Cloud Security Specialist

  • Full-time
  • Department: R&D
  • Province: Quebec

Company Description

MEDFAR Clinical Solutions was founded in 2010 by two aeronautical engineers who realized that the healthcare system was not exploiting the full potential of technology. Supported by a large community of medical experts and focused on clinical success and patient safety, MEDFAR was the first company to certify a cloud-based Electronic Medical Record in Canada: MYLE (Make Your Life Easy).

Committed to promoting excellence and effectiveness in healthcare worldwide, MEDFAR differentiates itself by offering a unique healthcare management solution for clinics, which replaces inefficient processes with a faster and safer technological alternative.

Job Description

As a Cloud Security Specialist, you will lead the integration of security practices within our R&D department. You will be helping our development teams to design, implement, and maintain secure, scalable, and efficient software architecture. You will ensure that security is baked into every step of the software development lifecycle. Your work will directly impact the security posture of our applications and services, ensuring the integrity and reliability of our deployments.

What you'll do:

  • Lead the design and implementation of secure software architecture, CI/CD pipelines for .NET applications on Azure, integrating security best practices and tools to ensure code quality and security.

  • Provide technical leadership and mentorship to the development teams as well as collaborate to establish a security-focused roadmap.

  • Assist with internal penetration testing duties and security assessments for our cloud infrastructure and applications, identifying vulnerabilities and implementing effective mitigation strategies.

  • Help design and deploy robust authentication systems, enhancing the security of user data and access controls.

  • Drive the integration of DevSecOps practices into the development lifecycle, ensuring continuous security from code to cloud.

  • Collaborate with development teams to incorporate .NET security features and best practices into application design and deployment.

  • Stay updated on the latest in security threats, vulnerabilities, and mitigation technologies, adapting our strategy to continuously protect against risks.

  • Develop and maintain comprehensive documentation on security configurations, procedures, and audits.

  • Provide technical leadership and mentorship to our teams on DevSecOps best practices, tools, and technologies.

  • Work closely with cross-functional teams to ensure compliance with all regulatory and industry security standards and certifications.

Qualifications

Who you are:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Proven experience as a DevOps Engineer or similar role with a strong focus on security and DevSecOps practices, preferably in an Azure environment.

  • Knowledge and experience of penetration testing tools and methodologies, along with a deep understanding of authentication protocols, application security, and web security principles.

  • Proficient in designing and implementing CI/CD pipelines, with a solid grasp of tools like SonarQube, ensuring code quality and security.

  • Familiarity with Microsoft and .NET ecosystem security features, best practices, and the integration of security into CI/CD pipelines.

  • Demonstrated ability to lead and mentor teams in the adoption of DevSecOps practices.

  • Excellent problem-solving skills with the ability to work independently or as part of a team.

  • Strong communication and leadership skills, with the capability to guide and influence technical teams and stakeholders.

  • Relevant certifications (e.g CISSP, Security+, A+, OSCP, OSCE, OSWE, Azure Security Engineer, DevSecOps, etc.) are highly desirable.

 

Working conditions:

  • Contract: Permanent, full-time (40h/week)

  • Working mode: Hybrid or remote

    • Occasional in-office presence may be required during the year (for events or team meetings, for example).

    • Candidates must reside in the province of Quebec.

Additional Information

  • Remote work and flexibility (supporting work-life balance)

  • RRSP contribution

  • Healthcare insurance from day one

  • Paid time off: 3 weeks + 1 additional week between Christmas and New Year

  • Annual training allowance to support your professional development

  • An onboarding program to help you get familiar with our environment and the digital healthcare field

  • All IT equipment is provided, with additional gear if needed

  • Internal growth opportunities (promotions, internal mobility)

  • Support from a wellness and social committee, with initiatives to foster team cohesion, mental health, and employee well-being

  • A company culture focused on transparency, collaboration, and innovation

  • Join a dynamic and innovative environment where your work has a real and wide-reaching impact, helping to modernize healthcare in Canada and internationally

With offices around the world, fluency in both French and English is a must at MEDFAR. Because of the need to communicate with colleagues and/or customers in other provinces or countries, bilingualism enables us to communicate in both languages while promoting the use of French. 

At MEDFAR, we value diversity, equity and inclusion within our team. We are committed to providing a work environment where every individual feels respected and supported, regardless of their background, identity or abilities.As part of our commitment to a fair and inclusive recruitment process, we offer accommodation to candidates who request it. If you need accommodation during your interview, please let us know so that we can provide you with an adapted experience.

MEDFAR has voluntarily subscribed to an Equal Employment Opportunity Program (EEOP). We encourage applications from women, visible minorities, ethnic minorities, aboriginal peoples and people with disabilities. When applying, we invite you to complete this section, which enables us to implement our Equal Employment Opportunity Program (EEOP). Self-identification is not compulsory, but may enable you to benefit from hiring or promotion measures if you have the skills required for the job.

To better understand the self-identification process, please consult this guide.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice