Staff SW Systems Engineer – GovRamp & FedRamp Compliance - 10396
Summary
Lead security scanning, vulnerability remediation, and compliance validation for a cloud-driven networking platform to meet GovRamp and FedRamp standards.
Staff Software Engineer – GovRamp & FedRamp Compliance
Reports To: Director of Software Systems Engineering
Location: San Jose,California
Experience : 8 to 13 Years of Experience
Hybrid role
JOB DESCRIPTION
We are seeking a highly skilled Staff Software Engineer to lead GovRamp and FedRamp compliance efforts for our Enterprise Platform (EP1). This role is critical for ensuring our platform meets stringent government compliance standards and maintains continuous compliance through proactive vulnerability management. The successful candidate will manage security scan operations, vulnerability remediation, dependency management, and compliance validation across the entire platform and underlying infrastructure.
Key Responsibilities
-
Security Scanning & Analysis
-
Execute comprehensive security scans on the entire EP1 platform and underlying infrastructure using industry-standard tools (SAST, DAST, container scanning, dependency scanning).
-
Establish and maintain regular scanning schedules to ensure continuous compliance monitoring.
-
Review and validate scan results for accuracy, filtering false positives and prioritizing genuine vulnerabilities.
-
Vulnerability Management & Remediation
-
Identify, triage, and fix open CVEs across the platform with priority based on severity and exploitability.
-
Research and implement patches and security fixes in coordination with development teams.
-
Track vulnerability remediation progress and ensure timely closure of identified issues.
-
Dependency & Library Management
-
Regularly upgrade dependencies and libraries across the EP1 platform to address known vulnerabilities.
-
Evaluate third-party components and libraries for security risks before integration.
-
Maintain a comprehensive inventory of all platform dependencies and their security status.
-
Build & Deployment Support
-
Generate and manage builds for GovRamp-related testing and validation.
-
Coordinate with QA and compliance teams to ensure builds meet GovRamp/FedRamp requirements.
-
Support pre-deployment security verification and compliance checks.
-
Compliance & Documentation
-
Maintain documentation of security findings, remediation efforts, and compliance status.
-
Generate compliance reports for internal and regulatory review.
-
Support security audit preparations and compliance assessments.
Required Qualifications
-
8 + years of software engineering experience with at least 3+ years focused on security, compliance, or vulnerability management.
-
Strong hands-on experience with security scanning tools (tenable, Snyk, or similar).
-
Demonstrated expertise in vulnerability assessment, CVE analysis, and remediation strategies.
-
Deep understanding of government compliance frameworks (GovRamp, FedRamp, or similar).
-
Proficiency in multiple programming languages (Java, Python, Go, C#, or similar).
-
Strong experience with CI/CD pipelines, build systems, and infrastructure scanning.
-
Solid understanding of container security, Kubernetes, and cloud infrastructure security.
-
Experience with dependency management tools and library upgrade processes.
-
Knowledge of common vulnerability types (OWASP Top 10, CWE) and remediation techniques.
-
Bachelor’s degree in computer science, Cybersecurity, or related field, or equivalent professional experience.
Preferred Qualifications
-
Active security certifications (CISSP, CCSK, CEH, Security+, or similar).
-
Experience with GovRamp or FedRamp compliance processes and assessments.
-
Background in DevSecOps practices and security automation.
-
Knowledge of threat modeling and attack surface analysis.
-
Experience with containerization security scanning and runtime protection.
-
Background in secure coding practices and code review for security issues.
-
Experience with API security testing and web application security.
-
Prior experience managing security programs or compliance initiatives.
Technical Skills & Competencies
Security & Compliance Tools:
-
SAST: Sonarqube, Checkmarx, Coverity, Fortify
-
DAST: OWASP ZAP, Burp Suite, Acunetix
-
Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot
-
Container Security: Trivy, Twistlock, Aqua Security
-
Infrastructure Scanning: CloudSploit, ScoutSuite, Prowler
Programming & Development:
-
Languages: Java, Python, Go, C#, JavaScript
-
Build Systems: Maven, Gradle, npm, pip, cargo
-
Version Control: Git, GitHub, GitLab
DevOps & Cloud:
-
Cloud Platforms: AWS, Azure, GCP
-
Container Technologies: Docker, Kubernetes, container registries
-
CI/CD: Jenkins, GitLab CI, GitHub Actions, Azure Pipelines
-
IaC: Terraform, CloudFormation, Ansible
Soft Skills:
-
Attention to detail and strong analytical thinking
-
Excellent written and verbal communication skills
-
Ability to work independently and manage multiple priorities
-
Proactive problem-solving and troubleshooting abilities
-
Passion for security and compliance best practices
What We Offer
-
Opportunity to drive government compliance and security initiatives for a major enterprise platform
-
Work with cutting-edge security tools and technologies
-
Collaborate with security, compliance, and engineering teams
-
Professional development support including certifications and training
-
Competitive compensation package with stock options and performance bonuses
-
Comprehensive health, wellness, and retirement benefits
-
Flexible work environment with remote options
-
Impact on government modernization through secure, compliant infrastructure
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company, Current Location - City/State/Country URL, LinkedIn URL, GitHub URL, Portfolio URL, Other website
- Please answer all of the questions so we can process your applications written answer
- Are you authorized to work lawfully in the United States for Extreme Networks, Inc.? written answer
- Do you now, or will you in the future, require sponsorship for employment visa status (for example, and not limited to: H-1B, F1, H4, L2, etc.) to work legally for Extreme Networks, Inc. in the United States? written answer
- How did you hear about this position? written answer
- What is the minimum amount of salary you require if offered this position? written answer
- Are you related to anyone at Extreme Networks? written answer
- Please list how much notice you will need to give your employer: written answer · optional
- Where will you reside if you accept an offer of employment? (City/State) written answer · optional
- What security clearance do you currently carry? written answer · optional
- US Citizen choose one · optional
- Green Card choose one · optional