Full-Time Lead Engineer Security
Fullscript is hiring a remote Full-Time Lead Engineer Security. The career level for this job opening is Experienced and is accepting Worldwide based applicants remotely. Read complete job description before applying.
Fullscript
Job Title
Posted
Career Level
Career Level
Locations Accepted
Share
Job Details
At Fullscript, we're not just changing healthcare—we're making it whole. We help 100,000+ healthcare practitioners support 10 million patients with a platform that delivers evidence-based health solutions, diagnostic support, and practitioner tools—all in one place. Healthcare today is disconnected. We're fixing that. Fullscript makes it easier for practitioners to treat the whole person, not just symptoms, so patients get the support they need—when they need it. We're building a better way—one where healthcare is connected, complete, and built for impact.
The Role We're looking for an experienced Lead Security Engineer to help shape and strengthen Fullscript's security posture. You'll play a key role in embedding security across our development lifecycle, leading initiatives in DevSecOps, AppSec, GRC, security operations, and incident response. This is an opportunity to tackle real-world security challenges, develop scalable security strategies, and work cross-functionally to ensure security is built into everything we do.
What You'll Do:
- Lead and mentor a security engineering team while partnering with teams like Engineering and IT to embed security throughout our development lifecycle.
- Define and implement security best practices, combining practical recommendations with automated guardrails.
- Drive security initiatives and provide technical guidance for infrastructure decisions, ensuring security is considered from design through implementation.
- Establish and optimize security triage processes, including SLAs, severity frameworks, and remediation protocols.
- Review feature designs and technical approaches to ensure features are developed with security in mind.
- Grow and expand our purple team capabilities.
- Sharing your knowledge and expertise with our developer community.
What You Bring:
- Demonstrated success mentoring and developing security engineering teams.
- Experience partnering with cross-organizational teams to drive security initiatives.
- Proven ability to translate complex security concepts for diverse technical audiences.
- Track record of building and optimizing security triage processes.
- Hands-on coding experience in at least one modern programming language.
- Understanding of industry frameworks (SOC2, PCI, HIPAA, HITRUST, NIST).
Bonus Points:
- Background in automation and infrastructure as code (Terraform, CloudFormation).
- Container security and Kubernetes ecosystem security.
- Implementation of cloud security platforms (Wiz) and SIEM solutions.
- Compliance automation and continuous control monitoring (Drata).
- Edge security (WAF).
- Experience securing Ruby on Rails and Javascript applications.
- Experience in securing APIs (GraphQL).
- Experience with pen-test software (Burpsuite).
- Experience with software threat modelling.
- Database security best practices (MySQL, Postgres).
- Experience with security tooling integration in CI/CD pipelines (GitLab, GitHub Actions).
- Advanced Linux/Unix systems security.