We are looking for a Senior Security Engineer to join our team. We need an Engineer who can sit at the intersection of compliance/legal requirements and engineering delivery: reading raw regulatory or audit requirements, scoping them into concrete technical work, tracking that work to closure, and running the evidence-collection process for external audits. This program will expand over time to cover additional government and commercial-regulated clients, plus country-specific privacy regimes (UK, EU, Australia, Canada).ResponsibilitiesTranslate regulatory and audit requirements into actionable work items by converting HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features, Stories, and Tasks with clear acceptance criteria, effort estimates, and a named owner, such as turning \"HIPAA privacy requirements not yet defined\" into assignable engineering workTrack delivery progress and maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions, closing ownership and sprint-assignment gaps before they escalate into RAID-log risksWrite and execute test cases to verify that controls function as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, documenting pass/fail evidence throughoutOwn the end-to-end audit support process, including intake, tracking, and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews, mapping each request to the relevant NIST 800-53 control, coordinating with engineering, ISRM, Privacy, and Legal to gather artifacts, and delivering on the auditor's scheduleProduce recurring compliance status reporting for stakeholders and build lightweight automation, such as scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles as the program expands to new clients and jurisdictionsCoordinate across teams, partnering with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure (FedRAMP, SOC 2) versus controls that must be built and owned internallyRequirementsA minimum of 3 years of relevant experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programsSolid working knowledge of the HIPAA Security & Privacy Rules, including administrative, physical, and technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families such as AC, AU, SI, and PMDemonstrated ability to translate compliance and regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar toolsDirect experience supporting third-party audits, such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlinesFamiliarity with cloud environments, such as AWS GovCloud and/or Azure Government, and the controls relevant to compliance, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletionExcellent English communication skills (B2 level or higher)Nice to haveDirect experience with FedRAMP Significant Change Requests (SCR) and assessor engagementsScripting and automation skills, such as Python or Bash, to automate evidence collection, control testing, or compliance dashboardsExperience with AWS IAM/identity governance tooling, such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, and RedshiftExposure to international privacy regimes, such as UK/EU GDPR, Australia's Privacy Act, or Canada's PIPEDA, or readiness to quickly ramp up as coverage expandsRelevant certifications, such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certificationExperience with security-scan remediation tracking, using tools such as Snyk, Wiz, Qualys, or Burp, along with experience managing secrets and certificate rotation programsBackground supporting legal-tech, healthcare, or government SaaS products that handle regulated dataWe offerInternational projects with top brandsWork with global teams of highly skilled, diverse peersHealthcare benefitsEmployee financial programsPaid time off and sick leaveUpskilling, reskilling and certification coursesUnlimited access to the LinkedIn Learning library and 22,000+ coursesGlobal career opportunitiesVolunteer and community involvement opportunitiesEPAM Employee GroupsAward-winning culture recognized by Glassdoor, Newsweek and LinkedInEPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.