At Fullscript, were not just changing healthcarewere making it whole.
We help 100,000+ healthcare practitioners support 10 million patients with a platform that delivers evidence-based health solutions, diagnostic support, and practitioner toolsall in one place.
Healthcare today is disconnected. Were fixing that. Fullscript makes it easier for practitioners to treat the whole person, not just symptoms, so patients get the support they needwhen they need it.
Were building a better wayone where healthcare is connected, complete, and built for impact.
The Role
Were looking for an experienced Lead Security Engineer to help shape and strengthen Fullscripts security posture. Youll play a key role in embedding security across our development lifecycle, leading initiatives in DevSecOps, AppSec, GRC, security operations, and incident response.
This is an opportunity to tackle real-world security challenges, develop scalable security strategies, and work cross-functionally to ensure security is built into everything we do.
What You'll Do:
- Lead and mentor a security engineering team while partnering with teams like Engineering and IT to embed security throughout our development lifecycle.
- Define and implement security best practices, combining practical recommendations with automated guardrails.
- Drive security initiatives and provide technical guidance for infrastructure decisions, ensuring security is considered from design through implementation.
- Establish and optimize security triage processes, including SLAs, severity frameworks, and remediation protocols.
- Review feature designs and technical approaches to ensure features are developed with security in mind.
- Grow and expand our purple team capabilities.
- Sharing your knowledge and expertise with our developer community.
What You Bring:
- Demonstrated success mentoring and developing security engineering teams.
- Experience partnering with cross-organizational teams to drive security initiatives.
- Proven ability to translate complex security concepts for diverse technical audiences.
- Track record of building and optimizing security triage processes.
- Hands-on coding experience in at least one modern programming language.
- Understanding of industry frameworks (SOC2, PCI, HIPAA, HITRUST, NIST).
Bonus Points
- Background in automation and infrastructure as code (Terraform, CloudFormation).
- Container security and Kubernetes ecosystem security.
- Implementation of cloud security platforms (Wiz) and SIEM solutions.
- Compliance automation and continuous control monitoring (Drata).
- Edge security (WAF).
- Experience securing Ruby on Rails and Javascript applications.
- Experience in securing APIs (GraphQL).
- Experience with pen-test software (Burpsuite).
- Experience with software threat modelling.
- Database security best practices (MySQL, Postgres).
- Experience with security tooling integration in CI/CD pipelines (GitLab, GitHub Actions).
- Advanced Linux/Unix systems security.
What You Get:
- Flexible PTO & competitive paybecause balance fuels performance.
- RRSP match & stock optionsinvest in your future.
- Customizable benefitsflexible coverage, paramedical services, and an HSA.
- Fullscript discountssave on high-quality wellness products.
- Continuous learningtraining budget + company-wide initiatives.
- Wherever You Work Wellhybrid and remote flexibility.
Why Fullscript?
Great work happens when people are supported, challenged, and inspired. Here, youll be part of a team that:
⬦ Values innovationwe push boundaries and always look for better ways.
⬦ Supports growththrough learning, mentorship, and meaningful work.
⬦ Cares about balancewith flexible work options and time off when you need it.
? Apply nowlets build the future of healthcare, together.
Fullscript is an equal-opportunity employer committed to creating an inclusive workplace. Accommodations are available upon requestemail accommodations@fullscript.com for support.
Before joining the team, all candidates who receive and accept an offer will complete a background check.
? MORE INFO: www.fullscript.com | www.rupahealth.com | Follow us on social media @fullscriptHQ
IN THE NEWS: Fullscript acquires Rupa Health
Lets make healthcare whole
Please mention the word **LOVELINESS** and tag RODIuMjIzLjExNy43OA== when applying to show you read the job post completely (#RODIuMjIzLjExNy43OA==). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.
RemoteOK
Jornada completa, 100% remoto.
Cualquier lugar del mundo.