Saatchi & Saatchi

Software Engineer 3, Security

Saatchi & Saatchi$88K — $135K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of software or infrastructure engineering experience, with hands-on exposure to application or infrastructure security
  • Bachelor's degree or equivalent experience
  • Ability to read and understand code and infrastructure config, not just interpret scanner output
  • Knowledge of common vulnerability classes and assessment of exploitability and impact
  • Proficient in AWS and Kubernetes for technical discussions with teams
  • Skilled at communicating technical findings to non-security stakeholders and influencing fixes without authority

Responsibilities

  • Triage and resolve vulnerabilities from tools like Wiz, Veracode, and pentests
  • Analyze code and infrastructure for evidence-backed risk evaluation
  • Manage the full lifecycle of the vulnerability queue: intake, prioritization, tracking, and fixing
  • Collaborate with engineering teams to clarify real threats behind security findings
  • Directly remediate vulnerabilities when context is available, fostering remediation partnerships when necessary
  • Integrate SAST/DAST security checks into GitLab CI/CD to catch issues early
  • Contribute to and coach on security standards and best practices

Benefits

  • Medical coverage
  • Dental and vision insurance
  • Disability insurance
  • 401(k) plan participation
  • Paid time off
  • Temporary employee medical plan eligibility for qualifying roles
  • Potential participation in 401(k) plan for temporary roles upon meeting criteria
Full Job Description
Overview

As a Software Engineer 3 focused on security within Engineering Experience (EngExp), you help drive the team's evolution from DevOps to DevSecOps. You work with engineering teams across the org to find, prioritize, and close out vulnerabilities in CJ's code and infrastructure, and you help serve as a technical bridge between engineering and the Global Security Office (GSO), auditors, and clients on security topics. You turn raw findings (Wiz, Veracode, pentest reports) into evidence-backed, actionable guidance. This is a hands-on role: you read and write code, and when you have the context to fix a vulnerability yourself, you do - not just file a ticket and hand it off.

Responsibilities

What You'll Do:

Triage and respond to vulnerabilities identified through tools such as Wiz, Veracode, and penetration tests, and help drive them to resolution
  • Analyze infrastructure and codebases to produce evidence-backed answers about real risk - exploitability, reachability, and impact - rather than relaying scanner severity alone
  • Help operate the vulnerability queue end to end: intake, prioritization, tracking, and validation of fixes
  • Partner with engineers to articulate the actual threat (or lack of one) behind a code or infrastructure finding
  • Remediate findings directly when you have the context - whether in EngExp's own infrastructure or another team's - and drive remediation through partnership where you don't
  • Integrate security checks (SAST/DAST) into GitLab CI/CD pipelines so issues are caught at build and merge-request time, not only in point-in-time scans
  • Contribute to security standards and best practices, and coach teams through adopting them
  • Help verify AI-proposed fixes and risk assessments against the actual code, config, and runtime context before they're accepted

Technologies We Use:
  • Application security tools: Veracode, Wiz
  • SAST/DAST tooling embedded in CI/CD
  • Vulnerability management and ticketing systems (Jira or equivalent)
  • Cloud environments: AWS, Kubernetes
  • Infrastructure as Code: Terraform and Kubernetes manifests
  • CI/CD pipelines and developer platforms (GitLab CI/CD, ArgoCD)
  • Programming languages: comfortable reading and fixing code in at least one of Python, Go, or the JVM languages (Java, Scala, Kotlin) - CJ's codebases span all of these


Qualifications

  • 3+ years of software or infrastructure engineering experience, with hands-on exposure to application or infrastructure security
  • Bachelor's degree or equivalent experience
  • Can read code and infrastructure config, not just interpret scanner output
  • Understands common vulnerability classes and how to reason about exploitability and impact
  • Enough AWS/Kubernetes fluency to have credible technical conversations with the teams that operate them
  • Comfortable translating technical findings for non-security stakeholders and driving fixes through influence rather than authority

Nice to Have:
  • Experience wiring automated security scanning into CI/CD pipelines
  • Familiarity with threat modeling and secure-by-design review
  • Interest in emerging threats, including AI systems, and willingness to learn fast

What Success Looks Like:
    • Engineering teams understand why a finding matters (or doesn't) instead of closing tickets to clear a queue
    • Audits and client security reviews go smoothly because evidence and answers are ready, not scrambled together
    • Security becomes a normal part of how teams build, not a gate bolted on at the end


Additional information

This is a hybrid role requiring 3 days a week in office.

Compensation Range: USD $88,540.00 - USD $135,632.00/Annually. This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law, compensation will be determined based on the skills, qualifications, and experience of the applicant along with the requirements of the position, and the Company reserves the right to modify this pay range at any time. Temporary roles may be eligible to participate in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been met. Temporary roles may also qualify for participation in our 401(k) plan after eligibility criteria have been met. For regular roles, the Company will offer medical coverage, dental, vision, disability, 401k, and paid time off. The Company anticipates the application deadline for this job posting will be 9/27/2026.

About Saatchi & Saatchi

Saatchi & Saatchi is a global advertising agency headquartered in New York City. The company was founded in London in 1970 by brothers Maurice and Charles Saatchi and is now part of the Publicis Groupe, a French multinational advertising and public relations company. Saatchi & Saatchi has over 6,000 employees in 114 countries and provides a range of advertising and marketing services to clients in various industries, including automotive, consumer goods, financial services, and telecommunications. The company is known for its creative and innovative advertising campaigns, including the iconic 'Nothing is Impossible' campaign for Toyota. Saatchi & Saatchi has won numerous awards for its work, including Cannes Lions, Clios, and Effies.
Learn more about Saatchi & Saatchi
Size
6,000 employees
Industry

Similar Jobs

More Jobs at Saatchi & Saatchi

More Information Technology Jobs

Find similar Software Engineer 3, Security jobs: