Senior Security Compliance Engineer
EPAM Systems · Remote, Spain
You apply off-site, with the employer or the job board. I never handle applications.
We're looking for a Senior Security Compliance Engineer to join our team in Spain in a remote working mode. In this role, you will operate at the intersection of compliance and engineering delivery, ensuring regulatory and audit requirements are translated into actionable work items, implemented effectively and validated through evidence collection.
You will contribute to major compliance initiatives, supporting FedRAMP Moderate authorization, HIPAA Security/Privacy Rule adherence and NIST 800-53 control implementation, eventually extending coverage to global privacy frameworks. This opportunity offers a chance to shape compliance programs for highly regulated government and enterprise clients, reduce operational risk and enable secure product delivery in cloud environments.
Responsibilities
- Translate regulatory and audit requirements (HIPAA, NIST 800-53) into scoped engineering tasks with clear acceptance criteria
- Maintain backlog hygiene across compliance initiatives for Azure DevOps/Jira features
- Test and validate technical security controls such as access restrictions, log retention and data deletion, documenting test outcomes
- Support third-party audits (FedRAMP, SOC 2) by mapping controls to evidence, coordinating data collection and delivering on schedule
- Develop recurring compliance reporting and create automation scripts or dashboards for monitoring and evidence collection
- Collaborate with ISRM, Privacy Office, Legal, SRE and platform teams to document shared versus owned controls in cloud architectures
- Monitor progress of identified compliance gaps to ensure timely remediation
- Assist with Significant Change Reviews (SCR) for FedRAMP and similar compliance frameworks
- Contribute to enhancing continuous improvement of compliance programs through process refinement and tooling updates
Requirements
- 3+ years of experience in security or privacy compliance, GRC or compliance engineering roles
- In-depth knowledge of HIPAA Security and Privacy rules and NIST 800-53 control families
- Experience transforming regulatory language into structured, estimable backlog items in Azure DevOps or Jira
- Proven track record supporting audits such as SOC 2, FedRAMP or HITRUST including evidence collection and auditor interactions
- Familiarity with cloud security in AWS or Azure, including IAM/RBAC, audit logging, encryption and data lifecycle controls
- Strong communication and stakeholder coordination skills
- Ability to work remotely with partial US time zone overlap (until at least 11:00 AM CST)
Nice to have
- Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagement
- Scripting proficiency in Python or Bash for automation of controls and compliance dashboards
- Exposure to international privacy laws such as GDPR, PIPEDA or equivalent frameworks
- Familiarity with identity governance platforms (e.g., SailPoint) and policy enforcement in cloud services
- Experience addressing vulnerability tracking systems (Snyk, Wiz, Qualys) and remediation activities
- Relevant certifications such as CIPP/US, CIPM, HCISPP, CISA, CISSP or AWS/Azure security certifications
- Prior experience in legal-tech, healthcare or government SaaS environments handling regulated datasets
We offer
- Private health insurance
- EPAM Employees Stock Purchase Plan
- 100% paid sick leave
- Referral Program
- Professional certification
- Language courses
EPAM is a leading digital transformation services and product engineering company with 61,700+ EPAMers in 55+ countries and regions. Since 1993, our multidisciplinary teams have been helping make the future real for our clients and communities around the world. In 2018, we opened an office in Spain that quickly grew to over 1,450 EPAMers distributed between the offices in Málaga, Madrid and Cáceres as well as remotely across the country. Here you will collaborate with multinational teams, contribute to numerous innovative projects, and have an opportunity to learn and grow continuously.
- Why Join EPAM
- WORK AND LIFE BALANCE. Enjoy more of your personal time with flexible work options, 24 working days of annual leave and paid time off for numerous public holidays.
- CONTINUOUS LEARNING CULTURE. Craft your personal Career Development Plan to align with your learning objectives. Take advantage of internal training, mentorship, sponsored certifications and LinkedIn courses.
- CLEAR AND DIFFERENT CAREER PATHS. Grow in engineering or managerial direction to become a People Manager, in-depth technical specialist, Solution Architect, or Project/Delivery Manager.
- STRONG PROFESSIONAL COMMUNITY. Join a global EPAM community of highly skilled experts and connect with them to solve challenges, exchange ideas, share expertise and make friends.