> Markdown version of [/jobs/ext/673668-staff-software-engineer-government-engineering-fedramp-traffic](https://www.wearedevelopers.com/jobs/ext/673668-staff-software-engineer-government-engineering-fedramp-traffic). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Software Engineer - Government Engineering (FedRAMP & Traffic) - **Company:** Procore - **Location:** West, TX, United States - **Experience:** Experienced - **Salary:** $168,560.0 - $231,770.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing, Federal Information Processing Standards (FIPS), Identity and Access Management, Python (Programming Language), Key Management, Project Management Software, OpenID, Role-Based Access Control, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Software Engineering, TypeScript, Datadog, Network Routing, Okta, Istio, Control Language, Solid Principles, Kubernetes, Hashicorp, Cloudflare, Golang - **Published:** June 27, 2026 - **Apply:** https://diversityjobs.com/career/17408278/Staff-Software-Engineer-Government-Engineering-Fedramp-Traffic-Texas-Austin ## About the Role * Experience: 8+ years of software or infrastructure engineering experience, with at least 3 years directly supporting or operating within a FedRAMP-authorized environment (AWS GovCloud experience is a plus). * Software Engineering Proficiency: Strong programming fundamentals with demonstrated proficiency in writing software (e.g., Golang, Typescript, or Python) to build robust platform infrastructure and automation tools. * Deep IAM Expertise: Comprehensive hands-on experience with identity management architecture, identity federation (SAML, OIDC), directory services, privileged access management, and zero-trust architecture principles. * FIPS Cryptography Real-World Experience: Deep understanding of FIPS 140-2/140-3 validated cryptographic modules. You know how to verify and enforce true NIST-certified algorithm/module testing in practice, rather than just knowing "encryption is on." * Cloud Traffic & Edge Infrastructure: Production experience managing high-throughput ingress/egress, traffic routing, and container network interfaces at scale using tools like Istio, Kong, and Cloudflare. * Kubernetes Ecosystem Mastery: Extensive experience architecting, operating, and hardening Kubernetes clusters, including policy enforcement (e.g., OPA/Gatekeeper, Kyverno) and secure secrets management., * Experience with secrets management platforms operating in FIPS mode (e.g., HashiCorp Vault). * Familiarity with FedRAMP Rev 5 transition requirements. * Experience with STIG application or CIS benchmark enforcement at scale. * Security certifications such as CISSP, AWS Certified Security - Specialty, or CKS. ## Description We are looking for a Staff Software Engineer to join Procore's Government Engineering team and serve as a senior technical contributor for our FedRAMP initiative. In this role, you will design, build, and maintain next-generation platform services that provide cloud traffic, ingress/egress, identity, and compliance capabilities. You will combine your technical and collaboration skills along with established software design principles to create a secure, compliant, and highly scalable foundation that Procore developers, partners, and customers can easily integrate with. The impact of this team is wide as it touches all aspects of Procore's ecosystem within our FedRAMP authorization boundaries, and MUST respect and protect those boundaries. This position reports to the Senior Engineering Manager of the Government Engineering team and is a hybrid role based out of our Austin, TX office. We're looking for someone to join us immediately. What you'll do: * Manage Cloud Traffic & Service Mesh technologies: Design, implement, and maintain our next-generation network routing, edge controls, and service mesh architecture using Istio, Kong, and Cloudflare. * Lead Platform Migrations: Drive the engineering lifecycle and migration strategies transitioning internal teams over to centralized, compliant infrastructure pipelines using Istio, and Datadog. * Manage Identity & Access: Design and implement robust Identity and Access Management (IAM) architectures within FedRAMP boundaries, leveraging Okta for identity federation (SAML/OIDC), SSO, RBAC, and zero-trust patterns. * Enforce Cryptographic Security: Select, configure, and enforce NIST-certified FIPS 140-2/140-3 validated cryptographic modules across services, TLS configurations, and key management systems. * Advise on FedRAMP Compliance: Serve as a technical subject matter expert on FedRAMP compliance controls (NIST SP 800-53), translating complex regulatory control language into concrete, automated technical implementations. Partner with security teams on continuous monitoring (ConMon) and annual assessment readiness. * Develop Automations: Actively write production-grade software to eliminate platform gaps while mentoring mid-level engineers on compliance-aware engineering design patterns. * Leverage AI Tools: Welcome the use of modern developer tooling-including AI-assisted development assistants-where appropriate to optimize coding efficiency, automate mundane tasks, and accelerate platform delivery. ## Related Videos - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How Much FAANG Companies Actually Pay Software Engineers in 2025](https://www.wearedevelopers.com/magazine/230-how-much-faang-companies-actually-pay-software-engineers-in-2025)