Enter a job title or keyword

SeniorLead Security Engineer HIPPA

EPAM Systems


Job Location:

Gurgaon - India

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (4 days ago)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

We are seeking a Senior/Lead Security Engineer to drive HIPAA and FedRAMP/NIST 800-53 compliance initiatives translating regulatory requirements into actionable engineering work while supporting third-party audits and cross-functional coordination across security privacy and legal teams.

Responsibilities
  • Translate HIPAA gap analyses NIST 800-53 privacy controls and audit findings into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria effort estimates and a named owner
  • Maintain backlog hygiene across active compliance features including access control data classification log scrubbing audit logging data retention & deletion and data access restrictions
  • Write and execute test cases to verify controls work as designed such as privileged-access restrictions time-bound SailPoint access PII minimization and deletion-on-request and document pass/fail evidence
  • Own the intake tracking and fulfillment of third-party auditor evidence requests such as Schellman FedRAMP Significant Change Reviews
  • Map each audit request to the relevant NIST 800-53 control and coordinate with engineering ISRM Privacy and Legal to gather artifacts and deliver on the auditors schedule
  • Produce recurring compliance status reporting for stakeholders
  • Build lightweight automation such as scripts dashboards and evidence pipelines to reduce manual effort in future audit cycles as the program scales to new clients and jurisdictions
  • Partner with ISRM Privacy Office Legal SRE and cloud platform teams to document controls inherited from AWS/Azure versus controls that must be built or owned internally
Requirements
  • 6-15 years of overall experience in IT
  • Experience in security/privacy compliance GRC or compliance engineering supporting HIPAA and/or FedRAMP/NIST 800-53 programs
  • Knowledge of the HIPAA Security & Privacy Rules including administrative/physical/technical safeguards BAAs breach notification and minimum necessary standards as well as NIST 800-53 control families such as AC AU SI and PM
  • Demonstrated ability to turn compliance/regulatory language into scoped estimable engineering backlog items in Azure DevOps Jira or similar tools
  • Direct experience supporting third-party audits such as SOC 2 FedRAMP or HITRUST including evidence collection control-to-evidence mapping and meeting auditor deadlines
  • Familiarity with cloud environments such as AWS GovCloud and/or Azure Government along with controls including IAM/RBAC encryption/KMS audit logging and data retention & deletion
Nice to have
  • Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
  • Skills in scripting/automation using Python or Bash to automate evidence collection control testing or compliance dashboards
  • Experience with AWS IAM/identity governance tooling such as SailPoint or equivalent and access policy management across S3 RDS DynamoDB and Redshift
  • Familiarity with international privacy regimes such as UK/EU GDPR Australia Privacy Act or Canada PIPEDA or readiness to ramp quickly as coverage expands
  • Relevant certifications: CIPP/US CIPM HCISPP CISA CISSP or an AWS/Azure security certification
  • Experience with security-scan remediation tracking tools such as Snyk Wiz Qualys or Burp and secrets/certificate rotation programs
  • Background supporting legal-tech healthcare or government SaaS products handling regulated data

Required Experience:

Staff IC