Staff SW Systems Engineer – GovRamp & FedRamp Compliance - 10396
Listed on 2026-08-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Over 50,000 customers globally trust our end-to-end, cloud-driven networking solutions. They rely on our top-rated services and support to accelerate their digital transformation efforts and deliver unprecedented progress. With double-digit growth year over year, no provider is better positioned to deliver scalable outcomes than Extreme.
Inclusion is one of our core values and in our DNA. We are committed to fostering an inclusive workplace that embraces our differences and creates an atmosphere where all our employees thrive because of their differences, not in spite of them.
Become part of Something big with Extreme! As a global networking leader, learn why there’s no better time to join the Extreme team.
Staff Software Engineer – Gov Ramp & Fed Ramp ComplianceReports To:
Director of Software Systems Engineering
Location:
San Jose, California
Experience:
8 to 13 Years of Experience
Hybrid role
JOB DESCRIPTIONWe areseekinga highly skilled Staff Software Engineer to lead
Gov Rampand Fed Rampcompliance efforts for our Enterprise Platform (EP1). This role is critical for ensuring our platform meets stringent government compliance standards andmaintainscontinuous compliance through proactive vulnerability management. The successful candidate will manage security scan operations, vulnerability remediation, dependency management, and compliance validation across the entire platform and underlying infrastructure.
- Security Scanning & Analysis
- Execute comprehensive security scans on the entire EP1 platform and underlying infrastructure using industry-standard tools (SAST, DAST, container scanning, dependency scanning).
- Establish andmaintainregular scanning schedules to ensure continuous compliance monitoring.
- Review andvalidatescan results for accuracy, filtering falsepositivesand prioritizing genuine vulnerabilities.
- Vulnerability Management & Remediation
- Identify, triage, and fix open CVEs across the platform with priority based on severity and exploitability.
- Research and implement patches and security fixes in coordination with development teams.
- Track vulnerability remediation progress and ensuretimelyclosure ofidentifiedissues.
- Dependency & Library Management
- Regularly upgrade dependencies and libraries across the EP1 platform to address known vulnerabilities.
- Evaluate third-party components and libraries for security risks before integration.
- Maintain a comprehensive inventory of all platform dependencies and their security status.
- Build & Deployment Support
- Generate and manage builds forGovRamp-related testing and validation.
- Coordinate with QA and compliance teams to ensure builds meet
GovRamp/Fed Ramprequirements. - Support pre-deployment security verification and compliance checks.
- Compliance & Documentation
- Maintain documentation of security findings, remediation efforts, and compliance status.
- Generate compliance reports for internal and regulatory review.
- Support security audit preparations and compliance assessments.
- 8 + years of software engineering experience with at least 3+ years focused on security, compliance, or vulnerability management.
- Strong hands-on experience with security scanning tools (tenable,Snyk, or similar).
- Demonstratedexpertisein vulnerability assessment, CVE analysis, and remediation strategies.
- Deep understanding of government compliance frameworks (Gov Ramp,Fed Ramp, or similar).
- Proficiency in multiple programming languages (Java, Python, Go, C#, or similar).
- Strong experience with CI/CD pipelines, build systems, and infrastructure scanning.
- Solid understanding of container security, Kubernetes, and cloud infrastructure security.
- Experience with dependency management tools and library upgrade processes.
- Knowledge of common vulnerability types (OWASP Top 10, CWE) and remediation techniques.
- Bachelor’s degree in computer science, Cybersecurity, or related field, or equivalent professional experience.
- Active security certifications (CISSP, CCSK, CEH, Security+, or similar).
- Experience with
Gov Rampor Fed Rampcompliance processes and assessments. - Background inDev Sec Ops practices and security automation.
- Knowledge of threat modeling and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).