01 Oct
|
EPAM Systems
|
Gurugram
01 Oct
EPAM Systems
Gurugram
We are seeking a Senior/Lead Security Engineer to drive HIPAA and FedRAMP/NIST 800-53 compliance initiatives, translating regulatory requirements into actionable engineering work while supporting third-party audits and cross-functional coordination across security, privacy, and legal teams.
Responsibilities
- Translate HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with transparent acceptance criteria, effort estimates, and a named owner
- Maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
- Write and execute test cases to verify controls work as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request, and document pass/fail evidence
- Own the intake, tracking, and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews
- Map each audit request to the relevant NIST 800-53 control and coordinate with engineering, ISRM, Privacy, and Legal to gather artifacts and deliver on the auditor's schedule
- Produce recurring compliance status reporting for stakeholders
- Build lightweight automation, such as scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles as the program scales to new clients and jurisdictions
- Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure versus controls that must be built or owned internally
Requirements
- 6-15 years of overall experience in IT
- Experience in security/privacy compliance,
GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
- Knowledge of the HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards, as well as NIST 800-53 control families such as AC, AU, SI, and PM
- Demonstrated ability to turn compliance/regulatory language into scoped, estimable engineering backlog items in Azure DevOps, Jira, or similar tools
- Direct experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
- Familiarity with cloud environments such as AWS GovCloud and/or Azure Government, along with controls including IAM/RBAC, encryption/KMS, audit logging, and data retention & deletion
Nice to have
- Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
- Skills in scripting/automation using Python or Bash to automate evidence collection, control testing, or compliance dashboards
- Experience with AWS IAM/identity governance tooling such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, and Redshift
- Familiarity with international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or readiness to ramp quickly as coverage expands
- Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
- Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, or Burp, and secrets/certificate rotation programs
- Background supporting legal-tech, healthcare, or government SaaS products handling regulated data
📌 Senior/Lead Security Engineer - HIPPA (Gurugram)
🏢 EPAM Systems
📍 Gurugram