About the Role
This new role supports Smile's growth and commitment to operational excellence by designing, deploying, and operating production-grade Azure Kubernetes Service (AKS) clusters. The position owns the platform end-to-end, focusing on cluster internals, networking, security, reliability, and performance tuning.
Responsibilities
- Act as the subject-matter expert (SME) for Kubernetes deployments, troubleshooting, and production issues across all environments.
- Design and deploy Azure Kubernetes Service (AKS) clusters with private cluster configurations, managed identities, and RBAC.
- Own the health, scaling, and lifecycle management of production AKS clusters, including upgrades, node pool management, autoscaling, and capacity planning.
- Configure AKS networking, including Azure CNI, internal load balancers, and ingress controllers (NGINX, Traefik).
- Design and maintain integrations between AKS with Azure Container Registry (ACR), Key Vault via CSI driver, Azure Monitor for containers, Azure SQL, Kafka/Event Hubs, Azure Storage, and other client-facing dependencies (DNS resolution, firewall rules, private endpoints, and service connectivity).
- Manage containerized application deployments using Docker and Helm; maintain reusable chart and templating standards, namespaces, resource quotas, and Azure Policy for AKS.
- Harden AKS environments through policy enforcement, network policies, and image scanning.
- Own container and cluster vulnerability management: scanning, triage, prioritization, and remediation coordination with engineering teams.
- Contribute to Terraform-based infrastructure as code for provisioning and managing Azure resources.
- Support Azure DevOps (or equivalent) CI/CD pipelines, including GitOps workflows (Flux/ArgoCD), to reduce deployment risk and improve release velocity.
- Design, implement, and manage observability across the Grafana stack (Prometheus, Loki, Tempo) and Azure-native tooling (Azure Monitor, Log Analytics Workspace, Application Insights) for critical systems; define SLIs/SLOs and tune alerting to reduce noise.
- Collaborate with performance engineering and application teams to identify, diagnose, and resolve performance bottlenecks spanning the AKS platform and its dependent services (database, messaging, network) to right-size node pools and workloads based on observed performance and utilization trends.
- Contribute to Disaster Recovery and Business Continuity Planning (DR/BCP) procedures for AKS-hosted workloads, including cross-team failover drill participation and RTO/RPO validation.
- Provide escalation support for production Kubernetes and infrastructure incidents; participate in on-call rotation, lead root-cause analysis, and drive preventative follow-up actions.
- Document runbooks and post-incident reviews, and operational knowledge; maintain a living knowledge base to reduce tribal knowledge.
Requirements
- 5+ years of hands-on Kubernetes experience, including at least 2 years running AKS in production.
- Strong knowledge of Kubernetes internals scheduling, networking, storage, RBAC.
- Proficiency in Azure CNI networking and AKS private cluster configuration.
- Hands-on experience integrating AKS with Azure PaaS services (ACR, AKV, Azure SQL, Kafka and Managed Identities) and troubleshooting network-layer dependencies (DNS, firewall, private endpoints).
- Experience with Helm and GitOps workflows (Flux/ArgoCD).
- Working knowledge of Terraform for infrastructure as code.
- Working knowledge of Azure DevOps or similar CI/CD tooling.
- Hands-on experience implementing and operating observability platforms: Grafana stack (Prometheus, Loki, Tempo) and Azure-native monitoring (Azure Monitor, Log Analytics, Application Insights); experience defining SLIs/SLOs for production systems.
- Practical experience with container/cluster vulnerability management and remediation workflows.
- Scripting skills in Bash, Python.
- Excellent written and verbal communication skills; able to convey technical issues clearly to both technical and non-technical stakeholders.
Skills
- Kubernetes
- Azure Kubernetes Service (AKS)
- AKS internals
- Networking
- Security hardening
- Reliability
- Cluster architecture
- CI/CD
- Performance tuning
- Observability
- Incident response
- Kubernetes deployments
- Production issues
- Private cluster configurations
- Managed identities
- RBAC
- Health management
- Scaling
- Lifecycle management
- Upgrades
- Node pool management
- Autoscaling
- Capacity planning
- Azure CNI
- Internal load balancers
- Ingress controllers (NGINX, Traefik)
- Azure Container Registry (ACR)
- Key Vault via CSI driver
- Azure Monitor for containers
- Azure SQL
- Kafka/Event Hubs
- Azure Storage
- DNS resolution
- Firewall rules
- Private endpoints
- Service connectivity
- Docker
- Helm
- Reusable chart and templating standards
- Namespaces
- Resource quotas
- Azure Policy for AKS
- Policy enforcement
- Network policies
- Image scanning
- Container vulnerability management
- Cluster vulnerability management
- Scanning
- Triage
- Prioritization
- Remediation coordination
- Terraform
- Infrastructure as code
- Azure DevOps
- GitOps workflows (Flux/ArgoCD)
- Release velocity
- Grafana stack (Prometheus, Loki, Tempo)
- Azure-native tooling (Azure Monitor, Log Analytics Workspace, Application Insights)
- SLIs/SLOs
- Alerting
- Performance engineering
- Database
- Messaging
- Network
- Disaster Recovery (DR)
- Business Continuity Planning (BCP)
- RTO/RPO validation
- Escalation support
- On-call rotation
- Root-cause analysis
- Runbooks
- Post-incident reviews
- Operational knowledge
- Bash
- Python
Location
- Remote
Work Type
- Remote Work Environment
Experience Level
- 5+ years of hands-on Kubernetes experience
- 2 years running AKS in production
Education Level
- Certified Kubernetes Administrator (CKA)
- CKAD certification
- Microsoft Certified: Azure Administrator (AZ-104)
Salary/Compensations
- $115,000 - $130,000 a year
Benefits
- Remote Work Environment
- Flexible Time Away From Work Policy including PTO, Personal and Sick Days
- Competitive Salary and Health/Medical Benefits
- RRSP/TFSA/401K Employee Contribution
- Life and Disability
- Employee Assistance Program
- FHIR Study Program and Skillsoft Learning
- Super HAPI Fun Club
About the Company
- Smile Digital Health supports the mandate for #BetterGlobalHealth through its innovative health data platform and data management solutions, used in over 20 countries.
- The company was #19 on Deloitte's Technology Fast 50 Ranking for 2024.
- Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with its leading FHIR-based data liberation platform.
- The Smile platform enables people and organizations to better manage healthcare data, generating and liberating structured healthcare data for effective delivery across care teams and health systems.
Equal Opportunity
- Smile discloses that artificial intelligence (AI) may be used in portions of the recruitment and selection process, such as resume screening or application assessment. All hiring decisions are ultimately made by qualified human decision-makers, and AI tools are used to support — not replace — fair and equitable hiring practices.
- Smile's core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success.
- We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.
- We are dedicated to fostering a workplace that values diversity, equity, and inclusion.
- We welcome and encourage candidates of all backgrounds to apply.
- Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.
