\nAt Fullscript, weโre not just changing healthcareโweโre making it whole.\n\n\nWe help 100,000+ healthcare practitioners support 10 million patients with a platform that delivers evidence-based health solutions, diagnostic support, and practitioner toolsโall in one place.\n\n\nHealthcare today is disconnected. Weโre fixing that. Fullscript makes it easier for practitioners to treat the whole person, not just symptoms, so patients get the support they needโwhen they need it.\n\n\nWeโre building a better wayโone where healthcare is connected, complete, and built for impact.\n\n\nThe Role\n\n\nWeโre looking for an experienced Lead Security Engineer to help shape and strengthen Fullscriptโs security posture. Youโll play a key role in embedding security across our development lifecycle, leading initiatives in DevSecOps, AppSec, GRC, security operations, and incident response.\n\n\nThis is an opportunity to tackle real-world security challenges, develop scalable security strategies, and work cross-functionally to ensure security is built into everything we do.\n\n\n\nWhat You'll Do:\n* Lead and mentor a security engineering team while partnering with teams like Engineering and IT to embed security throughout our development lifecycle.\n* Define and implement security best practices, combining practical recommendations with automated guardrails.\n* Drive security initiatives and provide technical guidance for infrastructure decisions, ensuring security is considered from design through implementation.\n* Establish and optimize security triage processes, including SLAs, severity frameworks, and remediation protocols.\n* Review feature designs and technical approaches to ensure features are developed with security in mind.\n* Grow and expand our purple team capabilities.\n* Sharing your knowledge and expertise with our developer community.\n\n\n\nWhat You Bring:\n* Demonstrated success mentoring and developing security engineering teams.\n* Experience partnering with cross-organizational teams to drive security initiatives.\n* Proven ability to translate complex security concepts for diverse technical audiences.\n* Track record of building and optimizing security triage processes.\n* Hands-on coding experience in at least one modern programming language.\n* Understanding of industry frameworks (SOC2, PCI, HIPAA, HITRUST, NIST).\n\n\n\nBonus Points\n* Background in automation and infrastructure as code (Terraform, CloudFormation).\n* Container security and Kubernetes ecosystem security.\n* Implementation of cloud security platforms (Wiz) and SIEM solutions.\n* Compliance automation and continuous control monitoring (Drata).\n* Edge security (WAF).\n* Experience securing Ruby on Rails and Javascript applications.\n* Experience in securing APIs (GraphQL).\n* Experience with pen-test software (Burpsuite).\n* Experience with software threat modelling.\n* Database security best practices (MySQL, Postgres).\n* Experience with security tooling integration in CI/CD pipelines (GitLab, GitHub Actions).\n* Advanced Linux/Unix systems security.\n\n\n\nWhat You Get:\n* Flexible PTO & competitive payโbecause balance fuels performance.\n* RRSP match & stock optionsโinvest in your future.\n* Customizable benefitsโflexible coverage, paramedical services, and an HSA.\n* Fullscript discountsโsave on high-quality wellness products.\n* Continuous learningโtraining budget + company-wide initiatives.\n* Wherever You Work Wellโhybrid and remote flexibility.\n\n\n\n\n\n\nWhy Fullscript?\n\n\nGreat work happens when people are supported, challenged, and inspired. Here, youโll be part of a team that:\n\n\nโฌฆ Values innovationโwe push boundaries and always look for better ways.\nโฌฆ Supports growthโthrough learning, mentorship, and meaningful work.\nโฌฆ Cares about balanceโwith flexible work options and time off when you need it.\n\n\n๐ Apply nowโletโs build the future of healthcare, together.\n\n\nFullscript is an equal-opportunity employer committed to creating an inclusive workplace. Accommodations are available upon requestโemail [email protected] for support.\n\n\nBefore joining the team, all candidates who receive and accept an offer will complete a background check.\n\n\n๐ MORE INFO: www.fullscript.com | www.rupahealth.com | Follow us on social media @fullscriptHQ\n๐ฅ IN THE NEWS: Fullscript acquires Rupa Health\n๐บLetโs make healthcare whole \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Design, JavaScript, Cloud, Ruby and Engineer jobs that are similar:\n\n
$60,000 — $100,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐ We hire old (and young)\n\n
๐ Please reference you found the job on Remote OK, this helps us get more companies to post here, thanks!
When applying for jobs, you should NEVER have to pay to apply. You should also NEVER have to pay to buy equipment which they then pay you back for later. Also never pay for trainings you have to do. Those are scams! NEVER PAY FOR ANYTHING! Posts that link to pages with "how to work online" are also scams. Don't use them or pay for them. Also always verify you're actually talking to the company in the job post and not an imposter. A good idea is to check the domain name for the site/email and see if it's the actual company's main domain name. Scams in remote work are rampant, be careful! Read more to avoid scams. When clicking on the button to apply above, you will leave Remote OK and go to the job application page for that company outside this site. Remote OK accepts no liability or responsibility as a consequence of any reliance upon information on there (external sites) or here.