Senior Security Compliance Engineer
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobWe're looking for a Senior Security Compliance Engineer to join our team in Spain in a remote working mode. In this role, you will operate at the intersection of compliance and engineering delivery, ensuring regulatory and audit requirements are translated into actionable work items, implemented effectively and validated through evidence collection.
You will contribute to major compliance initiatives, supporting FedRAMP Moderate authorization, HIPAA Security/Privacy Rule adherence and NIST 800-53 control implementation, eventually extending coverage to global privacy frameworks. This opportunity offers a chance to shape compliance programs for highly regulated government and enterprise clients, reduce operational risk and enable secure product delivery in cloud environments.
- Translate regulatory and audit requirements (HIPAA, NIST 800-53) into scoped engineering tasks with clear acceptance criteria
- Maintain backlog hygiene across compliance initiatives for Azure DevOps/Jira features
- Test and validate technical security controls such as access restrictions, log retention and data deletion, documenting test outcomes
- Support third-party audits (FedRAMP, SOC 2) by mapping controls to evidence, coordinating data collection and delivering on schedule
- Develop recurring compliance reporting and create automation scripts or dashboards for monitoring and evidence collection
- Collaborate with ISRM, Privacy Office, Legal, SRE and platform teams to document shared versus owned controls in cloud architectures
- Monitor progress of identified compliance gaps to ensure timely remediation
- Assist with Significant Change Reviews (SCR) for FedRAMP and similar compliance frameworks
- Contribute to enhancing continuous improvement of compliance programs through process refinement and tooling updates
- 3+ years of experience in security or privacy compliance, GRC or compliance engineering roles
- In-depth knowledge of HIPAA Security and Privacy rules and NIST 800-53 control families
- Experience transforming regulatory language into structured, estimable backlog items in Azure DevOps or Jira
- Proven track record supporting audits such as SOC 2, FedRAMP or HITRUST including evidence collection and auditor interactions
- Familiarity with cloud security in AWS or Azure, including IAM/RBAC, audit logging, encryption and data lifecycle controls
- Strong communication and stakeholder coordination skills
- Ability to work remotely with partial US time zone overlap (until at least 11:00 AM CST)
- Direct experience with FedRAMP Significant Change Requests (SCR) and assessor engagement
- Scripting proficiency in Python or Bash for automation of controls and compliance dashboards
- Exposure to international privacy laws such as GDPR, PIPEDA or equivalent frameworks
- Familiarity with identity governance platforms (e.g., SailPoint) and policy enforcement in cloud services
- Experience addressing vulnerability tracking systems (Snyk, Wiz, Qualys) and remediation activities
- Relevant certifications such as CIPP/US, CIPM, HCISPP, CISA, CISSP or AWS/Azure security certifications
- Prior experience in legal-tech, healthcare or government SaaS environments handling regulated datasets
