Назад
Company hidden
1 час назад

Staff Software Systems Engineer (Compliance)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Staff Software Systems Engineer (Compliance): Leading GovRamp and FedRamp compliance efforts for the Enterprise Platform (EP1) with an accent on vulnerability management and security scanning. Focus on executing SAST/DAST scans, remediating CVEs, and maintaining continuous compliance across cloud infrastructure.

Location: Hybrid (San Jose, California, US)

Company

hirify.global provides cloud-driven networking solutions trusted by over 50,000 customers globally to accelerate digital transformation.

What you will do

  • Lead GovRamp and FedRamp compliance initiatives for the Enterprise Platform (EP1).
  • Execute comprehensive security scans (SAST, DAST, container, dependency) and validate results to filter false positives.
  • Identify, triage, and remediate open CVEs across the platform based on severity and exploitability.
  • Manage dependency and library upgrades to ensure the platform remains secure and compliant.
  • Coordinate build generation and security verification for GovRamp-related testing.
  • Maintain detailed documentation of security findings and generate reports for regulatory reviews.

Requirements

  • 8+ years of software engineering experience, with 3+ years focused on security, compliance, or vulnerability management.
  • Hands-on experience with security scanning tools such as Tenable or Snyk.
  • Deep understanding of government compliance frameworks like GovRamp or FedRamp.
  • Proficiency in multiple programming languages including Java, Python, Go, or C#.
  • Strong experience with CI/CD pipelines, Kubernetes, and cloud infrastructure security.
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.

Nice to have

  • Active security certifications (CISSP, CCSK, CEH, Security+).
  • Background in DevSecOps practices and security automation.
  • Experience with threat modeling and attack surface analysis.
  • Knowledge of API security testing and secure coding practices.

Culture & Benefits

  • Flexible work environment with remote options.
  • Comprehensive health, wellness, and retirement benefits.
  • Competitive compensation package including stock options and performance bonuses.
  • Professional development support, including certifications and training.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →