368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$170k – $210k per year
Location
Remote/Hybrid (San Jose, United States)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Extreme Networks is a global leader in cloud networking solutions. The company specializes in providing wired and wireless LAN infrastructure, network security, and cloud-based network management services. Their products and solutions, such as ExtremeCloud™ IQ and Network Fabric, are designed to simplify IT operations through automation and intelligent management.

Staff Software Engineer - GovRamp& FedRampCompliance

Reports To: Director of Software Systems Engineering

Location: San Jose,California

Experience : 8 to 13 Years of Experience

Hybrid role

JOB DESCRIPTION

We are seeking a highly skilled Staff Software Engineer to lead GovRamp and FedRamp compliance efforts for our Enterprise Platform (EP1). This role is critical for ensuring our platform meets stringent government compliance standards and maintains continuous compliance through proactive vulnerability management. The successful candidate will manage security scan operations, vulnerability remediation, dependency management, and compliance validation across the entire platform and underlying infrastructure.

Key Responsibilities

  • Security Scanning & Analysis

  • Execute comprehensive security scans on the entire EP1 platform and underlying infrastructure using industry-standard tools (SAST, DAST, container scanning, dependency scanning).

  • Establish and maintain regular scanning schedules to ensure continuous compliance monitoring.

  • Review and validate scan results for accuracy, filtering false positives and prioritizing genuine vulnerabilities.

  • Vulnerability Management & Remediation

  • Identify, triage, and fix open CVEs across the platform with priority based on severity and exploitability.

  • Research and implement patches and security fixes in coordination with development teams.

  • Track vulnerability remediation progress and ensure timely closure of identified issues.

  • Dependency & Library Management

  • Regularly upgrade dependencies and libraries across the EP1 platform to address known vulnerabilities.

  • Evaluate third-party components and libraries for security risks before integration.

  • Maintain a comprehensive inventory of all platform dependencies and their security status.

  • Build & Deployment Support

  • Generate and manage builds for GovRamp-related testing and validation.

  • Coordinate with QA and compliance teams to ensure builds meet GovRamp/FedRamp requirements.

  • Support pre-deployment security verification and compliance checks.

  • Compliance & Documentation

  • Maintain documentation of security findings, remediation efforts, and compliance status.

  • Generate compliance reports for internal and regulatory review.

  • Support security audit preparations and compliance assessments.

Required Qualifications

  • 8 + years of software engineering experience with at least 3+ years focused on security, compliance, or vulnerability management.

  • Strong hands-on experience with security scanning tools (tenable, Snyk, or similar).

  • Demonstrated expertise in vulnerability assessment, CVE analysis, and remediation strategies.

  • Deep understanding of government compliance frameworks (GovRamp, FedRamp, or similar).

  • Proficiency in multiple programming languages (Java, Python, Go, C#, or similar).

  • Strong experience with CI/CD pipelines, build systems, and infrastructure scanning.

  • Solid understanding of container security, Kubernetes, and cloud infrastructure security.

  • Experience with dependency management tools and library upgrade processes.

  • Knowledge of common vulnerability types (OWASP Top 10, CWE) and remediation techniques.

  • Bachelor’s degree in computer science, Cybersecurity, or related field, or equivalent professional experience.

Preferred Qualifications

  • Active security certifications (CISSP, CCSK, CEH, Security+, or similar).

  • Experience with GovRamp or FedRamp compliance processes and assessments.

  • Background in DevSecOps practices and security automation.

  • Knowledge of threat modeling and attack surface analysis.

  • Experience with containerization security scanning and runtime protection.

  • Background in secure coding practices and code review for security issues.

  • Experience with API security testing and web application security.

  • Prior experience managing security programs or compliance initiatives.

Technical Skills & Competencies

Security & Compliance Tools:

  • SAST: Sonarqube, Checkmarx, Coverity, Fortify

  • DAST: OWASP ZAP, Burp Suite, Acunetix

  • Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot

  • Container Security: Trivy, Twistlock, Aqua Security

  • Infrastructure Scanning: CloudSploit, ScoutSuite, Prowler

Programming & Development:

  • Languages: Java, Python, Go, C#, JavaScript

  • Build Systems: Maven, Gradle, npm, pip, cargo

  • Version Control: Git, GitHub, GitLab

DevOps & Cloud:

  • Cloud Platforms: AWS, Azure, GCP

  • Container Technologies: Docker, Kubernetes, container registries

  • CI/CD: Jenkins, GitLab CI, GitHub Actions, Azure Pipelines

  • IaC: Terraform, CloudFormation, Ansible

Soft Skills:

  • Attention to detail and strong analytical thinking

  • Excellent written and verbal communication skills

  • Ability to work independently and manage multiple priorities

  • Proactive problem-solving and troubleshooting abilities

  • Passion for security and compliance best practices

What We Offer

  • Opportunity to drive government compliance and security initiatives for a major enterprise platform

  • Work with cutting-edge security tools and technologies

  • Collaborate with security, compliance, and engineering teams

  • Professional development support including certifications and training

  • Competitive compensation package with stock options and performance bonuses

  • Comprehensive health, wellness, and retirement benefits

  • Flexible work environment with remote options

  • Impact on government modernization through secure, compliant infrastructure

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Jose
$108k – $242k per year (Estimated) • Remote • Full-Time • 5+ years exp
C#
SQL
C#
.NET
Databases
MS SQL
RabbitMQ
AI/ML
ChatGPT
Claude
Claude Code
Copilot
Cursor
LLM
RAG
Model Context Protocol
DevOps
CI/CD
Git
GitHub
Apply
$40k – $107k per year (Estimated) • Remote • 5+ years exp • Tbilisi
C#
SQL
C#
.NET
Databases
MS SQL
RabbitMQ
AI/ML
ChatGPT
Claude
Claude Code
Copilot
Cursor
LLM
RAG
Model Context Protocol
DevOps
CI/CD
Git
GitHub
Apply
$93k – $210k per year (Estimated) • In office • Contractor • 8+ years exp • Bachelor's Degree • Singapore
DevOps
CI/CD
Apply
$77k – $194k per year (Estimated) • In office • Contractor • 5+ years exp • Singapore
Java
SQL
DevOps
CI/CD
Docker
Grafana
Incident Management
Kubernetes
OpenShift
SRE
Apply
$131k – $281k per year (Estimated) • In office • Contractor • 15+ years exp • Singapore
Java
SQL
Java
Maven
Databases
MS SQL
Oracle
DevOps
AWS
CI/CD
Incident Management
Kubernetes
OpenShift
OpenStack
Apply
$220k – $250k per year • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • San Jose
Databases
Apache Ignite
Apache Kafka
ClickHouse
ElasticSearch
PostgreSQL
RabbitMQ
Redis
AI/ML
Flink
DevOps
Ansible
AWS
Azure
Docker
GCP
Helm
Kibana
Kubernetes
Nagios
Prometheus
Terraform
Cybersecurity
FedRAMP
ISO 27001
SOC 2
Apply
$120k – $140k per year • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree
Bash
Groovy
Java
Java
Gradle
AI/ML
Claude
Copilot
DevOps
Ansible
ArgoCD
AWS
Azure
CI/CD
Docker
GCP
Git
GitOps
Helm
Jenkins
JFrog Artifactory
Kubernetes
Terraform
GitHub
Apply
$28k – $73k per year (Estimated) • Remote/Hybrid • Full-Time • Chennai
Go
Java
Databases
Apache Kafka
MariaDB
PostgreSQL
RabbitMQ
Redis
DevOps
CI/CD
Docker
Git
gRPC
Helm
Jenkins
K3s
Kubernetes
WebSockets
Apply
$42k – $91k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • Chennai
Go
Java
Databases
Apache Kafka
MariaDB
PostgreSQL
RabbitMQ
Redis
DevOps
CI/CD
Docker
Git
gRPC
Helm
Jenkins
K3s
Kubernetes
WebSockets
Apply
$28k – $62k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Chennai
Java
Perl
Python
SQL
Databases
PostgreSQL
Redis
DevOps
AWS
Azure
Docker
GCP
Git
Grafana
Hyper-V
Kubernetes
Prometheus
GitHub
Cybersecurity
Wireshark
QA
JMeter
Locust
Robot Framework
Selenium
Apply
$147k – $265k per year (Estimated) • In office • Full-Time • Folsom • San Jose
Apply
$117k – $255k per year (Estimated) • In office • Full-Time • 8+ years exp • Richardson • Boise • Folsom • San Jose
Verilog
AI/ML
Claude
Apply
$124k – $208k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Austin • San Jose
C++
Python
SystemVerilog
Chips/EDA
Formal Verification
Apply
$116k – $253k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Boise • San Jose
Apply
$68k – $85k per year • In office • Full-Time • Master's Degree • San Jose
Python
AI/ML
AI Agents
DevOps
Amazon EC2
AWS
AWS Lambda
Bitbucket
CI/CD
CloudFormation
Docker
Git
Kubernetes
Terraform
Amazon S3
IAM
HPC
Cybersecurity
Least Privilege
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.