ES
Senior/Lead Security Engineer - HIPPA
EPAM Systems
๐ฎ๐ณ India
On-site
Staff / Principal
1 day ago
- HIPAA
- FedRAMP
- NIST
- Azure DevOps
- SailPoint
- AWS
- Azure
- Jira
- SOC2
- HITRUST
- AWS GovCloud
- Azure Government
- IAM
- RBAC
- KMS
- Python
- Bash
- AWS IAM
- RDS
- DynamoDB
- Redshift
- GDPR
- CIPP/US
- CIPM
- CISA
- CISSP
- Snyk
- Wiz
- Qualys
- Burp
1 day ago
We're looking for aSenior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, converting regulatory mandates into concrete engineering tasks while facilitating third-party audits and collaborating across security, privacy, and legal functions.
Responsibilities
- Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with defined acceptance criteria, effort estimates, and a designated owner
- Keep the backlog organized across ongoing compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
- Develop and run test cases to confirm controls function as intended, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, then document pass/fail results
- Manage the intake, tracking, and completion of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews
- Link each audit request to its corresponding NIST 800-53 control and work with engineering, ISRM, Privacy, and Legal to collect artifacts and meet the auditor's timeline
- Generate ongoing compliance status reports for stakeholders
- Create simple automation tools, such as scripts, dashboards, and evidence pipelines, to cut down manual work in future audits as the program expands to new clients and jurisdictions
- Collaborate with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document which controls are inherited from AWS/Azure versus those that must be developed or maintained internally
Requirements
- 6-15 years of overall IT experience
- Background in security/privacy compliance, GRC, or compliance engineering, with support for HIPAA and/or FedRAMP/NIST 800-53 programs
- Understanding of the HIPAA Security & Privacy Rules, covering administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families such as AC, AU, SI, and PM
- Proven ability to convert compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar platforms
- Hands-on experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including gathering evidence, mapping controls to evidence, and meeting auditor deadlines
- Knowledge of cloud environments such as AWS GovCloud and/or Azure Government, plus controls including IAM/RBAC, encryption/KMS, audit logging, and data retention & deletion
Nice to have
- Hands-on experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
- Scripting/automation skills using Python or Bash to automate evidence collection, control testing, or compliance dashboards
- Experience with AWS IAM/identity governance tools such as SailPoint or equivalent, and managing access policies across S3, RDS, DynamoDB, and Redshift
- Understanding of international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or the ability to quickly learn as coverage expands
- Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
- Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, or Burp, along with secrets/certificate rotation programs
- Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data
Senior/Lead Security Engineer - HIPPA ยท EPAM Systems