Senior Cloud Security Engineer (Remote Canada)

🏢 Smile Digital Health · all 16 jobs
📍 Canada
💰 CAD 130,000 - 140,000 / annual
📅 Posted Sep 13, 2026 · via Himalayas
🏷 Cloud Security Engineering, Cloud Infrastructure Engineering, Devsecops Engineering, Healthcare It Engineering, Platform Engineering, Senior Cloud Infrastructure Security Engineer +5 more
Apply on original site ↗

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth . We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte's Technology Fast 50 Ranking for 2024!

Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.
At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing #BetterGlobalHealth to patients everyday!
Apply today and find plenty of reasons to SMILE!
The Senior Cloud Security Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP.
This role combines strategic security architecture with hands-on operational execution owning cloud security posture management (CSPM), threat detection and response, application security testing (SAST/DAST), and RBAC governance. The successful candidate works closely with DevOps, Platform Engineering, and Development teams to embed security throughout the software delivery lifecycle and ensure all environments meet healthcare-grade compliance requirements
Responsibilities:

- Design, implement, and continuously improve cloud security architecture and controls across Azure-based environments.

- Lead threat modelling, vulnerability assessments, and security architecture reviews for cloud-native and hybrid infrastructure.

- Own and operate cloud security posture management (CSPM) using Prisma Cloud — configure policies, monitor posture, triage findings, and drive remediation with engineering teams.

- Deploy, tune, and manage Microsoft Defender for Cloud (and related Defender suite products) across Azure subscriptions; investigate alerts and drive incident response.

- Integrate SAST and DAST tooling into CI/CD pipelines; triage findings, define severity thresholds, and partner with developers to close vulnerabilities prior to production release.

- Own the RBAC governance process: design role models, conduct periodic access reviews, enforce least-privilege principles, and document role assignments across Azure and application layers.

- Collaborate with DevOps and Platform Engineering teams to embed security controls (secrets management, image scanning, policy-as-code) into DevOps pipelines and IaC workflows (Terraform, Ansible).

- Act as SME for security compliance frameworks relevant to healthcare data (SOC 2, HIPAA, ISO 27001, PHIPA/PHIPPA); map controls and support audits.

- Provide Level 3 escalation for security incidents; participate in on-call rotation for incident response and forensic triage.

- Lead and educate internal teams and clients on cloud security best practices, secure-by-design patterns, and zero-trust principles.

- Document security runbooks, post-incident reviews, threat models, and lessons learned; maintain a living security knowledge base.

- Ensure all working hours are accurately reported in the Time tracking system; the majority of hours are expected to be billed to client engagements.

- Comply with all privacy, security, and confidentiality policies; hold all PHI and confidential information in strict confidence throughout and after employment.

Requirements :

- 7+ years of hands-on experience in cloud security, with the majority of that experience focused on Microsoft Azure (Azure Security Center, Azure Policy, Azure AD / Entra ID, Key Vault, NSGs, Private Endpoints, Defender for Cloud).

- Proven, production-level experience with Prisma Cloud (CSPM/CWPP) — policy management, alert triage, and remediation workflows.

- Hands-on experience with Microsoft Defender for Cloud and th

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs →

Get remote developer jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you