Staff, Security Engineer
Job description
About the role
You will lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems. You partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews. You own complex technical initiatives, helping shape security strategy and influencing how security is built into the software development lifecycle. You balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity. You are deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains. You understand how to build secure, scalable solutions in production environments by owning systems end-to-end from application development and infrastructure decisions through security design and implementation.
Key facts
What you'll do
Lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems.
Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
Drive application security, product security, and vulnerability management initiatives from concept through implementation.
Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript's long-term security posture.
Perform hands-on security work such as writing secure code, reviewing implementations, and validating fixes alongside engineering teams.
Collaborate with product managers, designers, and leadership to ensure security outcomes are considered in roadmap planning and delivery.
Contribute to the development and maintenance of security playbooks, runbooks, and operational procedures.
Evaluate and pilot new security tools and processes to improve developer workflows and security outcomes without sacrificing delivery speed.
Engage with the broader security community through knowledge sharing, talks, and internal training to build security awareness across the organization.
Support incident response efforts by applying deep technical expertise to investigate, triage, and remediate security findings quickly and effectively.
Measure the impact of security initiatives through metrics and continuously refine approaches to improve security and engineering efficiency.
Requirements
8+ years of software engineering experience designing, building, and operating production systems.
3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
Excellent communication skills, strong technical judgment, and a continuous learning mindset.
Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
Experience with AWS cloud security and cloud-native security controls.
Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
Experience with vulnerability management, application security posture management, or developer security tooling.
Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
Experience conducting penetration testing, security research, or ethical hacking activities.
Experience protecting healthcare, regulated, or sensitive customer data.
Nice to have
Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
Experience with AWS cloud security and cloud-native security controls.
Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
Experience with vulnerability management, application security posture management, or developer security tooling.
Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
Experience conducting penetration testing, security research, or ethical hacking activities.
Experience protecting healthcare, regulated, or sensitive customer data.
Practical notes
Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
Flexible PTO and competitive benefits.