Senior Cloud Security Engineer (Remote Ontario)
Summary
Designs, secures, and deploys cloud infrastructure for healthcare data platforms across AWS, Azure, OCI, and GCP, ensuring compliance with SOC2, HIPAA, and ISO27001 while supporting FHIR-based solutions.
Responsibilities:
- Design, implement, and continuously improve cloud security architecture and controls across Azure-based environments.
- Lead threat modelling, vulnerability assessments, and security architecture reviews for cloud-native and hybrid infrastructure.
- Own and operate cloud security posture management (CSPM) using Prisma Cloud — configure policies, monitor posture, triage findings, and drive remediation with engineering teams.
- Deploy, tune, and manage Microsoft Defender for Cloud (and related Defender suite products) across Azure subscriptions; investigate alerts and drive incident response.
- Integrate SAST and DAST tooling into CI/CD pipelines; triage findings, define severity thresholds, and partner with developers to close vulnerabilities prior to production release.
- Own the RBAC governance process: design role models, conduct periodic access reviews, enforce least-privilege principles, and document role assignments across Azure and application layers.
- Collaborate with DevOps and Platform Engineering teams to embed security controls (secrets management, image scanning, policy-as-code) into DevOps pipelines and IaC workflows (Terraform, Ansible).
- Act as SME for security compliance frameworks relevant to healthcare data (SOC 2, HIPAA, ISO 27001, PHIPA/PHIPPA); map controls and support audits.
- Provide Level 3 escalation for security incidents; participate in on-call rotation for incident response and forensic triage.
- Lead and educate internal teams and clients on cloud security best practices, secure-by-design patterns, and zero-trust principles.
- Document security runbooks, post-incident reviews, threat models, and lessons learned; maintain a living security knowledge base.
- Ensure all working hours are accurately reported in the Time tracking system; the majority of hours are expected to be billed to client engagements.
- Comply with all privacy, security, and confidentiality policies; hold all PHI and confidential information in strict confidence throughout and after employment.
Requirements :
- 7+ years of hands-on experience in cloud security, with the majority of that experience focused on Microsoft Azure (Azure Security Center, Azure Policy, Azure AD / Entra ID, Key Vault, NSGs, Private Endpoints, Defender for Cloud).
- Proven, production-level experience with Prisma Cloud (CSPM/CWPP) — policy management, alert triage, and remediation workflows.
- Hands-on experience with Microsoft Defender for Cloud and the broader Microsoft Defender suite (Defender for Servers, Containers, Identity, Endpoint).
- Practical experience implementing and operating SAST and DAST tools (e.g., MEND, SonarQube,GitHub Advanced Security, OWASP ZAP, Burp Suite) within CI/CD pipelines.
- Deep familiarity with DevOps pipeline security securing GitHub Actions / Azure DevOps pipelines, secrets management (Azure Key Vault, HashiCorp Vault), container image scanning, and supply-chain security.
- Strong RBAC design and governance experience, building and enforcing role models, access review processes, and least-privilege controls across Azure and multi-tier application stacks.
- Solid IaC experience with Terraform and/or Ansible; ability to write and review security-hardened infrastructure code.
- Experience with Kubernetes / OpenShift and container security (runtime protection, admission controllers, image policies).
- Solid understanding of networking fundamentals as they apply to cloud security: VNets, NSGs, Azure Firewall, Private Link, Zero Trust network segmentation.
- Demonstrated knowledge of compliance frameworks applicable to healthcare (SOC 2, HIPAA, ISO 27001, PHIPA); experience supporting audits and mapping technical controls.
- Professional cloud or security certifications preferred (e.g., AZ-500, MS-500, SC-200, CCSP, CISSP, or equivalent).
- Excellent written and verbal communication skills; ability to convey complex security concepts to both technical and non-technical stakeholders
This position is a new role, created to support Smile’s continued growth and commitment to operational excellence.
Skills
- AI
- Ansible
- AWS
- Azure
- Azure AD
- Azure DevOps
- Burp Suite
- CI/CD
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- Container Security
- DAST
- DevOps
- Entra ID
- FHIR
- Firewall
- GCP
- GitHub
- GitHub Actions
- hapi
- Hipaa
- Infrastructure as Code
- ISO 27001
- Kubernetes
- Networking
- OpenShift
- OWASP
- RBAC
- SAST
- Secrets Management
- SOC 2
- SonarQube
- Terraform
- Vault
- Zero Trust
As published by lever · 14 questions · 7 written answers
Basics
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website, I identify my ethnicity as, What gender do you identify as?, Do you identify as someone with a disability?, Are you a Veteran, What is your preferred pronoun?
Short answers (1)
- What are your salary expectation?
Pick from a list (6)
- I consent to receive SMS/text messages regarding my job application with Smile Digital Health. These messages may include updates on my application status, interview invitations, reminders, and other information directly related to this job application. Message frequency will vary. Message and data rates may apply. Reply HELP for help or STOP to cancel. For more information, please review the Terms and Conditions for SMS/Text Messaging linked at the end of this form. optional
- Are you legally authorized to work in Canada? optional
- Will you now or in the future require sponsorship in order to begin or continue employment in the Canada? optional
- Have you been convicted of a crime of which a pardon has not been granted? optional
- How did you hear about this opportunity? optional
- Our standard working hours are 9:00 AM to 5:00 PM Eastern Time. Since we work remotely with teams across different time zones, would you be flexible and available to work outside of these hours if needed? optional
Written answers (7)
- What is your reason for seeking a new opportunity or considering a job change?
- What motivates you to work with us?
- What is your earliest possible start date? What is your current notice period (if applicable)?
- Any planned or upcoming vacation within next 6 months optional
- Do you have hands-on experience with Prisma Cloud? Please briefly describe your experience and how you have used it ? optional
- Do you have hands-on experience implementing or managing SAST and/or DAST solutions? Please briefly describe the tools you have used and how you integrated them ? optional
- o you have hands-on experience with Azure Kubernetes Service (AKS)? Please briefly describe your experience with AKS. optional