Logo for Smile Digital Health

Senior Cloud Security Engineer (Remote Ontario)

Role overview

Qualifications

  • 7+ years of hands-on experience in cloud security, mainly focused on Microsoft Azure
  • Proven experience with Prisma Cloud (CSPM/CWPP)
  • Experience with Microsoft Defender for Cloud and broader Defender suite
  • Knowledge of compliance frameworks applicable to healthcare (SOC 2, HIPAA, ISO 27001, PHIPA)

Responsibilities

  • Design, implement, and continuously improve cloud security architecture and controls across Azure-based environments
  • Lead threat modelling, vulnerability assessments, and security architecture reviews for cloud-native and hybrid infrastructure
  • Own and operate cloud security posture management (CSPM) using Prisma Cloud
  • Integrate SAST and DAST tooling into CI/CD pipelines

Key facts

Hard skills

Other skills

  • Communication

About the company

Smile Digital Health logo

Smile Digital Health

Digital Health & Health Tech

Smile Digital Health (doing business as Smile CDR Inc.) specializes in delivering fast, secure, compliant data infrastructures as a service to enable and empower interconnectivity for data-intensive sectors such as healthcare. We are a solutions platform helping organizations like governments, researchers, health systems, healthcare providers, and app developers build connected health solutions and products by leveraging our core expertise in health data and HL7 FHIR.Our flagship product, Smile CDR, is the world’s first FHIR-based clinical data repository (CDR) as a service. Smile CDR is a high performance and secure solution built on the principles of Privacy by Design. Flexibility is a hallmark of the service as it can be hosted in the cloud or on-premises depending on your needs. The design was strongly influenced by real-world experience in both the jurisdictional and organizational setting. Smile CDR provides a rich set of features and capabilities including:-Multiple FHIR versions-FHIR Profiles-Full text indexing of clinical records-Type ahead search functionality-FHIR, HL7v2 and custom ETL for data input-Federated identity and identity provider functionality-International character locale support-Terminology services-Auditing-Smart on FHIR support-Rapid deployment-Extensive administrative toolingLeveraging more than 40 years of experience in building enterprise-class systems, our team includes experts in building integrated healthcare systems including FHIR-based solutions such as HAPI, e-prescriptions and other e-health solutions. We were motivated by the need to improve upon existing options for sharing health data within and across organizations.Smile CDR is the maintainer of HAPI FHIR, the prevailing open source reference implementation of FHIR worldwide

Company details

Company typeScaleup
IndustryDigital Health & Health Tech
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte's Technology Fast 50 Ranking for 2024!  Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform. At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!
Apply today and find plenty of reasons to SMILE!
The Senior Cloud Security Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP.   This role combines strategic security architecture with hands-on operational execution owning cloud security posture management (CSPM), threat detection and response, application security testing (SAST/DAST), and RBAC governance. The successful candidate works closely with DevOps, Platform Engineering, and Development teams to embed security throughout the software delivery lifecycle and ensure all environments meet healthcare-grade compliance requirements
Responsibilities:
  • Design, implement, and continuously improve cloud security architecture and controls across Azure-based environments.
  • Lead threat modelling, vulnerability assessments, and security architecture reviews for cloud-native and hybrid infrastructure.
  • Own and operate cloud security posture management (CSPM) using Prisma Cloud — configure policies, monitor posture, triage findings, and drive remediation with engineering teams.
  • Deploy, tune, and manage Microsoft Defender for Cloud (and related Defender suite products) across Azure subscriptions; investigate alerts and drive incident response.
  • Integrate SAST and DAST tooling into CI/CD pipelines; triage findings, define severity thresholds, and partner with developers to close vulnerabilities prior to production release.
  • Own the RBAC governance process: design role models, conduct periodic access reviews, enforce least-privilege principles, and document role assignments across Azure and application layers.
  • Collaborate with DevOps and Platform Engineering teams to embed security controls (secrets management, image scanning, policy-as-code) into DevOps pipelines and IaC workflows (Terraform, Ansible).
  • Act as SME for security compliance frameworks relevant to healthcare data (SOC 2, HIPAA, ISO 27001, PHIPA/PHIPPA); map controls and support audits.
  • Provide Level 3 escalation for security incidents; participate in on-call rotation for incident response and forensic triage.
  • Lead and educate internal teams and clients on cloud security best practices, secure-by-design patterns, and zero-trust principles.
  • Document security runbooks, post-incident reviews, threat models, and lessons learned; maintain a living security knowledge base.
  • Ensure all working hours are accurately reported in the Time tracking system; the majority of hours are expected to be billed to client engagements.
  • Comply with all privacy, security, and confidentiality policies; hold all PHI and confidential information in strict confidence throughout and after employment.

  • Requirements :
  • 7+ years of hands-on experience in cloud security, with the majority of that experience focused on Microsoft Azure (Azure Security Center, Azure Policy, Azure AD / Entra ID, Key Vault, NSGs, Private Endpoints, Defender for Cloud).
  • Proven, production-level experience with Prisma Cloud (CSPM/CWPP) — policy management, alert triage, and remediation workflows.
  • Hands-on experience with Microsoft Defender for Cloud and the broader Microsoft Defender suite (Defender for Servers, Containers, Identity, Endpoint).
  • Practical experience implementing and operating SAST and DAST tools (e.g., MEND, SonarQube,GitHub Advanced Security,  OWASP ZAP, Burp Suite) within CI/CD pipelines.
  • Deep familiarity with DevOps pipeline security securing GitHub Actions / Azure DevOps pipelines, secrets management (Azure Key Vault, HashiCorp Vault), container image scanning, and supply-chain security.
  • Strong RBAC design and governance experience, building and enforcing role models, access review processes, and least-privilege controls across Azure and multi-tier application stacks.
  • Solid IaC experience with Terraform and/or Ansible; ability to write and review security-hardened infrastructure code.
  • Experience with Kubernetes / OpenShift and container security (runtime protection, admission controllers, image policies).
  • Solid understanding of networking fundamentals as they apply to cloud security: VNets, NSGs, Azure Firewall, Private Link, Zero Trust network segmentation.
  • Demonstrated knowledge of compliance frameworks applicable to healthcare (SOC 2, HIPAA, ISO 27001, PHIPA); experience supporting audits and mapping technical controls.
  • Professional cloud or security certifications preferred (e.g., AZ-500, MS-500, SC-200, CCSP, CISSP, or equivalent).
  • Excellent written and verbal communication skills; ability to convey complex security concepts to both technical and non-technical stakeholders
  • Smile discloses that artificial intelligence (AI) may be used in portions of the recruitment and selection process, such as resume screening or application assessment. All hiring decisions are ultimately made by qualified human decision-makers, and AI tools are used to support — not replace — fair and equitable hiring practices. 
    This position is a new role, created to support Smile’s continued growth and commitment to operational excellence.
    Some of the benefits we offer:* Remote Work Environment* Flexible Time Away From Work Policy including PTO, Personal and Sick Days* Competitive Salary and Health/Medical Benefits* RRSP/TFSA/401K Employee Contribution* Life and Disability* Employee Assistance Program* FHIR Study Program and Skillsoft Learning* Super HAPI Fun Club
    Smile's core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion. We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    Cloud Security Engineer Related jobs

    Other jobs at Smile Digital Health

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.