Extreme Networks, Inc.

Staff SW Systems Engineer - GovRamp & FedRamp Compliance - 103396

Extreme Networks, Inc.$170K — $210K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of software engineering experience with at least 3+ years in security or compliance roles.
  • Hands-on experience with security scanning tools like Tenable or Snyk.
  • Expertise in vulnerability assessment and CVE analysis.
  • Familiarity with government compliance frameworks such as GovRamp and FedRamp.
  • Proficient in programming languages like Java, Python, Go, or C#.
  • Experience with CI/CD pipelines and build systems.
  • Knowledge of container security and cloud infrastructure security.

Responsibilities

  • Execute security scans on the EP1 platform and infrastructure using industry-standard tools.
  • Establish regular scanning schedules for compliance monitoring.
  • Validate scan results and prioritize vulnerabilities for remediation.
  • Identify and fix open CVEs across the platform based on severity.
  • Implement patches and security fixes with development teams.
  • Upgrade dependencies and manage third-party libraries for security risks.
  • Maintain documentation of security findings and generate compliance reports.

Benefits

  • Opportunity to lead government compliance initiatives for a major enterprise platform.
  • Access to advanced security tools and technologies.
  • Collaboration with cross-functional security, compliance, and engineering teams.
  • Support for professional development, including certifications and training.
  • Comprehensive health, wellness, and retirement benefits.
  • Flexible work environment with hybrid remote options.
  • Opportunity to directly impact government modernization through secure infrastructure.
Full Job Description
Staff Software Engineer - GovRamp & FedRamp Compliance

Reports To: Director of Software Systems Engineering

Location: San Jose,California

Experience : 8 to 13 Years of Experience

Hybrid role

JOB DESCRIPTION

We are seeking a highly skilled Staff Software Engineer to lead GovRamp and FedRamp compliance efforts for our Enterprise Platform (EP1). This role is critical for ensuring our platform meets stringent government compliance standards and maintains continuous compliance through proactive vulnerability management. The successful candidate will manage security scan operations, vulnerability remediation, dependency management, and compliance validation across the entire platform and underlying infrastructure.

Key Responsibilities

  • Security Scanning & Analysis


  • Execute comprehensive security scans on the entire EP1 platform and underlying infrastructure using industry-standard tools (SAST, DAST, container scanning, dependency scanning).


  • Establish and maintain regular scanning schedules to ensure continuous compliance monitoring.


  • Review and validate scan results for accuracy, filtering false positives and prioritizing genuine vulnerabilities.


  • Vulnerability Management & Remediation


  • Identify, triage, and fix open CVEs across the platform with priority based on severity and exploitability.


  • Research and implement patches and security fixes in coordination with development teams.


  • Track vulnerability remediation progress and ensure timely closure of identified issues.


  • Dependency & Library Management


  • Regularly upgrade dependencies and libraries across the EP1 platform to address known vulnerabilities.


  • Evaluate third-party components and libraries for security risks before integration.


  • Maintain a comprehensive inventory of all platform dependencies and their security status.


  • Build & Deployment Support


  • Generate and manage builds for GovRamp-related testing and validation.


  • Coordinate with QA and compliance teams to ensure builds meet GovRamp/FedRamp requirements.


  • Support pre-deployment security verification and compliance checks.


  • Compliance & Documentation


  • Maintain documentation of security findings, remediation efforts, and compliance status.


  • Generate compliance reports for internal and regulatory review.


  • Support security audit preparations and compliance assessments.


Required Qualifications

  • 8 + years of software engineering experience with at least 3+ years focused on security, compliance, or vulnerability management.


  • Strong hands-on experience with security scanning tools (tenable, Snyk, or similar).


  • Demonstrated expertise in vulnerability assessment, CVE analysis, and remediation strategies.


  • Deep understanding of government compliance frameworks (GovRamp, FedRamp, or similar).


  • Proficiency in multiple programming languages (Java, Python, Go, C#, or similar).


  • Strong experience with CI/CD pipelines, build systems, and infrastructure scanning.


  • Solid understanding of container security, Kubernetes, and cloud infrastructure security.


  • Experience with dependency management tools and library upgrade processes.


  • Knowledge of common vulnerability types (OWASP Top 10, CWE) and remediation techniques.


  • Bachelor's degree in computer science, Cybersecurity, or related field, or equivalent professional experience.


Preferred Qualifications

  • Active security certifications (CISSP, CCSK, CEH, Security+, or similar).


  • Experience with GovRamp or FedRamp compliance processes and assessments.


  • Background in DevSecOps practices and security automation.


  • Knowledge of threat modeling and attack surface analysis.


  • Experience with containerization security scanning and runtime protection.


  • Background in secure coding practices and code review for security issues.


  • Experience with API security testing and web application security.


  • Prior experience managing security programs or compliance initiatives.


Technical Skills & Competencies

Security & Compliance Tools:

  • SAST: Sonarqube, Checkmarx, Coverity, Fortify


  • DAST: OWASP ZAP, Burp Suite, Acunetix


  • Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot


  • Container Security: Trivy, Twistlock, Aqua Security


  • Infrastructure Scanning: CloudSploit, ScoutSuite, Prowler


Programming & Development:

  • Languages: Java, Python, Go, C#, JavaScript


  • Build Systems: Maven, Gradle, npm, pip, cargo


  • Version Control: Git, GitHub, GitLab


DevOps & Cloud:

  • Cloud Platforms: AWS, Azure, GCP


  • Container Technologies: Docker, Kubernetes, container registries


  • CI/CD: Jenkins, GitLab CI, GitHub Actions, Azure Pipelines


  • IaC: Terraform, CloudFormation, Ansible


Soft Skills:

  • Attention to detail and strong analytical thinking


  • Excellent written and verbal communication skills


  • Ability to work independently and manage multiple priorities


  • Proactive problem-solving and troubleshooting abilities


  • Passion for security and compliance best practices


What We Offer

  • Opportunity to drive government compliance and security initiatives for a major enterprise platform


  • Work with cutting-edge security tools and technologies


  • Collaborate with security, compliance, and engineering teams


  • Professional development support including certifications and training


  • Competitive compensation package with stock options and performance bonuses


  • Comprehensive health, wellness, and retirement benefits


  • Flexible work environment with remote options


  • Impact on government modernization through secure, compliant infrastructure


$170,000 - $210,000 a year

About Extreme Networks, Inc.

Extreme Networks of Santa Clara, Calif., founded in 1996, is a publicly listed company that designs, builds, and installs sophisticated Ethernet solutions that meet the toughest challenges in network connectivity and IP-based communications.

Extreme Networks Careers

Joining Extreme Networks presents an unparalleled opportunity to advance one's career at the forefront of innovation, leadership, and digital transformation. Extreme Networks, a leader in providing cutting-edge networking solutions, is actively seeking talented individuals to join its global team.

Explore Job Opportunities

Extreme Networks offers a variety of job opportunities that cater to a range of skills and experiences. Whether one is a seasoned professional or a recent graduate, Extreme Networks has a position that could be the perfect fit. From engineering to marketing, the company's expansive portfolio of roles ensures that every team member can find a path that aligns with their career aspirations.

Internship Programs

For those just starting their professional journey, Extreme Networks provides robust internship programs designed to foster growth, enhance skills, and immerse participants in the culture of innovation that the company champions. Internships at Extreme Networks are gateways to full-time employment and offer invaluable industry experience.

Culture and Benefits

Extreme Networks is committed to creating a workplace that values diversity, encourages innovation, and supports the professional growth of its team members. The company offers competitive benefits, including comprehensive health coverage, retirement plans, and wellness programs, all designed to support the well-being of its employees. The inclusive culture at Extreme Networks ensures that all team members feel valued and are given the opportunity to contribute meaningfully.

Professional Growth and Development

Career advancement is a cornerstone of employment at Extreme Networks. With access to cutting-edge technologies and a variety of professional development programs, employees are equipped to excel and innovate within their fields. Leadership training and diversity initiatives further enhance the professional environment, ensuring that all team members have the resources to succeed.

Networking and Innovation

At Extreme Networks, networking goes beyond technology—it’s about connecting people. Employees are encouraged to engage with one another through various networking events, fostering a community of collaboration and shared knowledge. This emphasis on teamwork bolsters innovation and drives the company’s success in the competitive tech industry.

Hiring Process

The hiring process at Extreme Networks is designed to be transparent and engaging. Candidates are encouraged to showcase their skills and experiences through detailed resumes and proactive interviews. The company looks for individuals who are curious, creative, and ready to contribute to a team that is driving technological advancements.

Join the Extreme Networks Team

Explore the career opportunities available at Extreme Networks today. Search open positions that match your skills and interests. Extreme Networks is looking for passionate, driven, and innovative team players.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights—all from the professionals who work at Extreme Networks. Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover what exciting and rewarding opportunities await at Extreme Networks.

SEARCH EXTREME NETWORKS JOBS

READ CAREERS BLOG

Job Alert Emails

Stay informed about the latest employment opportunities and company news by subscribing to job alert emails from Extreme Networks. Tailor your alerts to match your career interests and be the first to know about new openings and exclusive insights.
Learn more about Extreme Networks, Inc.
Size
2,441 employees
Market Cap
$2.4 billion
Industry
Net Income
-$77.4 million
5 Year Trend
+12.9%
Revenue
$902.9 million
NASDAQ

Similar Jobs

More Jobs at Extreme Networks, Inc.

More Information Technology Jobs

Find similar Staff SW Systems Engineer - GovRamp & FedRamp Compliance - 103396 jobs: