R

Red Hat

Enterprise open-source software subscriptions and services

Commercial Programs Analyst Intern

Winter 2026Deadline 11/13/26
No salary listed
Internship
Raleigh, NC, USA
In Person
No H1B Sponsorship

About the job

Requirements
  • Excellent written and verbal communication skills in English.
  • Ability to manage tasks, meet deadlines, and analyze data to foster data-driven decisions.
  • Ability to establish and maintain communication with internal and external stakeholders.
  • Willingness to learn and proactively work as part of a wider team.
  • Ability to work without a need for current or future visa sponsorship.
Responsibilities
  • Review requests from Sales to adapt standard language into non-standard contract language for complex non-standard contracts.
  • Request and assemble Legal team and Deal team input to draft non-standard terms for complex contracts.
  • Review business terms language in non-standard or complex agreements, contracts, forms, and templates for compliance with corporate policies.
  • Establish trusted working relationships and collaborate proactively with Red Hat stakeholder teams to support contract activities.
  • Leverage Deal Management frameworks, professional knowledge, and corporate policies, processes, and systems to deliver deal contracts that address customer needs.
  • Ensure the accuracy of the clause library and the contracts and agreement repository.

About the company

Red Hat sells subscriptions for open-source software and related services to enterprises. Its products, like Red Hat Enterprise Linux, OpenShift, and Ansible, are open-source but come with guaranteed updates, patches, and professional support through a subscription, so customers install the software and receive ongoing assistance. The company differentiates itself with an enterprise-focused, integrated stack and services around hybrid cloud, containers, and automation, backed by IBM as a strategic owner while Red Hat operates as a distinct unit. Its goal is to help large organizations deploy, manage, and scale open-source software across complex IT environments with predictable, enterprise-grade support.

Company Size

10,001+

Company Stage

Acquired

Total Funding

$34B

Headquarters

Raleigh, North Carolina

Founded

1993

Get referred to Red Hat

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • IBM reported Red Hat hybrid cloud revenue up 13% in Q1 2026.
  • OpenShift crossed $2 billion ARR in 2026, proving durable enterprise demand.
  • OpenShift Virtualization VM usage grew 417% in 2025, expanding migration momentum.

What critics are saying

  • IBM cut Red Hat engineering in April 2026, weakening product velocity and culture.
  • OpenShift security advisories in September 2026 show persistent supply-chain and cluster exposure.
  • If IBM fully absorbs Red Hat, the independent platform brand collapses by 2027.

What makes Red Hat unique

  • Red Hat OpenShift unifies VMs, containers, and AI across hybrid cloud.
  • Red Hat AI 3.5 adds governed agents, safety evaluations, and shared GPU controls.
  • Red Hat's upstream-first model still anchors enterprise trust in Linux and Kubernetes.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Paid Vacation

Paid Sick Leave

Paid Holidays

Parental Leave

Family Planning Benefits

Tuition Reimbursement

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 0%

2 year growth

↑ 1%
Red Hat
Sep 29th, 2026
Why Red Hat is building an open foundation for enterprise agents with OpenClaw Enterprise.

Why Red Hat is building an open foundation for enterprise agents with OpenClaw Enterprise. Vice President and General Manager, AI Business Unit at Red Hat Applications are moving beyond predefined workflows toward agentic systems that can reason, use tools, interact with enterprise data, execute code, delegate work and collaborate with other agents to accomplish goals. This has driven the development of new capabilities in areas like agent sandboxing to secure agent execution, AI gateways to secure access to models and tools, AgentOps for tracing, observability, evaluation and more. Red Hat, Inc. believe another important layer of the enterprise AI stack is emerging: an open control plane for agents. This is why Red Hat, Inc. is excited about contributing to OpenClaw and the newly announced OpenClaw Enterprise, an enterprise-grade control plane for deploying and operating persistent agents across users and teams. From rapid innovation to enterprise-readiness OpenClaw has evolved rapidly over the past year, maturing from an agile open-source project into a production-grade foundation for AI agents. That evolution continues with the newly announced OpenClaw Enterprise project, built specifically to securely deploy these agents in enterprise environments. Red Hat, NVIDIA and others are collaborating on OpenClaw Enterprise development in the open. Both OpenClaw and OpenClaw Enterprise are fully open source, driving both innovation as well as transparency and trust for enterprise AI deployments. A proven history with Linux and Kubernetes Its approach with OpenClaw follows a familiar playbook at Red Hat. Throughout Red Hat's history, some of the biggest changes in enterprise computing have been driven by fundamental shifts in how applications are built and operated. Linux helped enterprises move applications from proprietary Unix systems and specialized hardware onto an open operating system running on industry-standard infrastructure. Later, containers and Kubernetes helped drive another transformation toward cloud-native applications composed of distributed microservices. Red Hat Enterprise Linux and Red Hat OpenShift helped make those transitions possible for many enterprise customers, powered by Red Hat's extensive work in upstream projects to drive underlying technologies that are open, trusted, and secure. Today, AI agents are driving the next evolution of enterprise applications. This is fueling new innovations across the open source ecosystem and projects like OpenShell, vLLM, Pytorch and more that Red Hat is contributing to. Its work in the OpenClaw community and on OpenClaw Enterprise will help bring new agent runtime capabilities and an open agent control plane to the enterprise. "Enterprises want the flexibility and innovation of open source with the governance, security, and reliability they expect from enterprise software," said Kevin Lin, who leads OpenClaw Enterprise efforts at OpenAI. "OpenClaw Enterprise brings those pieces together, and working with Red Hat and the broader community will help make it a trusted, open foundation for how agents are managed and deployed in the enterprise." Building upstream together Red Hat recently announced its sponsorship of the OpenClaw Foundation and Red Hat, Inc. is putting engineers behind it. Red Hat engineers are already contributing to OpenClaw, and Red Hat, Inc. is expanding that investment with expertise in Linux, Kubernetes, distributed systems, security and enterprise infrastructure. Building on its internal use of OpenClaw today, Red Hat, Inc. look forward to deploying OpenClaw Enterprise to orchestrate internal agent deployments and help directly inform its upstream contributions. Red Hat, Inc. intend to work with OpenAI, NVIDIA and the broader OpenClaw community on the capabilities required to operate agents at enterprise scale to drive the evolution of this technology and help establish open standards. Joe Fernandes is Vice President and General Manager of the Artificial Intelligence (AI) Business Unit at Red Hat, where he leads product management, product marketing, and technical marketing for Red Hat's AI platforms, including Red Hat Enterprise Linux AI (RHEL AI) and Red Hat OpenShift AI. Original podcast

Phoronix
Sep 24th, 2026
Fwupd 2.1.8 released with new hardware support from ASUS, Lenovo & others.

Fwupd 2.1.8 released with new hardware support from ASUS, Lenovo & others. Lead LVFS/Fwupd developer Richard Hughes of Red Hat announced Fwupd 2.1.8 today as the newest feature release for this open-source firmware updating solution for Linux systems. With Fwupd 2.1.8 comes support for a number of newer devices plus plenty of bug fixes. Fwupd 2.1.8 introduces a new plug-in for notifying bootupd when the EFI System Partition (ESP) changes, RSA-3072 signature verification support for Lenovo hardware, and a number of different bug fixes from memory leaks and buffer overflows to supporting larger Redfish firmware blobs. New hardware support in Fwupd 2.1.8 includes: - ASUS GX5407 - Elan PID 0CB6 - FocalTech MOC fingerprint sensors - Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000 - MaxLinear MxL862xx - MediaTek MT9700 FCTE and MT9701 KSMU - Pixart PID 4F01, 4F02, 4F0D and 4F0E - Rolling RW101 The ASUS ProArt P16 GX5407 support is for a quirk with the ILITEK touch controller's firmware. Great seeing the continued firmware updating support for Lenovo, MaxLinear, MediaTek, and PixArt devices. Downloads and the full list of Fwupd 2.1.8 changes can be found via GitHub.

Cryptika
Sep 22nd, 2026
Red Hat OpenShift flaw lets attackers bypass PGP checks and push malicious releases.

Red Hat OpenShift flaw lets attackers bypass PGP checks and push malicious releases. Red Hat has disclosed an Important security vulnerability in the OpenShift oc-mirror tool that could allow attackers to bypass PGP signature verification and introduce malicious release images into disconnected OpenShift environments. Tracked as CVE-2026-75939, the issue carries a CVSS v3.1 score of 7.4 and was made public on September 21, 2026. The flaw affects the openshift/oc-mirror component, which organizations use to copy OpenShift release images, operator catalogs, and related content into private registries. This process is particularly important for air-gapped or disconnected deployments, where systems cannot download software directly from Red Hat registries or the public internet. According to Red Hat, oc-mirror incorrectly validates PGP-signed release image signatures. The tool checks for signature errors before it has finished processing the entire signed message body. This creates a verification bypass condition in which a specially crafted PGP message may appear trusted even though its signature is forged. Red Hat OpenShift flaw. An attacker would need the ability to intercept or alter traffic between the affected oc-mirror instance and the signature endpoint. They could then provide a forged PGP message that contains a valid Red Hat release key ID. Because of the flawed validation sequence, the tool could accept the malicious message as legitimate and mirror a hostile release payload into a disconnected registry. This is a serious supply-chain risk because mirrored content is commonly treated as approved internal software. Once a malicious release image reaches the private registry, OpenShift administrators or automated installation pipelines could select it for deployment. That could expose clusters to unauthorized code execution, application tampering, credential theft, or data access. Red Hat rated the issue as Important and assigned it a network attack vector. The vulnerability does not require attacker privileges or user interaction. However, exploitation has high attack complexity because the attacker must successfully manipulate signature-related network traffic. Red Hat's CVSS vector lists high confidentiality and integrity impact, while availability impact is rated as none. The affected component is openshift4/oc-mirror-plugin-rhel9 in Red Hat OpenShift Container Platform 4. The RHEL 8 version of the plugin is listed as not affected because the component is not present. Red Hat noted that older package versions in affected minor product streams should generally be considered vulnerable unless explicitly marked otherwise. At the time of disclosure, Red Hat said no practical mitigation met its standard deployment and stability criteria. Organizations using oc-mirror should therefore treat release-mirroring workflows as high risk until security errata or updated packages are issued. Administrators should restrict network access to signature endpoints, enforce TLS inspection safeguards carefully, monitor for unusual changes in mirrored registry content, and validate release digests through independent trusted channels before promoting content into production. Teams should also review disconnected registry access controls, audit recent mirrored releases, and watch Red Hat's security advisories for remediation updates. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Red Hat OpenShift flaw lets attackers bypass PGP checks and push malicious releases appeared first on cyber security News. Related cyber security News posts. Red Hat published security advisory CVE-2025-10725, detailing an Important severity flaw in the OpenShift AI Service that could enable low-privileged attackers to elevate their permissions to full cluster administrator and compromise the entire platform. With a CVSS v3 base score of 9.9, this vulnerability poses a critical risk for organizations... In "Cybersecurity News - Original News Source is cybersecuritynews.com" A critical use-after-free vulnerability has been discovered in the Linux kernel's netfilter subsystem. This vulnerability could potentially allow local, unprivileged users with CAP_NET_ADMIN capability to escalate their privileges. The flaw, identified in the upstream commit 5f68718b34a5 ("netfilter: nf_tables: GC transaction API to avoid race with control plane"), can cause a... In "Cybersecurity News - Original News Source is cybersecuritynews.com" Kubernetes security has its own shape admission control gating what deploys, network policy governing pod-to-pod traffic, runtime detection watching live workloads, and posture checking cluster configuration across modern multi-cloud security architectures. Sysdig and Aqua lead as specialists, Red Hat ACS owns OpenShift, and this category has the strongest open-source options... In "Cybersecurity News - Original News Source is cybersecuritynews.com"

Open Source For You
Sep 22nd, 2026
CERN pivoting away 2200 computers from Red Hat to Debian.

CERN pivoting away 2200 computers from Red Hat to Debian. September 22, 2026 CERN is transitioning 2200 accelerator control computers from RHEL to Debian by the end of 2026. At MiniDebConf Winterthur, Conseil Européen pour la Recherche Nucléaire/ European Organization for Nuclear Research (CERN) engineers Federico Vaga and Nikos Tsipinakis detailed the organisation's plan for migrating over 2200 particle accelerator control computers and embedded systems from Red Hat Enterprise Linux (RHEL) to Debian 13 ('Trixie') by the end of this year. The primary trigger was Red Hat's progressive tightening of compiler microarchitecture baselines. CERN's accelerator infrastructure manages more than 2200 specialised front-end computers and 17,000 embedded devices. When Red Hat builds RHEL, it picks a minimum central processing unit (CPU) generation the software will run on. RHEL 9's upstream microarchitecture mandates already obsolete CERN's oldest boards, the kind running chips like Intel's legacy Core 2 Duo and Ivy Bridge, which comprise about 47 percent of their fleet. Staying on RHEL would force CERN to replace functional legacy hardware and redesign custom circuit boards at an estimated cost of CHF 5.4 million (US$6.58 million). CERN selected Debian because it supports older 64-bit hardware, offers a massive software library, and works well with industrial tools. Also, built-in real-time updates in the Linux kernel allow Debian to run time-sensitive systems without needing specialized software. The accelerator control group is targeting Debian 13 ('Trixie') with the completion of the migration slated for the fourth quarter of 2026. Both CERN engineers emphasised that the migration is strictly scoped to accelerator control hardware; in other words, CERN's petabyte-sized compute farms and Tier-0 grid infrastructure will continue on AlmaLinux and RHEL.

Global Legal Post
Sep 22nd, 2026
Online education business Coursera hires ex-Red Hat GC as CLO.

Online education business Coursera hires ex-Red Hat GC as CLO. Tom Savage replaces GC Alan Cardenas, who is leaving the company at the end of the year 22 September 2026 Tom Savage Online learning platform Coursera has hired Tom Savage as chief legal officer to replace current legal head Alan Cardenas, who is stepping down later this year. Savage was previously general counsel at software business Red Hat. Greg Hart, CEO of Coursera, said: "[Savage] brings a phenomenal track record and deep experience working with community-focused technology companies, and he'll be a great addition to our leadership team as we continue to scale and serve our learners, customers and partners worldwide." Savage spent more than eight years as GC at Red Hat, latterly as part of IBM. Prior to joining Red Hat, he was GC at semiconductor business Marvell Technology - his first in-house role. Advertisement He was previously a partner at Wilson Sonsini Goodrich & Rosati in Palo Alto, his second stint at the firm following two years as counsel at legacy firm Shearman & Sterling. He started his legal career at Sidley Austin in Chicago. Savage said: "My entire career has been focused on helping technology companies create more opportunities for everyone, and I'm honoured to join Coursera at such a pivotal moment for the company and industry. I look forward to working with the entire leadership team in finding new ways to serve our growing community of learners and customers worldwide, and supporting Coursera's mission in the years ahead." Cardenas, meanwhile, is stepping down after five years with the company, just over three of them as GC. Cardenas will remain as GC until the end of the year to support Savage in his new role. Cardenas said: "Being part of Coursera's journey - through our early months as a public company to the successful close of the Udemy combination - has been one of the most rewarding chapters in my career, particularly the legal team we built along the way to support Coursera's expanding role in the world. LAW OVER BORDERS COMPARATIVE GUIDES The New World of Foreign Direct Investment Law Guide Historic attitudes favouring globalisation are fundamentally changing... | 3yrs. "I'm confident that I'm leaving the team in excellent hands with Tom. I look forward to supporting a smooth transition and spending more time with family before turning to the next chapter of my career." Prior to joining Coursera, Cardenas was head of corporate legal at Siemens Energy, having spent more than a decade at Siemens in a number of legal roles. He previously worked in private practice at Drinker Biddle & Reath and Debevoise & Plimpton. In other education-related in-house moves, back in August AI workforce training platform Skillsoft named former Pegasystems GC Matthew Cushing as CLO, replacing interim legal chief Scott Semel.