Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
EPAM provides enterprise software products, open source solutions, accelerators, and technology services.
задачи
Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features, Stories, and Tasks with acceptance criteria, effort estimates, and named owners;
Maintain backlog hygiene across compliance features covering access control, data classification, log scrubbing, audit logging, data retention and deletion, and data access restrictions;
Close ownership and sprint-assignment gaps before they escalate into RAID-log risks;
Write and execute test cases to verify controls such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request;
Document pass/fail evidence for control testing activities;
Own the intake, tracking, and fulfillment of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews;
Map auditor requests to relevant NIST 800-53 controls and coordinate with engineering, ISRM, Privacy, and Legal to gather artifacts;
Deliver evidence and documentation according to the auditor's schedule;
Produce recurring compliance status reports for stakeholders;
Build lightweight automation, including scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles;
Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure and controls that must be built or owned internally.
требования
3+ Years of experience in security/privacy compliance, GRC, or compliance engineering supporting HIPAA and/or FedRAMP/NIST 800-53 programs;
Knowledge of HIPAA Security and Privacy Rules, including administrative, physical, and technical safeguards, BAAs, breach notification, and minimum necessary standards;
Understanding of NIST 800-53 control families, including AC, AU, SI, and PM;
Ability to translate compliance and regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools;
Direct experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines;
Familiarity with cloud environments such as AWS GovCloud and/or Azure Government;
Knowledge of compliance-relevant controls, including IAM/RBAC, encryption/KMS, audit logging, and data retention and deletion practices;
English proficiency at B2 level or higher;
Nice to have: Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements, scripting or automation using Python or Bash, AWS IAM or identity governance tooling such as SailPoint, access policy management across S3, RDS, DynamoDB, and Redshift, familiarity with UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, relevant certifications such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or AWS/Azure security certifications, security-scan remediation tracking with Snyk, Wiz, Qualys, or Burp, secrets or certificate rotation programs, background supporting legal-tech, healthcare, or government SaaS products handling regulated data.