Stand out for this role — generate a tailored resume and cover letter in about a minute.
Extreme Networks, Inc. in Chennai seeks a Sw Systems Engineer to lead GovRamp and FedRamp compliance for the Enterprise Platform. You will manage security scans, vulnerability remediation, and dependency management across the platform and infra.
The role requires 2–5 years in software engineering with a strong security focus, CI/CD experience, and proficiency in Java/Python/Go. Join a Hybrid Chennai team driving security and compliance.
Over 50,000 customers globally trust our end-to-end, cloud-driven networking solutions. They rely on our top-rated services and support to accelerate their digital transformation efforts and deliver unprecedented progress. With double-digit growth year over year, no provider is better positioned to deliver scalable outcomes than Extreme.
Inclusion is one of our core values and in our DNA. We are committed to fostering an inclusive workplace that embraces our differences and creates an atmosphere where all our employees thrive because of their differences, not in spite of them.
Become part of Something big with Extreme! As a global networking leader, learn why there’s no better time to join the Extreme team.
Reports To: Director of Software Systems Engineering
Location: Only Chennai - Hybrid roleExperience : 2 to 5 Years of Experience
We are seeking a highly skilled Sw Systems Engineer to lead GovRamp and FedRamp compliance efforts for our Enterprise Platform (EP1). This role is critical for ensuring our platform meets stringent government compliance standards and maintains continuous compliance through proactive vulnerability management. The successful candidate will manage security scan operations, vulnerability remediation, dependency management, and compliance validation across the entire platform and underlying infrastructure.
Security Scanning & Analysis
Execute comprehensive security scans on the entire EP1 platform and underlying infrastructure using industry-standard tools (SAST, DAST, container scanning, dependency scanning).
Establish andmaintainregular scanning schedules to ensure continuous compliance monitoring.
Review andvalidate scan results for accuracy, filtering false positives and prioritizing genuine vulnerabilities.
Vulnerability Management & Remediation
Identify, triage, and fix open CVEs across the platform with priority based on severity and exploitability.
Research and implement patches and security fixes in coordination with development teams.
Track vulnerability remediation progress and ensure timely closure of identified issues.
Dependency & Library Management
Regularly upgrade dependencies and libraries across the EP1 platform to address known vulnerabilities.
Evaluate third-party components and libraries for security risks before integration.
Maintain a comprehensive inventory of all platform dependencies and their security status.
Build & Deployment Support
Generate and manage builds for GovRamp-related testing and validation.
Coordinate with QA and compliance teams to ensure builds meet GovRamp/FedRamp requirements.
Support pre-deployment security verification and compliance checks.
Compliance & Documentation
Maintain documentation of security findings, remediation efforts, and compliance status.
Generate compliance reports for internal and regulatory review.
Support security audit preparations and compliance assessments.
2 to 5 years of software engineering experience with at least 2+ years focused on security, compliance, or vulnerability management.
Strong hands-on experience with security scanning tools (tenable,Snyk, or similar).
Demonstratedexpertisein vulnerability assessment, CVE analysis, and remediation strategies.
Deep understanding of government compliance frameworks (GovRamp,FedRamp, or similar).
Proficiencyin multiple programming languages (Java, Python, Go, C#, or similar).
Strong experience with CI/CD pipelines, build systems, and infrastructure scanning.
Solid understanding of container security, Kubernetes, and cloud infrastructure security.
Experience with dependency management tools and library upgrade processes.
Knowledge of common vulnerability types (OWASP Top 10, CWE) and remediation techniques.
Bachelor’s degree in computer science, Cybersecurity, or related field, or equivalent professional experience.
Active security certifications (CISSP, CCSK, CEH, Security+, or similar).
Experience withGovRamporFedRampcompliance processes and assessments.
Background inDevSecOpspractices and security automation.
Knowledge of threat modeling and attack surface analysis.
Experience withcontainerizationsecurity scanning and runtime protection.
Background in secure coding practices and code review for security issues.
Experience with API security testing and web application security.
Prior experience managing security programs or compliance initiatives.
SAST:Sonarqube,Checkmarx, Coverity, Fortify
DAST: OWASP ZAP, Burp Suite,Acunetix
Dependency/SCA:Snyk, Black Duck,WhiteSource,Dependabot
Container Security:Trivy,Twistlock, Aqua Security
Infrastructure Scanning:CloudSploit,ScoutSuite, Prowler
Languages: Java, Python, Go, C#, JavaScript
Build Systems: Maven, Gradle,npm, pip, cargo
Version Control: Git, GitHub, GitLab
Cloud Platforms: AWS, Azure, GCP
Container Technologies: Docker, Kubernetes, container registries
CI/CD: Jenkins, GitLab CI, GitHub Actions, Azure Pipelines
IaC: Terraform, CloudFormation, Ansible
Attention to detail and strong analytical thinking
Excellent written and verbal communication skills
Ability to work independently and manage multiple priorities
Proactive problem-solving and troubleshooting abilities
Passion for security and compliance best practices
Opportunity to drive government compliance and security initiatives for a major enterprise platform
Work withcutting-edgesecurity tools and technologies
Collaborate with security, compliance, and engineering teams
Professional development support including certifications and training
Competitive compensation package with stock options and performance bonuses
Comprehensive health, wellness, and retirement benefits
Flexible work environment with remote options
Impact on government modernization through secure, compliant infrastructure
Extreme Networks, Inc. (EXTR) creates effortless networking experiences that enable all of us to advance. We push the boundaries of technology leveraging the powers of machine learning, artificial intelligence, analytics, and automation. Over 50,000 customers globally trust our end-to-end, cloud-driven networking solutions and rely on our top-rated services and support to accelerate their digital transformation efforts and deliver progress like never before. For more information, visit Extreme's website or follow us on Twitter, LinkedIn, and Facebook.
We encourage people from underrepresented groups to apply. Come Advance with us! In keeping with our values, no employee or applicant will face discrimination/harassment based on: race, color, ancestry, national origin, religion, age, gender, marital domestic partner status, sexual orientation, gender identity, disability status, or veteran status. Above and beyond discrimination/harassment based on “protected categories,” Extreme Networks also strives to prevent other, subtler forms of inappropriate behavior (e.g., stereotyping) from ever gaining a foothold in our organization. Whether blatant or hidden, barriers to success have no place at Extreme Networks.