Lead Security Compliance Engineer
- Hiring from
- Poland
- Work type
- Remote
- Posted
510,503 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
We are seeking a Lead Security Compliance Engineer to translate complex regulatory requirements into actionable engineering work, drive audit readiness, and strengthen compliance posture across HIPAA, FedRAMP, and NIST 800-53 programs. This role bridges the gap between compliance mandates and technical execution, partnering closely with engineering, ISRM, Privacy, Legal, and cloud platform teams to ensure controls are implemented, tested, and audit-ready at scale.
Responsibilities
- Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria, effort estimates, and a named owner
- Maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
- Close ownership and sprint-assignment gaps before they escalate into RAID-log risks
- Write and execute test cases to verify controls work as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request
- Document pass/fail evidence for all control testing activities
- Own the intake, tracking, and fulfillment of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews
- Map each auditor request to the relevant NIST 800-53 control and coordinate with engineering, ISRM, Privacy, and Legal to gather artifacts
- Deliver evidence and documentation on the auditor's schedule
- Produce recurring compliance status reporting for stakeholders
- Build lightweight automation, including scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles
- Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure versus controls that must be built or owned internally
Requirements
- 3+ years of experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
- Solid working knowledge of HIPAA Security & Privacy Rules, including administrative/physical/technical safeguards, BAAs, breach notification, and minimum necessary standards
- Knowledge of NIST 800-53 control families, including AC, AU, SI, and PM
- Demonstrated ability to translate compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
- Direct experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
- Familiarity with cloud environments such as AWS GovCloud and/or Azure Government
- Understanding of controls that matter for compliance, including IAM/RBAC, encryption/KMS, and audit logging, data retention & deletion
- English proficiency at B2 level or higher
Nice to have
- Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
- Skills in scripting/automation using Python or Bash to automate evidence collection, control testing, or compliance dashboards
- Experience with AWS IAM/identity governance tooling such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, Redshift
- Exposure to international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or readiness to ramp quickly as coverage expands
- Relevant certifications: CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
- Experience with security-scan remediation tracking tools such as Snyk, Wiz, Qualys, Burp, and secrets/certificate rotation programs
- Background supporting legal-tech, healthcare, or government SaaS products handling regulated data
We offer
We gather like-minded people:
- Top tech minds driving innovation in AI, cloud and digital platform modernization
- Supportive team and agile, startup-like culture
- Hybrid by design mode and opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
We provide growth opportunities:
- Career development programs
- Thought leadership, mentoring, soft skills and well-being programs
- Certification (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
We cover it all:
- Stable pay
- Participation in the Employee Stock Purchase Plan with a 15% discount
- Benefits package (health insurance, multisport, shopping vouchers)
- Referral bonuses up to $2,000
- Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
- Corporate, social and well-being events
Please, note:
- Benefits listed above are available to employees only
- We are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually
- We will reach out to selected candidates exclusively
EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Remote in Poland