03 Oct
|
Smiledigitalhealth
|
Mississauga
03 Oct
Smiledigitalhealth
Mississauga
Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth . We strive towards this goal every day, and the results can be seen in the impact of our creative health data platform and data management solutions, which are used in over 20 countries.
Smile Digital
Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform. At its heart, the Smile platform enables people and organizations to better manage healthcare data. We helpgenerate andliberate structured healthcare data to ensure effective delivery across care teams and health systems bringing #BetterGlobalHealth to patients everyday!
The Senior Cloud Security
Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP. This role combines strategic security architecture with hands-on operational execution owning cloud security posture management (CSPM), threat detection and response, application security testing (SAST/DAST), and RBAC governance. The successful candidate works closely with DevOps, Platform Engineering, and Development teams to embed security throughout the software delivery lifecycle and ensure all environments meet healthcare-grade compliance requirements Design, implement, and continuously improve cloud security architecture and controls across Azure-based environments.
Lead threat modelling, vulnerability assessments, and security architecture reviews for cloud-native and hybrid infrastructure. Own and operate cloud security posture management (CSPM) using Prisma Cloud — configure policies, monitor posture, triage findings, and drive remediation with engineering teams. Deploy, tune, and manage Microsoft Defender for Cloud (and related Defender suite products)
across Azure subscriptions; Integrate SAST and DAST tooling into CI/CD pipelines; Collaborate with DevOps and Platform Engineering teams to embed security controls (secrets management, image scanning, policy-as-code) into DevOps pipelines and IaC workflows (Terraform, Ansible).
Act as SME for security compliance frameworks relevant to healthcare data (SOC 2, HIPAA, ISO 27001, PHIPA/PHIPPA); Provide Level 3 escalation for security incidents; participate in on-call rotation for incident response and forensic triage. Lead and educate internal teams and clients on cloud security best practices, secure-by-design patterns, and zero-trust principles. Document security runbooks, post-incident reviews, threat models, and lessons learned; maintain a living security knowledge base.
Comply with all privacy, security, and confidentiality policies; 7+ years of hands-on experience in cloud security, with the majority of that experience focused on Microsoft Azure (Azure Security Center, Azure Policy, Azure AD / Entra ID, Key Vault, NSGs, Private Endpoints, Defender for Cloud). ~ Proven, production-level experience with Prisma Cloud (CSPM/CWPP) — policy management, alert triage, and remediation workflows. ~ Hands-on experience with Microsoft Defender for Cloud and the broader Microsoft Defender suite (Defender for Servers, Containers, Identity, Endpoint). ~ MEND, SonarQube,GitHub Advanced Security, OWASP ZAP, Burp Suite) within CI/CD pipelines.
~ Deep familiarity with DevOps pipeline security securing GitHub Actions / Azure DevOps pipelines, secrets management (Azure Key Vault, HashiCorp Vault), container image scanning, and supply-chain security. ~ Strong RBAC design and governance experience, building and enforcing role models, access review processes, and least-privilege controls across Azure and multi-tier application stacks. ~ Solid IaC experience with Terraform and/or Ansible; ability to write and review security-hardened infrastructure code. ~ Experience with Kubernetes / OpenShift and container security (runtime protection, admission controllers, image policies). ~ Solid understanding of networking fundamentals as they apply to cloud security: VNets, NSGs, Azure Firewall, Private Link, Zero Trust network segmentation. ~ experience supporting audits and mapping technical controls. ~ Professional cloud or security certifications preferred (e.g., ability to convey complex security concepts to both technical and non-technical stakeholders Smile discloses that artificial intelligence (AI) may be used in portions of the recruitment and selection process, such as resume screening or application assessment. All hiring decisions are ultimately made by qualified human decision-makers, and AI tools are used to support — not replace — fair and equitable hiring practices.
Remote Work Environment Flexible Time Away
From Work Policy including PTO, Personal and Sick Days Competitive Salary and Health/Medical Benefits Life and Disability Employee Assistance Program Smile's core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are dedicated to fostering a workplace that values diversity, equity, and inclusion.
📌 Senior Cloud Security Engineer (Remote Ontario) (Mississauga)
🏢 Smiledigitalhealth
📍 Mississauga