Skip to main content
EPAM Systems

Lead Security Engineer

RemoteArgentina, Colombia, Mexico onlyArchived
Published
Role
Unknown
Experience
Senior
Employment
Contract
Salary not disclosed
Check eligibility

Open to AR, CO, MX only. Set where you work from to check your eligibility.

No BS summary

Ця роль поєднує юридичні/комплаєнс-вимоги з практичною інженерію — інтерпретація регуляторного або аудиторського тексту, розбиття його на технічні завдання, виконання цих завдань і управління процесом збору доказів для зовнішніх аудитів.

Core skills

compliance frameworks/HIPAA/FedRAMP/NIST 800-53/SOC 2/HITRUST

Required skills

project management platforms/Azure DevOps/Jiracloud environments/AWS GovCloud/Azure Governmentsecurity controls/IAM/RBAC/encryption/KMS/audit logging/data retention/data deletion

Optional skills

Significant Change Requests (SCR)PythonBashAWS IAMSailPointS3RDSDynamoDB

Required languages

English B2 or higher

What you'll do

  • Convert regulatory and audit language into concrete, actionable backlog items by transforming HIPAA gap assessments, NIST 800-53 privacy controls, and audit findings into well-defined Azure DevOps Features, Stories, and Tasks complete with acceptance criteria, effort estimates, and assigned ownership, such as reshaping "HIPAA privacy requirements not yet defined" into a clear engineering deliverable
  • Monitor delivery progress and keep the backlog organized across live compliance initiatives, including access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions, closing gaps in ownership or sprint planning before they turn into RAID-log issues
  • Develop and run test cases confirming that controls operate as intended, such as privileged-access limitations, time-bound SailPoint access, PII minimization, and deletion-on-request functionality, capturing pass/fail results as supporting documentation
  • Manage the complete audit support lifecycle, from intake through tracking and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews, linking each request to its corresponding NIST 800-53 control, working with engineering, ISRM, Privacy, and Legal to compile artifacts, and meeting the auditor's timeline
  • Generate ongoing compliance status updates for stakeholders and develop streamlined automation, including scripts, dashboards, and evidence pipelines, to cut down on manual work in future audit cycles as the program grows to serve new clients and regions
  • Collaborate across departments, working with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to distinguish and document controls inherited from AWS/Azure (FedRAMP, SOC 2) versus those requiring internal ownership and development

What they require

  • At least 5 years of relevant experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 initiatives
  • A minimum of one year of experience leading and managing teams
  • Strong familiarity with the HIPAA Security & Privacy Rules, covering administrative, physical, and technical safeguards, BAAs, breach notification requirements, and minimum necessary principles, as well as NIST 800-53 control families such as AC, AU, SI, and PM
  • Proven capability to convert compliance and regulatory text into scoped, estimable engineering backlog items using platforms like Azure DevOps, Jira, or similar
  • Hands-on experience supporting third-party audits, including SOC 2, FedRAMP, or HITRUST, covering evidence gathering, mapping controls to evidence, and meeting auditor timelines
  • Working knowledge of cloud environments, such as AWS GovCloud and/or Azure Government, along with compliance-relevant controls, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletion practices

Benefits

  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn

Our Workforce Experience team helps clients realize digital and IT transformation by identifying and bridging gaps in employee knowledge, behaviors, and mindset. We design, develop, and implement a variety of solutions for online and in-person learning, including videos, articles, podcasts, interactive eLearning, coaching, experiential learning, instructor-led training, and assessments, using the latest insights from the learning sciences. In other words, we go beyond "training" to create learning experiences that really work.

🇺🇸 United StatesIT ServicesEnterpriseepam.com/
Salary not disclosed