Lead Security Engineer
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-10-04
Listing for:
EPAM Systems, Inc.
Full Time
position Listed on 2026-10-04
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Responsibilities Convert regulatory and audit language into concrete, actionable backlog items by transforming HIPAA gap assessments, NIST 800-53 privacy controls, and audit findings into well-defined Azure Dev Ops Features, Stories, and Tasks complete with acceptance criteria, effort estimates, and assigned ownership, such as reshaping "HIPAA privacy requirements not yet defined" into a clear engineering deliverable
Monitor delivery progress and keep the backlog organized across live compliance initiatives, including access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions, closing gaps in ownership or sprint planning before they turn into RAID-log issues
Develop and run test cases confirming that controls operate as intended, such as privileged-access limitations, time-bound SailPoint access, PII minimization, and deletion-on-request functionality, capturing pass/fail results as supporting documentation
Manage the complete audit support lifecycle, from intake through tracking and fulfillment of third-party auditor evidence requests, such as Schellman FedRAMP Significant Change Reviews, linking each request to its corresponding NIST 800-53 control, working with engineering, ISRM, Privacy, and Legal to compile artifacts, and meeting the auditor's timeline
Generate ongoing compliance status updates for stakeholders and develop streamlined automation, including scripts, dashboards, and evidence pipelines, to cut down on manual work in future audit cycles as the program grows to serve new clients and regions
Collaborate across departments, working with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to distinguish and document controls inherited from AWS/Azure (FedRAMP, SOC
2) versus those requiring internal ownership and development
Requirements
At least 5 years of relevant experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 initiativesA minimum of one year of experience leading and managing teams
Strong familiarity with the HIPAA Security & Privacy Rules, covering administrative, physical, and technical safeguards, BAAs, breach notification requirements, and minimum necessary principles, as well as NIST 800-53 control families such as AC, AU, SI, and PMProven capability to convert compliance and regulatory text into scoped, estimable engineering backlog items using platforms like Azure Dev Ops, Jira, or similar
Hands-on experience supporting third-party audits, including SOC 2, FedRAMP, or HITRUST, covering evidence gathering, mapping controls to evidence, and meeting auditor timelines
Working knowledge of cloud environments, such as AWS Gov Cloud and/or Azure Government, along with compliance-relevant controls, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletion practices
Excellent English communication skills (B2 level or higher)
Nice to have Hands-on experience with FedRAMP Significant Change Requests (SCR) and working directly with assessors
Ability to script and automate tasks using Python or Bash to streamline evidence gathering, control testing, or compliance dashboard creation
Experience with AWS IAM and identity governance platforms, such as SailPoint or similar tools, along with managing access policies across S3, RDS, DynamoDB, and Redshift Familiarity with international privacy regulations, such as UK/EU GDPR, Australia's Privacy Act, or Canada's PIPEDA, or willingness to quickly develop expertise as the program's scope broadens
Relevant industry certifications, such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or a security certification from AWS or Azure Experience tracking remediation from security scanning tools, such as Snyk, Wiz, Qualys, or Burp, along with managing programs for secrets and certificate rotation
Prior experience supporting legal-tech, healthcare, or government SaaS platforms that…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×