Senior Cloud Security Specialist
Digital nomads. Work from anywhereCompany: EPAM Systems
We are seeking a Senior Cloud Security Specialist to lead compliance engineering efforts across HIPAA and FedRAMP/NIST 800-53 programs, translating regulatory requirements into actionable engineering work while supporting third-party audits and cross-functional compliance initiatives.
Unlock the potential of remote work in Kazakhstan, giving you the flexibility to work from home or access our offices in Astana, Almaty or Karaganda.
Responsibilities
* Convert HIPAA gap analyses, NIST 800-53 privacy controls, and audit findings into scoped Azure DevOps Features/Stories/Tasks with clear acceptance criteria, effort estimates, and a named owner
* Maintain backlog hygiene across active compliance features, including access control, data classification, log scrubbing, audit logging, data retention & deletion, and data access restrictions
* Close ownership and sprint-assignment gaps before they escalate into RAID-log risks
* Write and execute test cases to verify controls work as designed, such as privileged-access restrictions, time-bound SailPoint access, PII minimization, and deletion-on-request
* Document pass/fail evidence for control testing activities
* Own the intake, tracking, and fulfillment of third-party auditor evidence requests, including Schellman FedRAMP Significant Change Reviews
* Map each auditor request to the relevant NIST 800-53 control and coordinate with engineering, ISRM, Privacy, and Legal to gather artifacts
* Deliver evidence and documentation on the auditor's schedule
* Produce recurring compliance status reporting for stakeholders
* Build lightweight automation, including scripts, dashboards, and evidence pipelines, to reduce manual effort in future audit cycles
* Partner with ISRM, Privacy Office, Legal, SRE, and cloud platform teams to document controls inherited from AWS/Azure versus controls that must be built or owned internally
Requirements
* 3+ years of experience in security/privacy compliance, GRC, or compliance engineering, supporting HIPAA and/or FedRAMP/NIST 800-53 programs
* Knowledge of the HIPAA Security & Privacy Rules, including administrative, physical, and technical safeguards, BAAs, breach notification, and minimum necessary standards
* Understanding of NIST 800-53 control families, such as AC, AU, SI, and PM
* Demonstrated ability to turn compliance/regulatory language into scoped, estimable engineering backlog items using Azure DevOps, Jira, or similar tools
* Direct experience supporting third-party audits such as SOC 2, FedRAMP, or HITRUST, including evidence collection, control-to-evidence mapping, and meeting auditor deadlines
* Familiarity with cloud environments such as AWS GovCloud and/or Azure Government
* Knowledge of compliance-relevant controls, including IAM/RBAC, encryption/KMS, and audit logging, as well as data retention & deletion practices
* English proficiency at B2 level or higher
Nice to have
* Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagements
* Skills in scripting/automation using Python or Bash to automate evidence collection, control testing, or compliance dashboards
* Experience with AWS IAM/identity governance tooling such as SailPoint or equivalent, and access policy management across S3, RDS, DynamoDB, and Redshift
* Familiarity with international privacy regimes such as UK/EU GDPR, Australia Privacy Act, or Canada PIPEDA, or readiness to ramp quickly as coverage expands
* Relevant certifications such as CIPP/US, CIPM, HCISPP, CISA, CISSP, or an AWS/Azure security certification
* Experience with security-scan remediation tracking using tools such as Snyk, Wiz, Qualys, or Burp, and secrets/certificate rotation programs
* Background supporting legal-tech, healthcare, or government SaaS products handling regulated data
We offer
* We connect like-minded people:
* Delivering innovative solutions to industry leaders, making a global impact
* Enjoyable working environment, whether it is the vibrant office or the comfort of your own home
* Opportunity to work abroad for up to two months per year
* Relocation opportunities within our offices in 55+ countries
* Corporate and social events
* We invest in your growth:
* Leadership development, career advising, soft skills and well-being programs
* Certifications, including GCP, Azure and AWS
* Unlimited access to EPAM's internal learning database
* Free English classes with certified teachers
* Discounts in local language schools, including online courses for the Kazakh language
* We cover it all:
* Participation in the Employee Stock Purchase Plan
* Monetary bonuses for engaging in the referral program
* Medical & family care package
* Six trust days per year (sick leave without a medical certificate)
* Coverage of psychology sessions of your choice
* Benefits package (sports activities, a variety of stores and services)
* Housing support program: preferential mortgage access via Otbasy Bank partnership
EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.