> Markdown version of [/jobs/ext/2803917-application-security-engineer-london-or-bristol](https://www.wearedevelopers.com/jobs/ext/2803917-application-security-engineer-london-or-bristol). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer (London or Bristol) - **Company:** HealthHero - **Location:** Bristol, UK - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Software System Penetration Testing, Code Review, Open Web Application Security, Secure Coding, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Information Security Management System, Software Security, Gitlab-ci, Prisma Cloud Platform, Splunk, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 9, 2026 - **Apply:** https://www.collegerecruiter.com/job/2858067636-application-security-engineer-london-or-bristol ## About the Role * 3+ years in application security, DevSecOps, and secure software development * Hands-on experience with CI/CD security integration (GitLab CI or similar) * Familiarity with SAST/DAST tooling and dependency scanning * Understanding of common vulnerabilities (OWASP Top 10) and remediation * Previous experience working as a back end or full stack developer * Knowledge of GDPR and data protection legislation * Strong communicator; able to translate security requirements for developers, * Development background with security focus * Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel) * Experience with CSPM tooling (Wiz, Prisma Cloud, or similar) * Penetration testing or bug bounty experienceExperience in regulated environments (healthcare, financial services)Familiarity with threat modelling frameworks (STRIDE, PASTA) ## Description You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams. DevSecOps & Pipeline Security * Implement and maintain security testing in GitLab CI pipelines * Configure and tune SAST, DAST, dependency scanning, and secrets detection * Build automated security gates that balance rigour with delivery velocity * Enable self-serve security tooling for development teams * Contribute code and patches to security tooling and configurations Secure Development * Define and enforce secure coding standards * Conduct security-focused code reviews and threat modelling for new features * Provide remediation guidance for application vulnerabilities * Train and support developers on secure coding practices Vulnerability Management * Triage, patch and track application vulnerabilities through to remediation * Manage dependency vulnerabilities and upgrade cycles * Report on application security posture to senior leadership Risk & Compliance * Embed GDPR and healthcare regulatory requirements into development processes * Support DCB0129 clinical safety compliance for software changes * Support customer security due diligence and audits * Support ISO27001:2022 ISMS controls and audit process ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)