Security & Compliance Engineer - HIPAA/NIST Audits

Enfint

United States

Remote

USD 110,000 - 165,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

EPAM ищет специалиста по безопасности и соответствию для поддержки HIPAA и FedRAMP/NIST 800-53. Вы будете конвертировать результаты аудита в scoped Azure DevOps Features, Stories и Tasks с критериями приемки, оценками усилий и назначенными владельцами.

Кроме того, вы будете поддерживать backlog по требованиям доступа, классификации данных, журналированию и хранению данных, готовить evidences и координировать взаимодействие с командами ISRM, Privacy, Legal и SRE, чтобы удовлетворять аудиторам.

Qualifications

  • 3+ года опыта в области безопасности/соответствия, GRC или инженерного обеспечения соответствия HIPAA и/или FedRAMP/NIST 800-53.
  • Знание HIPAA Security и Privacy Rules, включая административные, физические и технические меры, BAAs, уведомления о нарушениях и минимальные требования.
  • Понимание семейств контролей NIST 800-53, включая AC, AU, SI и PM.
  • Умение переводить регуляторный язык в чётко оцениваемые backlog-элементы через Azure DevOps, Jira или подобные инструменты.
  • Опыт поддержки аудитов сторонних организаций (SOC 2, FedRAMP, HITRUST), включая сбор доказательств, привязку контроля к доказательствам и соблюдение сроков.
  • Знание облачных сред AWS GovCloud и/или Azure Government.
  • Знание контролей по соответствию: IAM/RBAC, шифрование/KMS, аудит-логирование, хранение и удаление данных.
  • Уровень английского не ниже B2.
  • Наличие: опыт SCR FedRAMP Significant Change, скрипты/автоматизация Python или Bash, SailPoint, управление доступами (S3, RDS, DynamoDB, Redshift), знание GDPR/Privacy Act/Australia Privacy Act, сертификаты CIPP/US, CIPM, HCISPP, CISA, CISSP, или AWS/Azure security.

Responsibilities

  • Convert HIPAA gap analyses, NIST 800-53 controls into scoped Azure DevOps Features, Stories, and Tasks with acceptance criteria, effort estimates, and named owners.
  • Maintain backlog hygiene across compliance features covering access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions.
  • Close ownership and sprint-assignment gaps before they escape into RAID-log risks.
  • Write and execute test cases to verify controls such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request.
  • Document pass/fail evidence for control testing activities.
  • Own intake, tracking, and fulfillment of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews.
  • Map auditor requests to relevant NIST 800-53 controls and coordinate with engineering, ISRM, Privacy, and Legal to gather artifacts.
  • Deliver evidence and documentation according to the auditor's schedule.
  • Produce recurring compliance status reports for stakeholders.
  • Build lightweight automation, including scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles.
  • Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure and controls that must be built or owned internally.

Skills

HIPAA compliance
NIST 800-53
GRC
Audits
Documentation
FedRAMP
SOC 2
English (B2+)
Cloud knowledge

Tools

Azure DevOps
Jira

Job description

EPAM ищет специалиста по безопасности и соответствию для поддержки HIPAA и FedRAMP/NIST 800-53. Вы будете конвертировать результаты аудита в scoped Azure DevOps Features, Stories и Tasks с критериями приемки, оценками усилий и назначенными владельцами.

Кроме того, вы будете поддерживать backlog по требованиям доступа, классификации данных, журналированию и хранению данных, готовить evidences и координировать взаимодействие с командами ISRM, Privacy, Legal и SRE, чтобы удовлетворять аудиторам.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Security Governance Engineer
AI Security Governance Engineer

Enfint • United States

Remote
USD 120,000 - 160,000
Remote IT Security Administrator - Audits & Compliance
Remote IT Security Administrator - Audits & Compliance

Signature Performance • Columbus (OH)

Remote
USD 80,000 - 100,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil‌
+5
AI-Driven Business Analyst - Remote (Ukraine)
AI-Driven Business Analyst - Remote (Ukraine)

Enfint • United States

Remote
USD 90,000 - 120,000
Remote IT Security & Compliance Administrator
Remote IT Security & Compliance Administrator

Signature Performance • Boise (ID)

Remote
USD 80,000 - 100,000
Health Insurance
401(k) with Employer Match
Paid Vacation
+5
Azure Platform & Security Engineer — SOC 2 & HIPAA Ready
Azure Platform & Security Engineer — SOC 2 & HIPAA Ready

Highlight Health • Philadelphia

On-site
USD 140,000 - 180,000
Senior Web Analytics & Data Insights Analyst
Senior Web Analytics & Data Insights Analyst

Enfint • United States

Remote
USD 90,000 - 130,000
Remote Staff Security Engineer: Cloud & AppSec Leader
Remote Staff Security Engineer: Cloud & AppSec Leader

FirstMessage • United States

Remote
USD 140,000 - 200,000
Senior Compliance Engineer: GDPR, PCI DSS & Audit Lead
Senior Compliance Engineer: GDPR, PCI DSS & Audit Lead

Estuary • United States

On-site
USD 160,000 - 210,000
Remote Senior Cloud Security Engineer (HIPAA)
Remote Senior Cloud Security Engineer (HIPAA)

Healthmark Group • United States

Remote
USD 150,000 - 210,000
DevSecOps Engineer – Secure AWS & Compliance
DevSecOps Engineer – Secure AWS & Compliance

Magpie Health Analytics, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000