Lead Security Compliance Engineer @EPAM Systems
Compliance
Salary unspecified
Remote Location
Employment Type full-time
Posted 3d ago

[Hiring] Lead Security Compliance Engineer @EPAM Systems

3d ago - EPAM Systems is hiring a remote Lead Security Compliance Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Poland

Role Description

We are seeking a Lead Security Compliance Engineer to translate complex regulatory requirements into actionable engineering work, drive audit readiness, and strengthen compliance posture across HIPAA, FedRAMP, and NIST 800-53 programs. This role bridges the gap between compliance mandates and technical execution, partnering closely with engineering, ISRM, Privacy, Legal, and cloud platform teams to ensure controls are implemented, tested, and audit-ready at scale.

  • Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria, effort estimates, and a named owner
  • Maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
  • Close ownership and sprint-assignment gaps before they escalate into RAID-log risks
  • Write and execute test cases to verify controls work as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request
  • Document pass/fail evidence for all control testing activities
  • Own the intake, tracking, and fulfillment of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews
  • Map each auditor request to the relevant NIST 800-53 control and coordinate with engineering, ISRM, Privacy, and Legal to gather artifacts
  • Deliver evidence and documentation on the auditor's schedule
  • Produce recurring compliance status reporting for stakeholders
  • Build lightweight automation, including scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles
  • Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure versus controls that must be built or owned internally

Qualifications

  • 3+ years of experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
  • Solid working knowledge of HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards
  • Knowledge of NIST 800-53 control families, including AC, AU, SI, and PM
  • Demonstrated ability to translate compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
  • Direct experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
  • Familiarity with cloud environments such as AWS GovCloud and/or Azure Government
  • Understanding of controls that matter for compliance, including IAM/RBAC, encryption/KMS, and audit logging, data retention & deletion
  • English proficiency at B2 level or higher

Requirements

  • Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Skills in scripting/automation using Python or Bash to automate evidence collection, control testing, or compliance dashboards
  • Experience with AWS IAM/identity governance tooling such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, Redshift
  • Exposure to international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or readiness to ramp quickly as coverage expands
  • Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
  • Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, Burp, and secrets/certificate rotation programs
  • Background supporting legal-tech, healthcare, or government SaaS products handling regulated data
Before You Apply
️
remote Be aware of the location restriction for this remote position: Poland
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead Security Compliance Engineer @EPAM Systems
Compliance
Salary unspecified
Remote Location
Employment Type full-time
Posted 3d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Poland
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 128,845+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later