Lead Security Engineer

EPAM Systems

Argentina

Presencial

ARS 181.190.000 - 241.586.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Healthcare benefits
Paid time off
LinkedIn Learning access
Global career opportunities
Volunteer and community involvement
Employee financial programs

Descripción de la vacante

EPAM Systems seeks a Lead Security Engineer to bridge compliance and hands-on engineering, translating regulatory language into actionable backlogs, and driving evidence gathering for external audits.

You will own audits with SOC 2, FedRAMP, HIPAA, and NIST controls, convert findings into Azure DevOps stories, coordinate across ISRM, Privacy, Legal, and cloud platform teams, and implement automated dashboards to streamline future cycles.

Formación

  • 5+ years in security/privacy compliance or GRC roles.
  • 1+ year of leading and managing teams.
  • Experience with HIPAA and FedRAMP/NIST 800-53.
  • Ability to translate regulatory text into engineering work.
  • Experience supporting third-party audits (SOC 2, FedRAMP, HITRUST).
  • Experience with AWS/Azure gov clouds and IAM/RBAC controls.

Responsabilidades

  • Convert regulatory language into concrete backlog items with acceptance criteria.
  • Monitor delivery progress and maintain backlog for compliance initiatives.
  • Develop and run test cases for controls (e.g., privileged access limits, data retention).
  • Manage audit support lifecycle and evidence requests with auditors.
  • Generate compliance status updates and automate evidence pipelines.
  • Collaborate with ISRM, Privacy, Legal, SRE, and cloud teams to document controls.

Conocimientos

HIPAA/NIST 800-53 know-how
Audit & evidence gathering
Azure DevOps
Jira
Team leadership
Compliance engineering
Cloud security controls
Communications

Herramientas

Azure DevOps
Jira
SailPoint

Descripción del empleo

We are looking for a Lead Security Engineer to join our team. This role sits at the crossroads of legal/compliance obligations and hands-on engineering execution - interpreting raw regulatory or audit language, breaking it down into actionable technical tasks, driving that work through to completion, and managing the evidence-gathering process for external audits. Over time, this program will grow to encompass additional government and commercially regulated clients, as well as country-specific privacy frameworks across the UK, EU, Australia, and Canada.

Responsibilities
  • Convert regulatory and audit language into concrete, actionable backlog items by transforming HIPAA gap assessments, NIST 800-53 privacy controls, and audit findings into well-defined Azure DevOps Features, Stories, and Tasks complete with acceptance criteria, effort estimates, and assigned ownership, such as reshaping "HIPAA privacy requirements not yet defined" into a clear engineering deliverable
  • Monitor delivery progress and keep the backlog organized across live compliance initiatives, including access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions, closing gaps in ownership or sprint planning before they turn into RAID-log issues
  • Develop and run test cases confirming that controls operate as intended, such as privileged-access limitations, time-bound SailPoint access, PII minimization, and deletion-on-request functionality, capturing pass/fail results as supporting documentation
  • Manage the complete audit support lifecycle, from intake through tracking and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews, linking each request to its corresponding NIST 800-53 control, working with engineering, ISRM, Privacy, and Legal to compile artifacts, and meeting the auditor's timeline
  • Generate ongoing compliance status updates for stakeholders and develop streamlined automation, including scripts, dashboards, and evidence pipelines, to cut down on manual work in future audit cycles as the program grows to serve new clients and regions
  • Collaborate across departments, working with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to distinguish and document controls inherited from AWS/Azure (FedRAMP, SOC 2) versus those requiring internal ownership and development
Requirements
  • At least 5 years of relevant experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 initiatives
  • A minimum of one year of experience leading and managing teams
  • Strong familiarity with the HIPAA Security & Privacy Rules, covering administrative, physical, and technical safeguards, BAAs, breach notification requirements, and minimum necessary principles, as well as NIST 800-53 control families such as AC, AU, SI, and PM
  • Proven capability to convert compliance and regulatory text into scoped, estimable engineering backlog items using platforms like Azure DevOps, Jira, or similar
  • Hands-on experience supporting third-party audits, including SOC 2, FedRAMP, or HITRUST, covering evidence gathering, mapping controls to evidence, and meeting auditor timelines
  • Working knowledge of cloud environments, such as AWS GovCloud and/or Azure Government, along with compliance-relevant controls, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletion practices
  • Excellent English communication skills (B2 level or higher)
Nice to have
  • Hands-on experience with FedRAMP Significant Change Requests (SCR) and working directly with assessors
  • Ability to script and automate tasks using Python or Bash to streamline evidence gathering, control testing, or compliance dashboard creation
  • Experience with AWS IAM and identity governance platforms, such as SailPoint or similar tools, along with managing access policies across S3, RDS, DynamoDB, and Redshift
  • Familiarity with international privacy regulations, such as UK/EU GDPR, Australia's Privacy Act, or Canada's PIPEDA, or willingness to quickly develop expertise as the program's scope broadens
  • Relevant industry certifications, such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or a security certification from AWS or Azure
  • Experience tracking remediation from security scanning tools, such as Snyk, Wiz, Qualys, or Burp, along with managing programs for secrets and certificate rotation
  • Prior experience supporting legal-tech, healthcare, or government SaaS platforms that manage regulated data
We offer
  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Security Engineer
Senior Security Engineer

EPAM Systems • Argentina

Presencial
ARS 1.200.000 - 2.400.000
Healthcare benefits
Paid time off and sick leave
Upskilling and certifications
+3
Lead DevOps Engineer
Lead DevOps Engineer

EPAM Systems • Argentina

Presencial
ARS 2.000.000 - 5.000.000
Healthcare benefits
Employee financial programs
Paid time off and sick leave
+1
Lead Security & Compliance Engineer (Audit & GRC)
Lead Security & Compliance Engineer (Audit & GRC)

EPAM Systems • Argentina

Presencial
ARS 181.190.000 - 241.586.000
Healthcare benefits
Paid time off
LinkedIn Learning access
+3
Lead Scala/Java Developer
Lead Scala/Java Developer

EPAM Systems • Argentina

Presencial
ARS 1.800.000 - 3.200.000
Healthcare benefits
Global career opportunities
Paid time off
+1
Lead Cloud Engineer (AWS)
Lead Cloud Engineer (AWS)

EPAM Systems • Argentina

Presencial
ARS 1.200.000 - 1.800.000
Healthcare benefits
Paid time off
Upskilling and certification courses
+2
Senior Platform Engineer
Senior Platform Engineer

EPAM Systems • Argentina

Presencial
ARS 2.400.000 - 4.200.000
Healthcare benefits
Learning & development
LinkedIn Learning access
+2
Lead Platform Engineer
Lead Platform Engineer

EPAM Systems • Argentina

Presencial
ARS 135.892.000 - 211.388.000
Healthcare benefits
Employee financial programs
Paid time off and sick leave
+3
Data Engineering & Infrastructure Lead ID88014
Data Engineering & Infrastructure Lead ID88014

AgileEngine • Mar del Plata

Híbrido
ARS 9.999.999.999
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Data Engineering & Infrastructure Lead ID88014
Data Engineering & Infrastructure Lead ID88014

AgileEngine • Rosario

Presencial
ARS 90.595.000 - 150.991.000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Senior Data Software Engineer
Senior Data Software Engineer

EPAM Systems • Argentina

Presencial
ARS 1.200.000 - 1.800.000
Healthcare benefits
Paid time off
Upskilling
+5