11 Aug
|
Extreme Networks
|
Chennai
11 Aug
Extreme Networks
Chennai
Position Summary
We are seeking a highly skilled Sw Systems Engineer to lead GovRamp and FedRamp compliance efforts for our Enterprise Platform EP1. This role is critical for ensuring our platform meets stringent government compliance standards and maintains continuous compliance through proactive vulnerability management. The successful candidate will manage security scan operations, vulnerability remediation, dependency management, and compliance validation across the entire platform and underlying infrastructure.
Overview
Reports To: Director of Software Systems Engineering
Location: Chennai - Hybrid role
Experience: 5 to 9 Years
Key Responsibilities
- Security Scanning & Analysis: Execute comprehensive security scans on the entire EP1 platform and underlying infrastructure using industry-standard tools SAST, DAST, container scanning, dependency scanning.
- Establish and maintain regular scanning schedules to ensure continuous compliance monitoring.
- Review and validate scan results for accuracy, filtering false positives and prioritizing genuine vulnerabilities.
- Vulnerability Management & Remediation: Identify, triage, and fix open CVEs across the platform with priority based on severity and exploitability.
- Research and implement patches and security fixes in coordination with development teams.
- Track vulnerability remediation progress and ensure timely closure of identified issues.
- Dependency & Library Management: Regularly upgrade dependencies and libraries across the EP1 platform to address known vulnerabilities.
- Evaluate third-party components and libraries for security risks before integration.
- Maintain a comprehensive inventory of all platform dependencies and their security status.
- Build & Deployment Support: Generate and manage builds for GovRamp related testing and validation.
- Coordinate with QA and compliance teams to ensure builds meet GovRamp/FedRamp requirements.
- Support pre deployment security verification and compliance checks.
- Compliance & Documentation: Maintain documentation of security findings, remediation efforts, and compliance status.
- Generate compliance reports for internal and regulatory review.
- Support security audit preparations and compliance assessments.
Required Qualifications
- 5 to 9 years of software engineering experience with at least 3+ years focused on security, compliance, or vulnerability management.
- Robust hands-on experience with security scanning tools Tenable Snyk or similar.
- Demonstrated expertise in vulnerability assessment, CVE analysis, and remediation strategies.
- Deep understanding of government compliance frameworks GovRamp FedRamp or similar.
- Proficiency in multiple programming languages Java Python Go C# or similar.
- Strong experience with CI/CD pipelines, build systems, and infrastructure scanning.
- Solid understanding of container security, Kubernetes, and cloud infrastructure security.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 SR SW Systems Engineer - GovRamp & FedRamp Compliance (Chennai)
🏢 Extreme Networks
📍 Chennai