Lead Security Compliance Engineer

EPAM Systems Inc

United States

À distance

USD 120 000 - 210 000

Plein temps

Il y a 41 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’il recherche.

Passez les filtres ATS

Résumé du poste

EPAM Systems Inc. seeks a Lead Security Compliance Engineer to translate regulatory requirements into actionable engineering work, drive audit readiness, and strengthen the compliance posture across HIPAA, FedRAMP, and NIST 800-53 programs.

You will coordinate with engineering, ISRM, Privacy, Legal and cloud teams to ensure controls are implemented, tested, and audit-ready at scale. Responsibilities include turning audit findings into backlog items, maintaining backlog hygiene, writing tests,

Qualifications

  • 3+ years of experience in security/privacy compliance, GRC, or compliance engineering.
  • Strong knowledge of HIPAA Security & Privacy Rules and safeguards.
  • Knowledge of NIST 800-53 control families (AC, AU, SI, PM).
  • Ability to translate regulatory language into backlog items using Azure DevOps or Jira.
  • Experience supporting third-party audits (SOC 2, FedRAMP, HITRUST).
  • Familiarity with cloud environments such as AWS GovCloud or Azure Government.
  • Understanding IAM/RBAC, encryption/KMS, and audit logging.
  • English proficiency at B2 level or higher.
  • Nice to have: FedRAMP SCRs and assessor engagements.
  • Experience with scripting (Python or Bash) to automate evidence collection.

Responsabilités

  • Convert HIPAA gap analyses and audit findings into scoped Azure DevOps features.
  • Maintain backlog hygiene across compliance features (access control, data classification, logging, retention).
  • Close ownership and sprint-assignment gaps to avoid RAID-log risks.
  • Write and execute test cases to verify controls work as designed.
  • Document pass/fail evidence for control testing.
  • Manage intake and fulfillment of auditor evidence requests (Schellman FedRAMP reviews).
  • Map auditor requests to relevant NIST 800-53 controls and coordinate with teams.
  • Deliver evidence and documentation on the auditor's schedule.
  • Produce recurring compliance status reporting for stakeholders.
  • Build lightweight automation, dashboards, and pipelines for future audits.
  • Collaborate with ISRM, Privacy, Legal, SRE, and cloud teams on inherited vs built controls.

Connaissances

Security compliance
GRC experience
Azure DevOps/Jira
Audit readiness
Backlog management
Automation scripting
IAM/RBAC
Encryption/KMS
SailPoint
S3 access governance

Formation

CIPP/US
CIPM
HCISPP
CISA
CISSP
AWS/Azure security cert

Outils

Azure DevOps
Jira
SailPoint
AWS GovCloud
Azure Government

Description du poste

We are seeking a Lead Security Compliance Engineer to translate complex regulatory requirements into actionable engineering work, drive audit readiness, and strengthen compliance posture across HIPAA, FedRAMP, and NIST 800-53 programs. This role bridges the gap between compliance mandates and technical execution, partnering closely with engineering, ISRM, Privacy, Legal, and cloud platform teams to ensure controls are implemented, tested, and audit-ready at scale.

Responsibilities
  • Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria, effort estimates, and a named owner
  • Maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
  • Close ownership and sprint-assignment gaps before they esc ate into RAID-log risks
  • Write and execute test cases to verify controls work as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request
  • Document pass/fail evidence for all control testing activities
  • Own the intake, tracking, and fulfillment of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews
  • Map each auditor request to the relevant NIST 800-53 control and coordinate with engineering, ISRM, Privacy and Legal to gather artifacts
  • Deliver evidence and documentation on the auditor's schedule
  • Produce recurring compliance status reporting for stakeholders
  • Build lightweight automation, including scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles
  • Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure versus controls that must be built or owned internally
Requirements
  • 3+ years of experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
  • Solid working knowledge of HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards
  • Knowledge of NIST 800-53 control families, including AC, AU, SI, and PM
  • Demonstrated ability to translate compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
  • Direct experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
  • Familiarity with cloud environments such as AWS GovCloud and/or Azure Government
  • Understanding of controls that matter for compliance, including IAM/RBAC, encryption/KMS, and audit logging, data retention & deletion
  • English proficiency at B2 level or higher
  • Nice to have
  • Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Skills in scripting/automation using Python or Bash to automate evidence collection, control testing, or compliance dashboards
  • Experience with AWS IAM/identity governance tooling such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, Redshift
  • Exposure to international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or readiness to ramp quickly as coverage expands
  • Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
  • Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, Burp, and secrets/certificate rotation programs
  • Background supporting legal-tech, healthcare, or government SaaS products handling regulated data
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Cloud Security Specialist
Senior Cloud Security Specialist

EPAM Systems Inc • États-Unis

À distance
USD 140 000 - 190 000
Lead Security Engineer
Lead Security Engineer

EPAM Systems, Inc. • États-Unis

À distance
USD 140 000 - 190 000
Healthcare benefits
Paid time off
Upskilling programs
+3
Lead Security & Compliance Engineer
Lead Security & Compliance Engineer

EPAM Systems, Inc. • États-Unis

À distance
USD 140 000 - 190 000
Healthcare benefits
Paid time off
Upskilling programs
+3
Senior Security Engineer
Senior Security Engineer

Prestige Staffing • Georgia

Sur place
USD 140 000 - 200 000
Cybersecurity Compliance Engineer
Cybersecurity Compliance Engineer

iSeatz, Inc. • États-Unis

À distance
USD 90 000 - 130 000
Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • New York (NY)

À distance
USD 170 000 - 240 000
Senior Cloud Security & Compliance Engineer
Senior Cloud Security & Compliance Engineer

EPAM Systems Inc • États-Unis

À distance
USD 140 000 - 190 000
Sr. Cloud Security Engineer (Remote)
Sr. Cloud Security Engineer (Remote)

inspiracareers • Oak Brook (IL)

Hybride
USD 160 000 - 190 000
Security Compliance Engineer
Security Compliance Engineer

ANAUTICS INC • Oklahoma City (OK)

Sur place
USD 80 000 - 100 000
Lead Security Compliance Engineer - HIPAA, FedRAMP, NIST
Lead Security Compliance Engineer - HIPAA, FedRAMP, NIST

EPAM Systems Inc • États-Unis

À distance
USD 120 000 - 210 000