Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
EPAM provides enterprise software products, open source solutions, and accelerators. The company supports highly regulated government and enterprise clients by enabling secure product delivery in cloud environments.
задачи
Translate regulatory and audit requirements, including HIPAA and NIST 800-53, into scoped engineering tasks with clear acceptance criteria;
Maintain backlog hygiene across compliance initiatives in Azure DevOps and Jira;
Test and validate technical security controls, including access restrictions, log retention, and data deletion, and document test outcomes;
Support third-party audits such as FedRAMP and SOC 2 by mapping controls to evidence, coordinating data collection, and delivering on schedule;
Develop recurring compliance reporting and create automation scripts or dashboards for monitoring and evidence collection;
Collaborate with ISRM, Privacy Office, Legal, SRE, and platform teams to document shared and owned controls in cloud architectures;
Monitor identified compliance gaps to ensure timely remediation;
Assist with Significant Change Reviews for FedRAMP and similar compliance frameworks;
Contribute to continuous improvement of compliance programs through process refinement and tooling updates.
требования
3+ Years of experience in security or privacy compliance, GRC, or compliance engineering roles;
In-depth knowledge of HIPAA Security and Privacy rules and NIST 800-53 control families;
Experience transforming regulatory language into structured, estimable backlog items in Azure DevOps or Jira;
Proven experience supporting SOC 2, FedRAMP, or HITRUST audits, including evidence collection and auditor interactions;
Familiarity with cloud security in AWS or Azure, including IAM/RBAC, audit logging, encryption, and data lifecycle controls;
Strong communication and stakeholder coordination skills;
Ability to work remotely with partial US time zone overlap until at least 11:00 AM CST;
Nice to have: direct experience with FedRAMP Significant Change Requests and assessor engagement, Python or Bash scripting proficiency, exposure to GDPR, PIPEDA, or equivalent privacy frameworks, familiarity with identity governance platforms such as SailPoint, experience with Snyk, Wiz, or Qualys vulnerability tracking and remediation, CIPP/US, CIPM, HCISPP, CISA, CISSP, or AWS/Azure security certifications, prior experience in legal-tech, healthcare, or government SaaS environments handling regulated datasets.