Senior/Lead Security Engineer - HIPPA (Chennai)

Senior/Lead Security Engineer - HIPPA (Chennai)

30 Sep
|
EPAM Systems
|
Chennai

30 Sep

EPAM Systems

Chennai

EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.

We're looking for a Senior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, turning regulatory requirements into concrete engineering tasks while supporting third-party audits and collaborating across security, privacy, and legal teams.

Responsibilities

- Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with defined acceptance criteria, effort estimates, and an assigned owner
- Keep the backlog organized across active compliance features, covering access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
- Develop and run test cases to confirm controls function as intended, including privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, and record pass/fail results
- Manage the intake, tracking, and completion of evidence requests from third-party auditors, such as Schellman FedRAMP Significant Change Reviews
- Link each audit request to its corresponding NIST 800-53 control and work with engineering, ISRM, Privacy,



and Legal to collect artifacts and meet auditor deadlines
- Deliver regular compliance status updates to stakeholders
- Create lightweight automation—scripts, dashboards, and evidence pipelines—to cut down manual work in future audits as the program expands to new clients and jurisdictions
- Collaborate with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document which controls are inherited from AWS/Azure versus those that need to be built or maintained internally

Requirements

- 6-15 years of overall IT experience
- Background in security/privacy compliance, GRC, or compliance engineering, with support for HIPAA and/or FedRAMP/NIST 800-53 programs
- Understanding of the HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families like AC, AU, SI, and PM
- Proven ability to convert compliance/regulatory language into scoped, estimable backlog items using Azure DevOps, Jira, or similar tools
- Hands-on experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
- Familiarity with cloud environments such as AWS GovCloud and/or Azure Government, plus controls like IAM/RBAC,



encryption/KMS, audit logging, and data retention & deletion

Nice to have

- Hands-on experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
- Scripting/automation skills in Python or Bash for automating evidence collection, control testing, or compliance dashboards
- Experience with AWS IAM/identity governance tools like SailPoint or equivalent, and managing access policies across S3, RDS, DynamoDB, and Redshift
- Knowledge of international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or willingness to quickly learn as coverage grows
- Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
- Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, or Burp, along with secrets/certificate rotation programs
- Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data

We offer

- Prospect to work on technical challenges that may impact across geographies
- Vast opportunities for self-development: online university, knowledge sharing opportunities globally, learning opportunities through external certifications
- Opportunity to share your ideas on international platforms
- Sponsored Tech Talks & Hackathons
- Unlimited access to LinkedIn learning solutions
- Possibility to relocate to any EPAM office for short and long-term projects
- Focused individual development
- Benefit package:
- Health benefits
- Retirement benefits
- Paid time off
- Flexible benefits

- Forums to explore beyond work passion (CSR, photography, painting, sports, etc.)

📌 Senior/Lead Security Engineer - HIPPA (Chennai)
🏢 EPAM Systems
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior/lead security engineer - hippa (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: senior/lead security engineer - hippa (chennai) / chennai