Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
ES

Senior/Lead Security Engineer - HIPPA

EPAM Systems
🇮🇳 India
On-site
Staff / Principal
1 day ago
  • HIPAA
  • FedRAMP
  • NIST
  • Azure DevOps
  • SailPoint
  • AWS
  • Azure
  • Jira
  • SOC2
  • HITRUST
  • AWS GovCloud
  • Azure Government
  • IAM
  • RBAC
  • KMS
  • Python
  • Bash
  • AWS IAM
  • RDS
  • DynamoDB
  • Redshift
  • GDPR
  • CIPP/US
  • CIPM
  • CISA
  • CISSP
  • Snyk
  • Wiz
  • Qualys
  • Burp
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

We're looking for aSenior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, turning regulatory requirements into concrete engineering tasks while supporting third-party audits and collaborating across security, privacy, and legal teams.

Responsibilities

  • Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with defined acceptance criteria, effort estimates, and an assigned owner
  • Keep the backlog organized across active compliance features, covering access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
  • Develop and run test cases to confirm controls function as intended, including privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, and record pass/fail results
  • Manage the intake, tracking, and completion of evidence requests from third-party auditors, such as Schellman FedRAMP Significant Change Reviews
  • Link each audit request to its corresponding NIST 800-53 control and work with engineering, ISRM, Privacy, and Legal to collect artifacts and meet auditor deadlines
  • Deliver regular compliance status updates to stakeholders
  • Create lightweight automation—scripts, dashboards, and evidence pipelines—to cut down manual work in future audits as the program expands to new clients and jurisdictions
  • Collaborate with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document which controls are inherited from AWS/Azure versus those that need to be built or maintained internally

Requirements

  • 6-15 years of overall IT experience
  • Background in security/privacy compliance, GRC, or compliance engineering, with support for HIPAA and/or FedRAMP/NIST 800-53 programs
  • Understanding of the HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families like AC, AU, SI, and PM
  • Proven ability to convert compliance/regulatory language into scoped, estimable backlog items using Azure DevOps, Jira, or similar tools
  • Hands-on experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
  • Familiarity with cloud environments such as AWS GovCloud and/or Azure Government, plus controls like IAM/RBAC, encryption/KMS, audit logging, and data retention & deletion

Nice to have

  • Hands-on experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Scripting/automation skills in Python or Bash for automating evidence collection, control testing, or compliance dashboards
  • Experience with AWS IAM/identity governance tools like SailPoint or equivalent, and managing access policies across S3, RDS, DynamoDB, and Redshift
  • Knowledge of international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or willingness to quickly learn as coverage grows
  • Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
  • Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, or Burp, along with secrets/certificate rotation programs
  • Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data

Senior/Lead Security Engineer - HIPPA · EPAM Systems

Auto apply with Likeremote