Lead Security Engineer

EPAM Systems, Inc.

México

A distancia

MXN 900.000 - 1.300.000

Jornada completa

Hace 3 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca la empresa.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Healthcare benefits
Paid time off
Upskilling & certification courses
LinkedIn Learning access
Global career opportunities
Volunteer opportunities

Descripción de la vacante

EPAM Systems, Inc. is seeking a Lead Security Engineer to bridge legal and compliance requirements with hands-on engineering. You will translate HIPAA/NIST 800-53 language into Azure DevOps items, drive completion, and gather evidence for external audits.

You will shape IAM, data retention, encryption, and log management controls, collaborating with ISRM, Privacy, Legal, and cloud platform teams to scale the program across regions and clients while maintaining clear stakeholder communications.

Formación

  • 5+ years in security/privacy compliance, GRC, or compliance engineering.
  • Experience leading teams and coordinating audits (SOC 2, FedRAMP, HITRUST).
  • Ability to map regulatory text to engineering backlog items and backlogs in Azure DevOps/Jira.

Responsabilidades

  • Convert regulatory/audit language into actionable backlog items with clear acceptance criteria and ownership.
  • Monitor backlog progress and maintain alignment across access control, data classification, log scrubbing, audit logging, retention, and deletion.
  • Develop and run test cases to verify controls; manage evidence for third-party audits.
  • Manage end-to-end audit support lifecycle and produce status updates for stakeholders.

Conocimientos

Regulatory translation
Backlog management
Audit readiness
Stakeholder communication
Security engineering
Leadership
Test case execution

Herramientas

Azure DevOps
Jira
SailPoint
AWS GovCloud
Azure Government

Descripción del empleo

We are looking for a Lead Security Engineer to join our team. This role sits at the crossroads of legal/compliance obligations and hands-on engineering execution - interpreting raw regulatory or audit language, breaking it down into actionable technical tasks, driving that work through to completion, and managing the evidence-gathering process for external audits. Over time, this program will grow to encompass additional government and commercially regulated clients, as well as country-specific privacy frameworks across the UK, EU, Australia, and Canada.ResponsibilitiesConvert regulatory and audit language into concrete, actionable backlog items by transforming HIPAA gap assessments, NIST 800-53 privacy controls, and audit findings into well-defined Azure DevOps Features, Stories, and Tasks complete with acceptance criteria, effort estimates, and assigned ownership, such as reshaping \"HIPAA privacy requirements not yet defined\" into a clear engineering deliverableMonitor delivery progress and keep the backlog organized across live compliance initiatives, including access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions, closing gaps in ownership or sprint planning before they turn into RAID-log issuesDevelop and run test cases confirming that controls operate as intended, such as privileged-access limitations, time-bound SailPoint access, PII minimization, and deletion-on-request functionality, capturing pass/fail results as supporting documentationManage the complete audit support lifecycle, from intake through tracking and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews, linking each request to its corresponding NIST 800-53 control, working with engineering, ISRM, Privacy, and Legal to compile artifacts, and meeting the auditor's timelineGenerate ongoing compliance status updates for stakeholders and develop streamlined automation, including scripts, dashboards, and evidence pipelines, to cut down on manual work in future audit cycles as the program grows to serve new clients and regionsCollaborate across departments, working with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to distinguish and document controls inherited from AWS/Azure (FedRAMP, SOC 2) versus those requiring internal ownership and developmentRequirementsAt least 5 years of relevant experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 initiativesA minimum of one year of experience leading and managing teamsStrong familiarity with the HIPAA Security & Privacy Rules, covering administrative, physical, and technical safeguards, BAAs, breach notification requirements, and minimum necessary principles, as well as NIST 800-53 control families such as AC, AU, SI, and PMProven capability to convert compliance and regulatory text into scoped, estimable engineering backlog items using platforms like Azure DevOps, Jira, or similarHands-on experience supporting third-party audits, including SOC 2, FedRAMP, or HITRUST, covering evidence gathering, mapping controls to evidence, and meeting auditor timelinesWorking knowledge of cloud environments, such as AWS GovCloud and/or Azure Government, along with compliance-relevant controls, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletion practicesExcellent English communication skills (B2 level or higher)Nice to haveHands-on experience with FedRAMP Significant Change Requests (SCR) and working directly with assessorsAbility to script and automate tasks using Python or Bash to streamline evidence gathering, control testing, or compliance dashboard creationExperience with AWS IAM and identity governance platforms, such as SailPoint or similar tools, along with managing access policies across S3, RDS, DynamoDB, and RedshiftFamiliarity with international privacy regulations, such as UK/EU GDPR, Australia's Privacy Act, or Canada's PIPEDA, or willingness to quickly develop expertise as the program's scope broadensRelevant industry certifications, such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or a security certification from AWS or AzureExperience tracking remediation from security scanning tools, such as Snyk, Wiz, Qualys, or Burp, along with managing programs for secrets and certificate rotationPrior experience supporting legal-tech, healthcare, or government SaaS platforms that manage regulated dataWe offerInternational projects with top brandsWork with global teams of highly skilled, diverse peersHealthcare benefitsEmployee financial programsPaid time off and sick leaveUpskilling, reskilling and certification coursesUnlimited access to the LinkedIn Learning library and 22,000+ coursesGlobal career opportunitiesVolunteer and community involvement opportunitiesEPAM Employee GroupsAward-winning culture recognized by Glassdoor, Newsweek and LinkedInEPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Lead Security Engineer: Compliance & Audit Programs
Lead Security Engineer: Compliance & Audit Programs

EPAM Systems, Inc. • México

A distancia
MXN 900.000 - 1.300.000
Healthcare benefits
Paid time off
Upskilling & certification courses
+3
Lead DevOps Engineer
Lead DevOps Engineer

EPAM Systems, Inc. • México

A distancia
MXN 900.000 - 1.500.000
Healthcare benefits
Learning and development
Global career opportunities
+1
Chief DevOps Engineer
Chief DevOps Engineer

EPAM Systems, Inc. • México

A distancia
MXN 1.200.000 - 2.000.000
Healthcare benefits
Employee financial programs
Paid time off
+3
Senior IAM Engineer
Senior IAM Engineer

EPAM Systems, Inc. • México

A distancia
MXN 800.000 - 1.200.000
Healthcare benefits
Paid time off
LinkedIn Learning access
+2
IAM Security Engineer
IAM Security Engineer

EPAM Systems, Inc. • México

A distancia
MXN 420.000 - 780.000
Healthcare benefits
Paid time off
Learning & certification budget
+1
Lead Application Security Engineer
Lead Application Security Engineer

EPAM Systems, Inc. • México

A distancia
MXN 700.000 - 900.000
Healthcare benefits
Paid time off
Sick leave
+1
Chief Forward Deployed Engineer
Chief Forward Deployed Engineer

EPAM Systems, Inc. • México

A distancia
MXN 1.800.000 - 2.400.000
Healthcare benefits
Paid time off
Career development opportunities
Lead Fullstack Developer (JavaScript)
Lead Fullstack Developer (JavaScript)

EPAM Systems, Inc. • México

A distancia
MXN 900.000 - 1.500.000
Healthcare benefits
Paid time off
LinkedIn Learning access
+1
Senior Security Engineer
Senior Security Engineer

EPAM Systems, Inc. • México

A distancia
MXN 900.000 - 1.300.000
Healthcare benefits
Paid time off and sick leave
Upskilling, reskilling and certificate
+3
Senior DevOps Engineer
Senior DevOps Engineer

EPAM Systems, Inc. • México

A distancia
MXN 600.000 - 1.000.000