Senior/Lead Security Engineer - HIPPA (Gurugram)

Senior/Lead Security Engineer - HIPPA (Gurugram)

30 Sep
|
EPAM Systems
|
Gurugram

30 Sep

EPAM Systems

Gurugram

EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture.

Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.

We're looking for a Senior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, converting regulatory mandates into actionable engineering tasks, supporting third-party audits, and coordinating across security, privacy, and legal functions.

Responsibilities

- Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with defined acceptance criteria, effort estimates, and an assigned owner
- Keep the backlog organized across active compliance features, covering access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
- Develop and run test cases to confirm controls perform as intended, including privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, and log pass/fail results
- Manage the intake, tracking, and completion of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews
- Link each audit request to its corresponding NIST 800-53 control and work with engineering, ISRM, Privacy,



and Legal to collect artifacts and meet the auditor's timeline
- Generate ongoing compliance status reports for stakeholders
- Develop lightweight automation, including scripts, dashboards, and evidence pipelines, to minimize manual work in future audits as the program expands to new clients and jurisdictions
- Collaborate with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document which controls are inherited from AWS/Azure and which must be developed or maintained internally

Requirements

- 6-15 years of overall IT experience
- Background in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
- Understanding of HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families such as AC, AU, SI, and PM
- Proven ability to translate compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
- Hands-on experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
- Knowledge of cloud environments such as AWS GovCloud and/or Azure Government, plus controls including IAM/RBAC,



encryption/KMS, audit logging, and data retention & deletion

Nice to have

- Hands-on experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
- Scripting/automation skills in Python or Bash for automating evidence collection, control testing, or compliance dashboards
- Experience with AWS IAM/identity governance tools such as SailPoint or similar, and access policy management across S3, RDS, DynamoDB, and Redshift
- Awareness of international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or willingness to quickly learn as coverage grows
- Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
- Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, or Burp, and secrets/certificate rotation programs
- Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data

We offer

- Opportunity to work on technical challenges that may impact across geographies
- Vast opportunities for self-development: online university, knowledge sharing opportunities globally, learning opportunities through external certifications
- Opportunity to share your ideas on international platforms
- Sponsored Tech Talks & Hackathons
- Unlimited access to LinkedIn learning solutions
- Possibility to relocate to any EPAM office for short and long-term projects
- Focused individual development
- Benefit package:
- Health benefits
- Retirement perks
- Paid time off
- Flexible benefits

- Forums to explore beyond work passion (CSR, photography, painting, sports, etc.)

📌 Senior/Lead Security Engineer - HIPPA (Gurugram)
🏢 EPAM Systems
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior/lead security engineer - hippa (gurugram) / gurugram

Subscribe to this job alert:

Get the latest job offers by email for: senior/lead security engineer - hippa (gurugram) / gurugram