Senior Security Engineer

EPAM Systems

Colombia

Presencial

COP 186.347.000 - 341.636.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Healthcare benefits
Paid time off
Upskilling & certification
Global career opportunities
Volunteer opportunities

Descripción de la vacante

EPAM Systems, a leading global provider of digital platform engineering and development services, seeks a security/privacy compliance engineer in Colombia. You will translate regulatory requirements into scoped engineering work, track progress across HIPAA, FedRAMP, and NIST controls, and support third-party audits with evidence mapping.

You will collaborate with ISRM, Privacy Office, Legal, and cloud teams to ensure controls are implemented, tested, and documented, enabling timely auditor

Formación

  • 3+ years in security/privacy compliance, GRC, or compliance engineering (HIPAA and FedRAMP/NIST 800-53).
  • Knowledge of HIPAA Security/Privacy Rules and NIST 800-53 families (AC, AU, SI, PM).
  • Ability to translate regulatory language into estimable engineering backlog items (Azure DevOps/Jira).
  • Experience supporting third-party audits (SOC 2, FedRAMP, HITRUST) with evidence mapping.
  • Familiarity with AWS GovCloud or Azure Government and IAM/RBAC, encryption, audit logs.

Responsabilidades

  • Translate regulatory requirements into actionable DevOps work items with clear acceptance criteria.
  • Track delivery progress and maintain backlog hygiene across compliance features.
  • Write and execute test cases to verify controls and evidence.
  • Coordinate with ISRM, Privacy, Legal to gather artifacts for audits.
  • Produce recurring compliance status reports and build lightweight automation.

Conocimientos

Security compliance
GRC
Audit support
Azure DevOps/Jira
Cloud security
English B2+

Herramientas

Azure DevOps
Jira
SailPoint

Descripción del empleo

EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.

Responsibilities
  • Translate regulatory and audit requirements into actionable work items by converting HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features, Stories, and Tasks with clear acceptance criteria, effort estimates, and a named owner, such as turning "HIPAA privacy requirements not yet defined" into assignable engineering work
  • Track delivery progress and maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions, closing ownership and sprint-assignment gaps before they escalated into RAID-log risks
  • Write and execute test cases to verify that controls function as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, documenting pass/fail evidence throughout
  • Own the end-to-end audit support process, including intake, tracking, and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews, mapping each request to the relevant NIST 800-53 control, coordinating with engineering, ISRM, Privacy, and Legal to gather artifacts, and delivering on the auditor's schedule
  • Produce recurring compliance status reporting for stakeholders and build lightweight automation, such as scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles as the program expands to new clients and jurisdictions
  • Coordinate across teams, partnering with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure (FedRAMP, SOC 2) versus controls that must be built and owned internally
Requirements
  • A minimum of 3 years of relevant experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
  • Solid working knowledge of the HIPAA Security & Privacy Rules, including administrative, physical, and technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families such as AC, AU, SI, and PM
  • Demonstrated ability to translate compliance and regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
  • Direct experience supporting third-party audits, such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
  • Familiarity with cloud environments, such as AWS GovCloud and/or Azure Government, and the controls relevant to compliance, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletion
  • Excellent English communication skills (B2 level or higher)
Nice to have
  • Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Scripting and automation skills, such as Python or Bash, to automate evidence collection, control testing, or compliance dashboards
  • Experience with AWS IAM/identity governance tooling, such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, and Redshift
  • Exposure to international privacy regimes, such as UK/EU GDPR, Australia's Privacy Act, or Canada's PIPEDA, or readiness to quickly ramp up as coverage expands
  • Relevant certifications, such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
  • Experience with security-scan remediation tracking, using tools such as Snyk, Wiz, Qualys, or Burp, along with experience managing secrets and certificate rotation programs
  • Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data
We offer
  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn

EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Lead Security Engineer
Lead Security Engineer

EPAM Systems • Colombia

Presencial
COP 120.000.000 - 180.000.000
Healthcare benefits
Global career opportunities
LinkedIn Learning access
Senior DevOps Cloud Engineer (Azure)
Senior DevOps Cloud Engineer (Azure)

EPAM Systems • Colombia

Presencial
COP 240.000.000 - 360.000.000
Healthcare benefits
Learning & development
Global career opportunities
+2
Chief Forward Deployed Engineer
Chief Forward Deployed Engineer

EPAM Systems • Colombia

Presencial
COP 186.347.000 - 372.694.000
Healthcare benefits
Paid time off
Global career opportunities
+1
Senior DevOps Engineer
Senior DevOps Engineer

EPAM Systems • Colombia

Presencial
COP 120.000.000 - 180.000.000
Healthcare benefits
Paid time off
Upskilling and certification
+2
Lead DevOps Cloud Engineer
Lead DevOps Cloud Engineer

EPAM Systems • Colombia

Presencial
COP 180.000.000 - 300.000.000
Healthcare benefits
Employee financial programs
Paid time off
+5
Lead Security Engineer: Compliance & Audit Delivery
Lead Security Engineer: Compliance & Audit Delivery

EPAM Systems • Colombia

Presencial
COP 120.000.000 - 180.000.000
Healthcare benefits
Global career opportunities
LinkedIn Learning access
Lead DevOps Engineer
Lead DevOps Engineer

EPAM Systems • Colombia

Presencial
COP 156.240.000 - 267.840.000
Healthcare benefits
Paid time off
Learning & development resources
+1
Lead Forward Deployed Engineer
Lead Forward Deployed Engineer

EPAM Systems • Colombia

A distancia
COP 310.578.000 - 527.983.000
Healthcare benefits
Paid time off
Upskilling & certifications
+3
Senior Platform Engineer
Senior Platform Engineer

EPAM Systems • Colombia

Presencial
COP 120.000.000 - 180.000.000
Healthcare benefits
Employee financial programs
Paid time off and sick leave
+2
Senior Security Engineer, Compliance & Audit
Senior Security Engineer, Compliance & Audit

EPAM Systems • Colombia

Presencial
COP 186.347.000 - 341.636.000
Healthcare benefits
Paid time off
Upskilling & certification
+2