Senior Cloud Security Specialist

EPAM Systems Inc

United States

Remote

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

EPAM Systems seeks a Senior Cloud Security Specialist to lead compliance engineering across HIPAA and FedRAMP/NIST 800-53 programs, translating regulatory requirements into engineering work while supporting audits and cross-functional initiatives.

Responsibilities include turning gap analyses into Azure DevOps items, maintaining backlog hygiene for access control and data handling, coordinating with ISRM, Privacy, and Legal, and delivering evidence to auditors.

Qualifications

  • 3+ years in security/privacy compliance, GRC, or compliance engineering in HIPAA/FedRAMP/NIST contexts.
  • Knowledge of HIPAA Security & Privacy Rules and NIST 800-53 control families.
  • Ability to map regulatory language to scoped engineering backlog items.

Responsibilities

  • Convert HIPAA gap analyses and NIST controls into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria.
  • Maintain backlog hygiene for access control, data classification, logging, retention, and deletion.
  • Coordinate with ISRM, Privacy, Legal to gather artifacts for audits.
  • Write and execute test cases to verify controls, including privileged access restrictions and PII minimization.
  • Deliver auditor evidence and status updates; build automation to streamline future cycles.

Skills

Scripting (Python or Bash)
Regulatory compliance
Audit readiness
Cross-functional collaboration
Cloud security

Education

Certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP or AWS/Azure security cert

Tools

Azure DevOps
Jira
SailPoint
Snyk
Qualys
Burp

Job description

We are seeking a Senior Cloud Security Specialist to lead compliance engineering efforts across HIPAA and FedRAMP/NIST 800-53 programs, translating regulatory requirements into actionable engineering work while supporting third-party audits and cross‑functional compliance initiatives.

Responsibilities
  • Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria, effort estimates, and a named owner
  • Maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
  • Close ownership and sprint‑assignment gaps before they escalatE into RAID‑log risks
  • Write and execute test cases to verify controls work as designed, such as privileged‑access restrictions, time‑bound SailPoint access, PII minimization, and deletion‑on‑request
  • Document pass/fail evidence for control testing activities
  • Own the intake, tracking, and fulfillment of third‑party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews
  • Map each auditor request to the relevant NIST 800-53 control and coordinate with engineering, ISRM, Privacy, and Legal to gather artifacts
  • Deliver evidence and documentation on the auditor's schedule
  • Produce recurring compliance status reporting for stakeholders
  • Build lightweight automation, including scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles
  • Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure versus controls that must be built or owned internally
Requirements
  • 3+ years of experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
  • Knowledge of the HIPAA Security & Privacy Rules, including administrative, physical, and technical safeguards, BAAs, breach notification, and minimum necessary standards
  • Understanding of NIST 800-53 control families, such as AC, AU, SI, and PM
  • Demonstrated ability to turn compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
  • Direct experience supporting third‑party audits such as SOC2, FedRAMP, or HITRUST, including evidence collection, control‑to‑evidence mapping, and meeting auditor deadlines
  • Familiarity with cloud environments such as AWS GovCloud and/or Azure Government
  • Knowledge of compliance‑relevant controls, including IAM/RBAC, encryption/KMS, and audit logging, as well as data retention & deletion practices
  • English proficiency at B2 level or higher
  • Nice to have Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Skills in scripting/automation using Python or Bash to automate evidence collection, control testing, or compliance dashboards
  • Experience with AWS IAM/identity governance tooling such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, and Redshift
  • Familiarity with international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or readiness to ramp quickly as coverage expands
  • Relevant certifications such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
  • Experience with security‑scan remediation tracking using tools such as Snyk, Wiz, Qualys, or Burp, and secrets/certificate rotation programs
  • Background supporting legal‑tech, healthcare, or government SaaS products handling regulated data
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • New York (NY)

Remote
USD 170,000 - 240,000
Senior Cloud Security & Compliance Engineer
Senior Cloud Security & Compliance Engineer

EPAM Systems Inc • United States

Remote
USD 140,000 - 190,000
Senior DevSecOps Engineer (Azure)
Senior DevSecOps Engineer (Azure)

The Judge Group • Chicago (IL)

On-site
USD 150,000 - 190,000
Sr. Cloud Security Engineer (Remote)
Sr. Cloud Security Engineer (Remote)

inspiracareers • Oak Brook (IL)

Hybrid
USD 160,000 - 190,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Maestro Technologies, Inc. • Santa Monica (CA)

Hybrid
USD 150,000 - 210,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Healthmark Group • United States

Remote
USD 150,000 - 210,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 145,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Mbi Llc • Mechanicsburg

On-site
USD 100,000 - 130,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Eleven Recruiting • Santa Monica (CA)

On-site
USD 140,000 - 190,000
Security Software Engineer
Security Software Engineer

Eccalon, LLC • Hanover (MD)

On-site
USD 120,000 - 190,000