Senior/Lead Security Engineer - HIPPA

schedule10 days ago
trending_upExperience level:Lead
historyMinimum experience:6+ years
Apply Nowopen_in_new

Job description

We're looking for a Senior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, converting regulatory mandates into concrete engineering tasks while facilitating third-party audits and collaborating across security, privacy, and legal functions.

Responsibilities

  • Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with defined acceptance criteria, effort estimates, and a designated owner
  • Keep the backlog organized across ongoing compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
  • Develop and run test cases to confirm controls function as intended, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, then document pass/fail results
  • Manage the intake, tracking, and completion of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews
  • Link each audit request to its corresponding NIST 800-53 control and work with engineering, ISRM, Privacy, and Legal to collect artifacts and meet the auditor's timeline
  • Generate ongoing compliance status reports for stakeholders
  • Create simple automation tools, such as scripts, dashboards, and evidence pipelines, to cut down manual work in future audits as the program expands to new clients and jurisdictions
  • Collaborate with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document which controls are inherited from AWS/Azure versus those that must be developed or maintained internally

Requirements

  • 6-15 years of overall IT experience
  • Background in security/privacy compliance, GRC, or compliance engineering, with support for HIPAA and/or FedRAMP/NIST 800-53 programs
  • Understanding of the HIPAA Security & Privacy Rules, covering administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families such as AC, AU, SI, and PM
  • Proven ability to convert compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar platforms
  • Hands-on experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including gathering evidence, mapping controls to evidence, and meeting auditor deadlines
  • Knowledge of cloud environments such as AWS GovCloud and/or Azure Government, plus controls including IAM/RBAC, encryption/KMS, audit logging, and data retention & deletion

Nice to have

  • Hands-on experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Scripting/automation skills using Python or Bash to automate evidence collection, control testing, or compliance dashboards
  • Experience with AWS IAM/identity governance tools such as SailPoint or equivalent, and managing access policies across S3, RDS, DynamoDB, and Redshift
  • Understanding of international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or the ability to quickly learn as coverage expands
  • Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
  • Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, or Burp, along with secrets/certificate rotation programs
  • Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data

Benefits

Opportunity to work on technical challenges that may impact across geographies

Vast opportunities for self-development: online university, knowledge sharing opportunities globally, learning opportunities through external certifications

Opportunity to share your ideas on international platforms

Sponsored Tech Talks & Hackathons

Unlimited access to LinkedIn learning solutions

Possibility to relocate to any EPAM office for short and long-term projects

Focused individual development

Benefit package:

  • Health benefits
  • Retirement benefits
  • Paid time off
  • Flexible benefits

Forums to explore beyond work passion (CSR, photography, painting, sports, etc.)

Skills mentioned

Apply for this job

Use the application link supplied with this listing to apply to EPAM Systems. Check the destination before entering personal information.

Apply Nowopen_in_new