{bc}
lever

SW Systems Engineer – 10399

Extreme Networks
Chennai, IND
Full-time
Mid · 2+ years experience
Hybrid
Discovered 6 days ago
SASTDASTTenableSnykJavaPython
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

SASTDASTTenable
Smart Apply

Full Job Posting

Location: Only Chennai - Hybrid role

  • Experience : 2 to 5 Years of Experience

JOB DESCRIPTION

We are seeking a highly skilled Sw Systems Engineer to lead GovRamp and FedRamp compliance efforts for our Enterprise Platform (EP1). This role is critical for ensuring our platform meets stringent government compliance standards and maintains continuous compliance through proactive vulnerability management. The successful candidate will manage security scan operations, vulnerability remediation, dependency management, and compliance validation across the entire platform and underlying infrastructure.

Key Responsibilities

Security Scanning & Analysis

Execute comprehensive security scans on the entire EP1 platform and underlying infrastructure using industry-standard tools (SAST, DAST, container scanning, dependency scanning).

Establish and maintain regular scanning schedules to ensure continuous compliance monitoring.

Review and validate scan results for accuracy, filtering false positives and prioritizing genuine vulnerabilities.

Vulnerability Management & Remediation

Identify, triage, and fix open CVEs across the platform with priority based on severity and exploitability.

Research and implement patches and security fixes in coordination with development teams.

Track vulnerability remediation progress and ensure timely closure of identified issues.

Dependency & Library Management

Regularly upgrade dependencies and libraries across the EP1 platform to address known vulnerabilities.

Evaluate third-party components and libraries for security risks before integration.

Maintain a comprehensive inventory of all platform dependencies and their security status.

Build & Deployment Support

Generate and manage builds for GovRamp-related testing and validation.

Coordinate with QA and compliance teams to ensure builds meet GovRamp/FedRamp requirements.

Support pre-deployment security verification and compliance checks.

Compliance & Documentation

Maintain documentation of security findings, remediation efforts, and compliance status.

Generate compliance reports for internal and regulatory review.

Support security audit preparations and compliance assessments.

Required Qualifications

2 to 5 years of software engineering experience with at least 2+ years focused on security, compliance, or vulnerability management.

Strong hands-on experience with security scanning tools (tenable, Snyk, or similar).

Demonstrated expertise in vulnerability assessment, CVE analysis, and remediation strategies.

Deep understanding of government compliance frameworks (GovRamp, FedRamp, or similar).

Proficiency in multiple programming languages (Java, Python, Go, C#, or similar).

Strong experience with CI/CD pipelines, build systems, and infrastructure scanning.

Solid understanding of container security, Kubernetes, and cloud infrastructure security.

Experience with dependency management tools and library upgrade processes.

Knowledge of common vulnerability types (OWASP Top 10, CWE) and remediation techniques.

Bachelor’s degree in computer science, Cybersecurity, or related field, or equivalent professional experience.

Preferred Qualifications

Active security certifications (CISSP, CCSK, CEH, Security+, or similar).

Experience with GovRamp or FedRamp compliance processes and assessments.

Background in DevSecOps practices and security automation.

Knowledge of threat modeling and attack surface analysis.

Experience with containerization security scanning and runtime protection.

Background in secure coding practices and code review for security issues.

Experience with API security testing and web application security.

Prior experience managing security programs or compliance initiatives.

Technical Skills & Competencies

Security & Compliance Tools:

SAST: Sonarqube, Checkmarx, Coverity, Fortify

DAST: OWASP ZAP, Burp Suite, Acunetix

Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot

Container Security: Trivy, Twistlock, Aqua Security

Infrastructure Scanning: CloudSploit, ScoutSuite, Prowler

Programming & Development:

Languages: Java, Python, Go, C#, JavaScript

Build Systems: Maven, Gradle, npm, pip, cargo

Version Control: Git, GitHub, GitLab

DevOps & Cloud:

Cloud Platforms: AWS, Azure, GCP

Container Technologies: Docker, Kubernetes, container registries

CI/CD: Jenkins, GitLab CI, GitHub Actions, Azure Pipelines

IaC: Terraform, CloudFormation, Ansible

Soft Skills:

Attention to detail and strong analytical thinking

Excellent written and verbal communication skills

Ability to work independently and manage multiple priorities

Proactive problem-solving and troubleshooting abilities

Passion for security and compliance best practices

What We Offer

Opportunity to drive government compliance and security initiatives for a major enterprise platform

Work with cutting-edge security tools and technologies

Collaborate with security, compliance, and engineering teams

Professional development support including certifications and training

Competitive compensation package with stock options and performance bonuses

Comprehensive health, wellness, and retirement benefits

Flexible work environment with remote options

Impact on government modernization through secure, compliant infrastructure

SW Systems Engineer – GovRamp & FedRamp Compliance

Reports To: Director of Software Systems Engineering

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Extreme Networks