Senior Security Engineer

EPAM Systems

Mexico

On-site

PHP 5,016,000 - 7,524,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Healthcare benefits
Paid time off
Upskilling and certification courses
Global career opportunities
Volunteer opportunities

Job summary

EPAM Systems is a global provider of digital platform engineering and development services, seeking a security/privacy compliance professional. You will translate regulatory requirements into engineering work items, track backlog hygiene, and support third-party audits across AWS/Azure environments.

The role involves creating test cases for access control, data retention, and audit logging, and delivering compliance status reports to stakeholders.

Qualifications

  • 3+ years of security/privacy compliance experience (HIPAA/FedRAMP/NIST 800-53).
  • Strong knowledge of HIPAA Security & Privacy Rules and NIST 800-53 controls.
  • Experience translating regulatory language into engineering backlog items in Azure DevOps or Jira.
  • Direct experience supporting third-party audits (SOC 2, FedRAMP, HITRUST).
  • Familiarity with AWS/Azure security controls and IAM/RBAC, encryption, and audit logging.

Responsibilities

  • Translate regulatory and audit requirements into actionable engineering work items with clear acceptance criteria and owners.
  • Track delivery progress and maintain backlog hygiene across compliance features and audit controls.
  • Write and execute test cases to verify access controls, PII minimization, and deletion-on-request.
  • Own end-to-end audit support including intake, tracking, and evidence requests.
  • Produce recurring compliance status reports and lightweight automation for evidence pipelines.

Skills

HIPAA/NIST knowledge
Azure DevOps
Jira
Audit support
Regulatory translation
Cloud security

Tools

Azure DevOps
Jira

Job description

EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.

Responsibilities
  • Translate regulatory and audit requirements into actionable work items by converting HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features, Stories, and Tasks with clear acceptance criteria, effort estimates, and a named owner, such as turning "HIPAA privacy requirements not yet defined" into assignable engineering work
  • Track delivery progress and maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions, closing ownership and sprint-assignment gaps before they escalated into RAID-log risks
  • Write and execute test cases to verify that controls function as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, documenting pass/fail evidence throughout
  • Own the end-to-end audit support process, including intake, tracking, and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews, mapping each request to the relevant NIST 800-53 control, coordinating with engineering, ISRM, Privacy, and Legal to gather artifacts, and delivering on the auditor's schedule
  • Produce recurring compliance status reporting for stakeholders and build lightweight automation, such as scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles as the program expands to new clients and jurisdictions
  • Coordinate across teams, partnering with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure (FedRAMP, SOC 2) versus controls that must be built and owned internally
Requirements
  • A minimum of 3 years of relevant experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
  • Solid working knowledge of the HIPAA Security & Privacy Rules, including administrative, physical, and technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families such as AC, AU, SI, and PM
  • Demonstrated ability to translate compliance and regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
  • Direct experience supporting third-party audits, such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
  • Familiarity with cloud environments, such as AWS GovCloud and/or Azure Government, and the controls relevant to compliance, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletion
  • Excellent English communication skills (B2 level or higher)
Nice to have
  • Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Scripting and automation skills, such as Python or Bash, to automate evidence collection, control testing, or compliance dashboards
  • Experience with AWS IAM/identity governance tooling, such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, and Redshift
  • Exposure to international privacy regimes, such as UK/EU GDPR, Australia's Privacy Act, or Canada's PIPEDA, or readiness to quickly ramp up as coverage expands
  • Relevant certifications, such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
  • Experience with security-scan remediation tracking, using tools such as Snyk, Wiz, Qualys, or Burp, along with experience managing secrets and certificate rotation programs
  • Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data
We offer
  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn

EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

EPAM Systems • Mexico

On-site
PHP 7,524,000 - 11,285,000
Healthcare benefits
Career opportunities
Paid time off
+4
Senior Security & Compliance Engineer - HIPAA/FedRAMP
Senior Security & Compliance Engineer - HIPAA/FedRAMP

EPAM Systems • Mexico

On-site
PHP 5,016,000 - 7,524,000
Healthcare benefits
Paid time off
Upskilling and certification courses
+2
Senior DevOps Cloud Engineer (Azure)
Senior DevOps Cloud Engineer (Azure)

EPAM Systems • Mexico

On-site
PHP 5,643,000 - 8,150,000
Healthcare benefits
Employee financial programs
Paid time off and sick leave
+6
Chief Forward Deployed Engineer
Chief Forward Deployed Engineer

EPAM Systems • Mexico

On-site
PHP 7,524,000 - 11,285,000
Healthcare benefits
Employee financial programs
Paid time off and sick leave
+4
Lead Security & Compliance Engineer for Audits
Lead Security & Compliance Engineer for Audits

EPAM Systems • Mexico

Hybrid
PHP 7,524,000 - 11,285,000
Healthcare benefits
Career opportunities
Paid time off
+4
Lead DevOps Cloud Engineer
Lead DevOps Cloud Engineer

EPAM Systems • Mexico

On-site
PHP 7,524,000 - 11,285,000
Healthcare benefits
Employee financial programs
Paid time off and sick leave
+3
Lead DevOps Engineer
Lead DevOps Engineer

EPAM Systems • Mexico

On-site
PHP 7,524,000 - 11,285,000
Healthcare benefits
Paid time off
Learning & certification opportunities
+2
Senior DevOps Engineer
Senior DevOps Engineer

EPAM Systems • Mexico

On-site
PHP 7,524,000 - 11,285,000
Healthcare benefits
Global projects
Upskilling and certifications
+2
Lead Forward Deployed Engineer
Lead Forward Deployed Engineer

EPAM Systems • Mexico

On-site
PHP 7,524,000 - 11,285,000
Healthcare benefits
Paid time off and sick leave
Upskilling and certification courses
+3
Senior Platform Engineer
Senior Platform Engineer

EPAM Systems • Mexico

On-site
PHP 5,643,000 - 8,150,000