EPAM Systems logo
EPAM Systems

4,194 open roles

Senior/Lead Security Engineer - HIPPA

Gurgaon, Haryana, IndiaPune, Maharashtra, IndiaCoimbatore, Tamil Nadu, IndiaChennai, Tamil Nadu, IndiaFull-timePosted Sep 29, 2026

Job description

We're looking for a Senior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, converting regulatory mandates into actionable engineering tasks, supporting third-party audits, and coordinating across security, privacy, and legal functions.

Responsibilities

Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with defined acceptance criteria, effort estimates, and an assigned owner Keep the backlog organized across active compliance features, covering access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions Develop and run test cases to confirm controls perform as intended, including privileged-access restrictions, time-bound Sail.

Point access, PII minimization, and deletion-on-request, and log pass/fail results Manage the intake, tracking, and completion of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews Link each audit request to its corresponding NIST 800-53 control and work with engineering, ISRM, Privacy, and Legal to collect artifacts and meet the auditor's timeline Generate ongoing compliance status reports for stakeholders Develop lightweight automation, including scripts, dashboards, and evidence pipelines, to minimize manual work in future audits as the program expands to new clients and jurisdictions Collaborate with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document which controls are inherited from AWS/Azure and which must be developed or maintained internally Requirements 6-15 years of overall IT experience Background in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs Understanding of HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards, along with NIST 800-53 control families such as AC, AU, SI, and PM Proven ability to translate compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools Hands-on experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines Knowledge of cloud environments such as AWS Gov.

Cloud and/or Azure Government, plus controls including IAM/RBAC, encryption/KMS, audit logging, and data retention & deletion Nice to have Hands-on experience with FedRAMP Significant Change Requests (SCR) and assessor engagements Scripting/automation skills in Python or Bash for automating evidence collection, control testing, or compliance dashboards Experience with AWS IAM/identity governance tools such as Sail.

Point or similar, and access policy management across S3, RDS, DynamoDB, and Redshift Awareness of international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or willingness to quickly learn as coverage grows Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, or Burp, and secrets/certificate rotation programs Background supporting legal-tech, healthcare, or government SaaS products that handle regulated data

Description copied from EPAM Systems's careers page. Read the full posting before you apply.

More jobs at EPAM Systems

See all openings at EPAM Systems