach consumers wherever they are.
A Quick Peek at Affiliate Marketing Think back to your last online purchase. Did an influencer tip you off about a great product and offer a discount Or perhaps you relied on a trusted review site to make your decision Whatever path you took affiliate publishers likely played a role by influencing informing or helping you find the best deal. CJ connects brands with these publishers creating valuable resources for shoppers like you.
Job Description
As a Software Engineer 3 focused on security within Engineering Experience (EngExp) you help drive the teams evolution from DevOps to DevSecOps. You work with engineering teams across the org to find prioritize and close out vulnerabilities in CJs code and infrastructure and you help serve as a technical bridge between engineering and the Global Security Office (GSO) auditors and clients on security topics. You turn raw findings (Wiz Veracode pentest reports) into evidence-backed actionable guidance. This is a hands-on role: you read and write code and when you have the context to fix a vulnerability yourself you do - not just file a ticket and hand it off.
Responsibilities
What Youll Do:
Triage and respond to vulnerabilities identified through tools such as Wiz Veracode and penetration tests and help drive them to resolution
Analyze infrastructure and codebases to produce evidence-backed answers about real risk - exploitability reachability and impact - rather than relaying scanner severity alone
Help operate the vulnerability queue end to end: intake prioritization tracking and validation of fixes
Partner with engineers to articulate the actual threat (or lack of one) behind a code or infrastructure finding
Remediate findings directly when you have the context - whether in EngExps own infrastructure or another teams - and drive remediation through partnership where you dont
Integrate security checks (SAST/DAST) into GitLab CI/CD pipelines so issues are caught at build and merge-request time not only in point-in-time scans
Contribute to security standards and best practices and coach teams through adopting them
Help verify AI-proposed fixes and risk assessments against the actual code config and runtime context before theyre accepted
Technologies We Use:
Application security tools: Veracode Wiz
SAST/DAST tooling embedded in CI/CD
Vulnerability management and ticketing systems (Jira or equivalent)
Cloud environments: AWS Kubernetes
Infrastructure as Code: Terraform and Kubernetes manifests
CI/CD pipelines and developer platforms (GitLab CI/CD ArgoCD)
Programming languages: comfortable reading and fixing code in at least one of Python Go or the JVM languages (Java Scala Kotlin) - CJs codebases span all of these
Engineering Practices We Employ:
Agile software development
Infrastructure as Code (IaC)
Pair programming
Test-Driven Development (TDD)
Continuous Delivery
Qualifications
What We Look For:
3 years of software or infrastructure engineering experience with hands-on exposure to application or infrastructure security
Bachelors degree or equivalent experience
Can read code and infrastructure config not just interpret scanner output
Understands common vulnerability classes and how to reason about exploitability and impact
Enough AWS/Kubernetes fluency to have credible technical conversations with the teams that operate them
Comfortable translating technical findings for non-security stakeholders and driving fixes through influence rather than authority
Nice to Have:
Experience wiring automated security scanning into CI/CD pipelines
Familiarity with threat modeling and secure-by-design review
Interest in emerging threats including AI systems and willingness to learn fast
What Success Looks Like:
Engineering teams understand why a finding matters (or doesnt) instead of closing tickets to clear a queue
Audits and client security reviews go smoothly because evidence and answers are ready not scrambled together
Security becomes a normal part of how teams build not a gate bolted on at the end
Find out more: Information
This is a hybrid role requiring 3 days a week in office.
CJ is the leader in Performance Marketing. We take pride in our innovative technology comprehensive data solutions and our people. We equip our teams with advanced tools training and career development opportunities all to provide modern solutions strategies and support to deliver high quality results for our clients. We work in an enthusiastic collaborative team setting that values outstanding performance.
Were a community of creative and passionate problem solvers who go the distance to tackle the tough questions think creatively and drive resourceful growth for our clientsand ourselves. We foster and embody an inclusive and collaborative culture where diverse perspectives are sought relationships are valued and people feel accepted with a sense of belonging in expressing themselves authentically. We pride ourselves in having a workplace environment that values both work and play.
Why Our Workplace Stands Out Apart from offering competitive salaries 401K matching wellness programs and comprehensive medical dental and vision coverage we provide: Flexible time off without the hassle of accrual A generous number of paid holidays Company-sponsored team-building events An Employee Referral Program Annual recognition awards Hybrid work arrangements for optimal work-life balance Parental bonding leave Backup care options for children and elders An employee discount program International SOS program for global support Business Resource Groups where employees connect over shared interests to cultivate an engaging inclusive environment
and those are just a few of our great perks! Come join us and see what makes our company a great place to work.
If you require accommodation or assistance with the application or onboarding process specifically please contact
All your information will be kept confidential according to EEO guidelines.
#LI-DT1
Compensation Range: USD $87210.00 - USD $125265.00/Annually. This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law compensation will be determined based on the skills qualifications and experience of the applicant along with the requirements of the position and the Company reserves the right to modify this pay range at any time. Temporary roles may be eligible to participate in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been met. Temporary roles may also qualify for participation in our 401(k) plan after eligibility criteria have been met. For regular roles the Company will offer medical coverage dental vision disability 401k and paid time off. The Company anticipates the application deadline for this job posting will be 8/28/2026.
Required Experience:
IC
Company DescriptionWelcome to Our WorldWeve been leading the charge in the affiliate industry from day oneestablishing performance marketing and paving the way for future innovations. Were known for maintaining one of the largest most reliable partnership platforms with impeccable personalized servi...
Company Description
Welcome to Our World Weve been leading the charge in the affiliate industry from day oneestablishing performance marketing and paving the way for future innovations. Were known for maintaining one of the largest most reliable partnership platforms with impeccable personalized service.
Founded in Santa Barbara California in 1998 CJ (formerly Commission Junction) stands as the most trusted name in performance marketing. We specialize in building partnerships between top brands and reputable publishers to drive revenue and business growth. CJs industry-leading solutions make us the platform of choice for over 3800 global brands across sectors like retail travel finance technology and home services. As part of Publicis Groupe our savvy data capabilities cutting-edge tech and strategic expertise facilitate genuine connections allowing brands to reach consumers wherever they are.
A Quick Peek at Affiliate Marketing Think back to your last online purchase. Did an influencer tip you off about a great product and offer a discount Or perhaps you relied on a trusted review site to make your decision Whatever path you took affiliate publishers likely played a role by influencing informing or helping you find the best deal. CJ connects brands with these publishers creating valuable resources for shoppers like you.
Job Description
As a Software Engineer 3 focused on security within Engineering Experience (EngExp) you help drive the teams evolution from DevOps to DevSecOps. You work with engineering teams across the org to find prioritize and close out vulnerabilities in CJs code and infrastructure and you help serve as a technical bridge between engineering and the Global Security Office (GSO) auditors and clients on security topics. You turn raw findings (Wiz Veracode pentest reports) into evidence-backed actionable guidance. This is a hands-on role: you read and write code and when you have the context to fix a vulnerability yourself you do - not just file a ticket and hand it off.
Responsibilities
What Youll Do:
Triage and respond to vulnerabilities identified through tools such as Wiz Veracode and penetration tests and help drive them to resolution
Analyze infrastructure and codebases to produce evidence-backed answers about real risk - exploitability reachability and impact - rather than relaying scanner severity alone
Help operate the vulnerability queue end to end: intake prioritization tracking and validation of fixes
Partner with engineers to articulate the actual threat (or lack of one) behind a code or infrastructure finding
Remediate findings directly when you have the context - whether in EngExps own infrastructure or another teams - and drive remediation through partnership where you dont
Integrate security checks (SAST/DAST) into GitLab CI/CD pipelines so issues are caught at build and merge-request time not only in point-in-time scans
Contribute to security standards and best practices and coach teams through adopting them
Help verify AI-proposed fixes and risk assessments against the actual code config and runtime context before theyre accepted
Technologies We Use:
Application security tools: Veracode Wiz
SAST/DAST tooling embedded in CI/CD
Vulnerability management and ticketing systems (Jira or equivalent)
Cloud environments: AWS Kubernetes
Infrastructure as Code: Terraform and Kubernetes manifests
CI/CD pipelines and developer platforms (GitLab CI/CD ArgoCD)
Programming languages: comfortable reading and fixing code in at least one of Python Go or the JVM languages (Java Scala Kotlin) - CJs codebases span all of these
Engineering Practices We Employ:
Agile software development
Infrastructure as Code (IaC)
Pair programming
Test-Driven Development (TDD)
Continuous Delivery
Qualifications
What We Look For:
3 years of software or infrastructure engineering experience with hands-on exposure to application or infrastructure security
Bachelors degree or equivalent experience
Can read code and infrastructure config not just interpret scanner output
Understands common vulnerability classes and how to reason about exploitability and impact
Enough AWS/Kubernetes fluency to have credible technical conversations with the teams that operate them
Comfortable translating technical findings for non-security stakeholders and driving fixes through influence rather than authority
Nice to Have:
Experience wiring automated security scanning into CI/CD pipelines
Familiarity with threat modeling and secure-by-design review
Interest in emerging threats including AI systems and willingness to learn fast
What Success Looks Like:
Engineering teams understand why a finding matters (or doesnt) instead of closing tickets to clear a queue
Audits and client security reviews go smoothly because evidence and answers are ready not scrambled together
Security becomes a normal part of how teams build not a gate bolted on at the end
Find out more: Information
This is a hybrid role requiring 3 days a week in office.
CJ is the leader in Performance Marketing. We take pride in our innovative technology comprehensive data solutions and our people. We equip our teams with advanced tools training and career development opportunities all to provide modern solutions strategies and support to deliver high quality results for our clients. We work in an enthusiastic collaborative team setting that values outstanding performance.
Were a community of creative and passionate problem solvers who go the distance to tackle the tough questions think creatively and drive resourceful growth for our clientsand ourselves. We foster and embody an inclusive and collaborative culture where diverse perspectives are sought relationships are valued and people feel accepted with a sense of belonging in expressing themselves authentically. We pride ourselves in having a workplace environment that values both work and play.
Why Our Workplace Stands Out Apart from offering competitive salaries 401K matching wellness programs and comprehensive medical dental and vision coverage we provide: Flexible time off without the hassle of accrual A generous number of paid holidays Company-sponsored team-building events An Employee Referral Program Annual recognition awards Hybrid work arrangements for optimal work-life balance Parental bonding leave Backup care options for children and elders An employee discount program International SOS program for global support Business Resource Groups where employees connect over shared interests to cultivate an engaging inclusive environment
and those are just a few of our great perks! Come join us and see what makes our company a great place to work.
If you require accommodation or assistance with the application or onboarding process specifically please contact
All your information will be kept confidential according to EEO guidelines.
#LI-DT1
Compensation Range: USD $87210.00 - USD $125265.00/Annually. This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law compensation will be determined based on the skills qualifications and experience of the applicant along with the requirements of the position and the Company reserves the right to modify this pay range at any time. Temporary roles may be eligible to participate in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been met. Temporary roles may also qualify for participation in our 401(k) plan after eligibility criteria have been met. For regular roles the Company will offer medical coverage dental vision disability 401k and paid time off. The Company anticipates the application deadline for this job posting will be 8/28/2026.
Publicis Media is one of the four solutions hubs of Publicis Groupe ([Euronext Paris FR0000130577, CAC 40], alongside Publicis Communications, Publicis.Sapient and Publicis Healthcare. Led by Steve King, CEO, Publicis Media is powered by its five global brands, Starcom, Zenith, Spark
... View more