Fullscript

Staff, Security Engineer

Fullscript$130K — $160K *
US-AnywhereRemote in Toronto, ON
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in software engineering with production systems experience.
  • 3+ years in application security, product security, or security engineering.
  • Deep knowledge of secure software development and modern app architectures.
  • Experience leading cross-team technical initiatives from conception to completion.
  • Ability to mentor peers and promote security best practices effectively.
  • Hands-on experience with security tools and automation for vulnerability management.
  • Excellent communication abilities and a commitment to continual learning.

Responsibilities

  • Lead the creation of security solutions for Fullscript's applications and AI systems.
  • Collaborate with engineering teams to integrate security into the software development lifecycle.
  • Manage application and product security initiatives from start to finish.
  • Address complex security challenges while aligning technical and business goals.
  • Guide and mentor teams to enhance secure software development practices.
  • Shape technical strategy and security standards through active leadership.
  • Stay informed on new threats and security technologies to fortify the company's security stance.

Benefits

  • Remote-first work environment with flexibility in location.
  • Flexible PTO policy to support work-life balance.
  • Retirement savings matching and stock options for future investment.
  • Comprehensive benefits package with customizable options and health savings accounts.
  • Discounts on wellness products offered by Fullscript.
  • Opportunities for continuous learning and career advancement.
Full Job Description
The Opportunity

We're looking for a Staff Security Engineer to join Fullscript's Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.

You'll work closely with engineering teams to design and implement security solutions that scale across Fullscript's products and platforms. As a Staff-level engineer, you'll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You'll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.

We're looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.

What you'll do
  • Lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems.
  • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
  • Drive application security, product security, and vulnerability management initiatives from concept through implementation.
  • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
  • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
  • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
  • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript's long-term security posture.

What you bring to the table

  • 8+ years of software engineering experience designing, building, and operating production systems.
  • 3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
  • Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
  • Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
  • Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
  • Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
  • Excellent communication skills, strong technical judgment, and a continuous learning mindset.


Bonus if you have
  • Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
  • Experience with AWS cloud security and cloud-native security controls.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Experience with vulnerability management, application security posture management, or developer security tooling.
  • Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
  • Experience conducting penetration testing, security research, or ethical hacking activities.
  • Experience protecting healthcare, regulated, or sensitive customer data.

What we can offer you
  • Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
  • Flexible PTO and competitive pay, because work-life balance matters
  • RRSP/401k match and stock options to invest in your future
  • Premium benefits package with customizable coverage, paramedical services, and an HSA.
  • Fullscript discounts to save on high-quality wellness products
  • Continuous learning opportunities to grow your skills and career


Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript's total rewards package.

Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Learn More

www.fullscript.com

on instagram

@fullscript on YouTube

FullScript on LinkedIn

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Similar Jobs

More Jobs at Fullscript

More Information Technology Jobs

Find similar Staff, Security Engineer jobs: