Fullscript
Posted 2mo ago

Staff, Security Engineer

Fullscript
Ottawa or Toronto or Calgary or Vancouver or Austin
RemoteFull Time
Responsibilities
  • designing solutions
  • embedding security
  • mentoring engineers
Requirements
  • 8+ years software engineering experience with 3+ years in application/product/security engineering
  • Deep knowledge of secure software development
  • Cloud-native architectures
  • Vulnerability management
  • Security tooling, and mentoring
Technical tools mentioned
Ruby on RailsNode.jsJavaScriptGraphQLAWSSTRIDEPASTAGitHubGitLabWiz

Job description

About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.

That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.

We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.

Bring your ideas, your grit, and your care for people.
Join us and shape the future of care.
The Opportunity

We're looking for a Staff Security Engineer to join Fullscript's Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.

You'll work closely with engineering teams to design and implement security solutions that scale across Fullscript's products and platforms. As a Staff-level engineer, you'll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You'll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.

We're looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.

What you'll do
  • Lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems.
  • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
  • Drive application security, product security, and vulnerability management initiatives from concept through implementation.
  • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
  • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
  • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
  • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript's long-term security posture.
What you bring to the table
  • 8+ years of software engineering experience designing, building, and operating production systems.
  • 3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
  • Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
  • Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
  • Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
  • Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
  • Excellent communication skills, strong technical judgment, and a continuous learning mindset.
Bonus if you have
  • Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
  • Experience with AWS cloud security and cloud-native security controls.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Experience with vulnerability management, application security posture management, or developer security tooling.
  • Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
  • Experience conducting penetration testing, security research, or ethical hacking activities.
  • Experience protecting healthcare, regulated, or sensitive customer data.
What we can offer you
  • Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
  • Flexible PTO and competitive pay, because work-life balance matters
  • RRSP/401k match and stock options to invest in your future
  • Premium benefits package with customizable coverage, paramedical services, and an HSA.
  • Fullscript discounts to save on high-quality wellness products
  • Continuous learning opportunities to grow your skills and career

Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript’s total rewards package.

Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript

Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.

What to Know Before You Apply

We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.

A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.

Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].

All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.

We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.

Learn More
www.fullscript.com
@fullscriptHQ on instagram
@fullscript on YouTube
FullScript on LinkedIn


About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.

That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.

We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.

Bring your ideas, your grit, and your care for people.
Join us and shape the future of care.
The Opportunity

We're looking for a Staff Security Engineer to join Fullscript's Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.

You'll work closely with engineering teams to design and implement security solutions that scale across Fullscript's products and platforms. As a Staff-level engineer, you'll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You'll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.

We're looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.

What you'll do
  • Lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems.
  • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
  • Drive application security, product security, and vulnerability management initiatives from concept through implementation.
  • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
  • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
  • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
  • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript's long-term security posture.
What you bring to the table
  • 8+ years of software engineering experience designing, building, and operating production systems.
  • 3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
  • Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
  • Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
  • Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
  • Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
  • Excellent communication skills, strong technical judgment, and a continuous learning mindset.
Bonus if you have
  • Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
  • Experience with AWS cloud security and cloud-native security controls.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Experience with vulnerability management, application security posture management, or developer security tooling.
  • Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
  • Experience conducting penetration testing, security research, or ethical hacking activities.
  • Experience protecting healthcare, regulated, or sensitive customer data.
What we can offer you
  • Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
  • Flexible PTO and competitive pay, because work-life balance matters
  • RRSP/401k match and stock options to invest in your future
  • Premium benefits package with customizable coverage, paramedical services, and an HSA.
  • Fullscript discounts to save on high-quality wellness products
  • Continuous learning opportunities to grow your skills and career

Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript’s total rewards package.

Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript

Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.

What to Know Before You Apply

We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.

A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.

Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].

All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.

We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.

Learn More
www.fullscript.com
@fullscriptHQ on instagram
@fullscript on YouTube
FullScript on LinkedIn


About Fullscript
We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.
That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.
We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.
This is your invitation.
Bring your ideas, your grit, and your care for people.
Join us and shape the future of care.
The Opportunity
We're looking for a Staff Security Engineer to join Fullscript's Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.
You'll work closely with engineering teams to design and implement security solutions that scale across Fullscript's products and platforms. As a Staff-level engineer, you'll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You'll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.
We're looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.
What you'll do
Lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems.
Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
Drive application security, product security, and vulnerability management initiatives from concept through implementation.
Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript's long-term security posture.
What you bring to the table
8+ years of software engineering experience designing, building, and operating production systems.
3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
Excellent communication skills, strong technical judgment, and a continuous learning mindset.
Bonus if you have
Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
Experience with AWS cloud security and cloud-native security controls.
Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
Experience with vulnerability management, application security posture management, or developer security tooling.
Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
Experience conducting penetration testing, security research, or ethical hacking activities.
Experience protecting healthcare, regulated, or sensitive customer data.
What we can offer you
Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
Flexible PTO and competitive pay, because work-life balance matters
RRSP/401k match and stock options to invest in your future
Premium benefits package with customizable coverage, paramedical services, and an HSA.
Fullscript discounts to save on high-quality wellness products
Continuous learning opportunities to grow your skills and career
Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript’s total rewards package.
Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.
Why Fullscript
Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.
What to Know Before You Apply
We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.
A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.
Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].
All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.
We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.
Learn More
www.fullscript.com
@fullscriptHQon instagram
@fullscripton YouTube
FullScript on LinkedIn

About Fullscript

Healthcare platform for practitioner supplement dispensing and patient management.

Year founded
2011
Employees
950
Organization type
Private
Latest investment
Raised $300.00M Private Equity (2025) — led by Leonard Green & Partners
Headquarters
CA

Similar jobs

Security Engineer roles near Ottawa, Ontario
3w
Save
Mark Applied
Hide
Senior Security Engineer
Toronto or Ottawa
$123k-$153k/yr HybridFull Time
Arup
Arup: Global professional services firm for the built environment.
8+ YOE4+ Mgmt8+ years professional experience with 5+ years leading security design and 4+ years management; experience with video surveillance/access control, TVRA, Revit/AutoCAD, construction administration; PSP/CPP/PEng or equivalent and ability to obtain Canada Secret Clearance.
Revit, AutoCAD, PlanGrid, Procore, FacilityGrid, BIM360
1mo
Save
Mark Applied
Hide
Senior Security Engineer
Toronto or Ottawa
OnsiteFull Time
Dominion Dynamics
Dominion Dynamics: Developing autonomous defense platforms and Arctic sensing technology.
5+ YOE5+ years security engineering experience; hands-on identity & access management, Terraform IaC, EDR/MDM, SIEM/log pipelines, SOAR automation; scripting (Python); knowledge of NIST SP 800-171 and Canadian data-residency requirements.
Terraform, WebAuthn, FIDO2, IdP, SSO, SCIM, EDR, MDM, SIEM, SOAR, HRIS, Python, CI/CD, GenAI/LLM, NIST SP 800-171, CMMC, CPCSC, ITSP.10.171
5d
Save
Mark Applied
Hide
Radio Security Developer
Ottawa, Ontario, Canada
$102k-$133k/yr OnsiteFull Time
Ericsson
EricssonNasdaq Stockholm: ERIC B: Global provider of telecommunications equipment and services.
5+ YOERequires 5+ years in cybersecurity or related security domains, radio security and verification expertise, C/C++, Python, Linux, networking, automation, debugging, and security testing experience.
Linux, C, C++, Python, embedded Linux, Git, Gerrit, IPsec, IKEv2, TLS, SNMP, LDAP, CI/CD, DevOps, SSDF, ISO 27001, ISO 21434, IEC 62443, NIST, SBOM, SCA, AI
5d
Save
Mark Applied
Hide
Radio Security Developer (785427)
Ottawa, Ontario, Canada
$102k-$133k/yr OnsiteFull Time
Ericsson
EricssonNasdaq: ERIC: Manufactures telecommunications equipment and provides networking services.
5+ YOERequires 5+ years in cybersecurity or related security domains, radio verification, Linux, networking, automation, C/C++, Python, protocols, security testing, vulnerability analysis, and secure software development.
Linux, IPsec, IKEv2, TLS, SNMP, LDAP, C, C++, Python, embedded Linux, Git, Gerrit, CI/CD, SSDF, ISO 27001, ISO 21434, IEC 62443, NIST, AI, fuzzing suites, web security tools, vulnerability scanners, SBOM, SCA, packet analyzers
1mo
Save
Mark Applied
Hide
Senior Cloud Security Engineer
Toronto or Austin or Addison or Phoenix or Kanata
HybridFull Time
Semperis
Semperis: Secures and recovers enterprise identity systems from cyber threats.
6+ YOE6+ years in cloud/security engineering; hands-on Azure or AWS experience; Kubernetes (AKS/EKS) security; cloud network and CSPM experience; IaC automation (Terraform/Bicep/CloudFormation); scripting and strong communication.
Azure, AWS, AKS, EKS, Kubernetes, CSPM, Terraform, Bicep, CloudFormation, Python, PowerShell, Bash, CI/CD, RBAC, Application Gateway, WAF, FinOps, DevSecOps, FedRAMP, SOC 2, ISO 27001, NIST
2mo
Save
Mark Applied
Hide
Infrastructure Security Engineer (Secret + Clearance)
Toronto or Ottawa
RemoteFull Time
Cohere
Cohere: Provides enterprise-grade large language models and AI software platforms.
5+ YOE5+ years in infrastructure security; Protected B environment experience; Kubernetes; Terraform; Canadian government security standards; Active Secret+ preferred.
Kubernetes, Terraform, AWS, GCP, Azure, IAM, Encryption, Logging, Monitoring
3mo
Save
Mark Applied
Hide
Senior Security Engineer in Toronto, Ontario, Canada
Toronto or Ottawa
HybridFull Time
Arup
Arup: Global engineering and design consultancy for the built environment.
8+ YOE4+ Mgmt8+ years in security design/consulting; lead project/people management; experience with video surveillance, access control, TVRA; strong Revit/AutoCAD; security licenses/certifications; ability to obtain Canada Secret Clearance.
Revit, AutoCAD, PlanGrid, Procore, BIM360
3mo
Save
Mark Applied
Hide
Senior Security Engineer in Toronto, Ontario, Canada
Toronto or Ottawa
HybridFull Time
Arup
Arup: Provide engineering and design services for the built environment.
8+ YOE5+ Mgmt8+ years in security design/lead role; experience managing teams; Revit/AutoCAD; security system design, TVRA; travel; Canada secret clearance possible.
Revit, AutoCAD