Lead Security Compliance Engineer

Brak informacji o wynagrodzeniu
SeniorFull-time
#453839·Dodano 2 dni temu·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Security ComplianceHipaaNIST 800-53GRCFedRAMPAzure DevOpsSOC 2Identity and Access Management

Firma i stanowisko

EPAM Systems is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and startups. They have over thirty years of expertise in custom software, product, and platform engineering, empowering clients to become AI-Native enterprises.

Wymagania

  • 3+ years of experience in security/privacy compliance, GRC, or compliance engineering supporting HIPAA and/or FedRAMP/NIST 800-53 programs
  • Solid working knowledge of HIPAA Security & Privacy Rules including administrative, physical, technical safeguards, BAAs, breach notification, and minimum necessary standards
  • Knowledge of NIST 800-53 control families including AC, AU, SI, and PM
  • Ability to translate compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
  • Direct experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
  • Familiarity with cloud environments like AWS GovCloud and/or Azure Government
  • Understanding of controls important for compliance, including IAM/RBAC, encryption/KMS, audit logging, data retention and deletion
  • English proficiency at B2 level or higher

Nice to have:

  • Experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Skills in scripting/automation using Python or Bash for evidence collection, control testing, or dashboards
  • Experience with AWS IAM/identity governance tooling such as SailPoint and access policy management across services
  • Exposure to international privacy laws like UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA
  • Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or AWS/Azure security certifications
  • Experience with security-scan remediation tools like Snyk, Wiz, Qualys, Burp, and secrets/certificate rotation
  • Background supporting legal-tech, healthcare, or government SaaS products handling regulated data

Obowiązki

  • Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria, effort estimates, and a named owner
  • Maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
  • Close ownership and sprint-assignment gaps before they escalate into RAID-log risks
  • Write and execute test cases to verify controls such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request
  • Document pass/fail evidence for all control testing activities
  • Own the intake, tracking, and fulfillment of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews
  • Map each auditor request to the relevant NIST 800-53 control and coordinate artifact gathering with engineering, ISRM, Privacy, and Legal
  • Deliver evidence and documentation on the auditor's schedule
  • Produce recurring compliance status reporting for stakeholders
  • Build lightweight automation such as scripts, dashboards, and evidence pipelines to reduce manual effort in future audit cycles
  • Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document inherited and internally owned controls

Benefity

  • Opportunity to work remotely within Poland with hybrid-friendly mode
  • Chance to work abroad up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs including mentoring, soft skills, and certification support (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • Stable pay and participation in Employee Stock Purchase Plan with 15% discount
  • Benefits package including health insurance, multisport, shopping vouchers
  • Referral bonuses up to $2,000
  • Offices with entertainment and relaxation zones, table tennis, football, free snacks, coffee, and more
  • Corporate, social, and well-being events
Elastyczne godziny
Pakiet relokacyjny
Budżet konferencyjny
Szkolenia wewnętrzne
Dofinansowanie szkoleń
Kursy językowe
Karta sportowa
Opieka zdrowotna
Premie
Udziały pracownicze
Darmowe przekąski

Inne informacje

Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności.

EPAM Systems

EPAM Systems

1351 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz