Application Security Engineer

Qare
Paris, France
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Code Review Encodings Continuous Integration Open Web Application Security Secure Coding Security Software Security Information and Event Management Software Engineering Software Vulnerability Management Information Security Management System Software Security
+6 more
Gitlab-ci Prisma Cloud Platform Splunk Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams.

As an experienced Application Security Engineer, your working day will include but not be limited to:

DevSecOps & Pipeline Security

  • Implement and maintain security testing in GitLab CI pipelines
  • Configure and tune SAST, DAST, dependency scanning, and secrets detection
  • Build automated security gates that balance rigour with delivery velocity
  • Enable self-serve security tooling for development teams
  • Contribute code and patches to security tooling and configurations

Secure Development

  • Define and enforce secure coding standards
  • Conduct security-focused code reviews and threat modelling for new features
  • Provide remediation guidance for application vulnerabilities
  • Train and support developers on secure coding practices

Vulnerability Management

  • Triage, patch and track application vulnerabilities through to remediation
  • Manage dependency vulnerabilities and upgrade cycles
  • Report on application security posture to senior leadership

Risk & Compliance

  • Embed GDPR and healthcare regulatory requirements into development processes
  • Support DCB0129 clinical safety compliance for software changes
  • Support customer security due diligence and audits
  • Support ISO27001:2022 ISMS controls and audit process

Requirements

Do you have experience in Splunk?, Essential:

  • 3+ years in application security, DevSecOps, and secure software development
  • Hands-on experience with CI/CD security integration (GitLab CI or similar)
  • Familiarity with SAST/DAST tooling and dependency scanning
  • Understanding of common vulnerabilities (OWASP Top 10) and remediation
  • Previous experience working as a back end or full stack developer
  • Knowledge of GDPR and data protection legislation
  • Strong communicator; able to translate security requirements for developers

Desirable:

  • Development background with security focus
  • Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel)
  • Experience with CSPM tooling (Wiz, Prisma Cloud, or similar)
  • Penetration testing or bug bounty experience
  • Experience in regulated environments (healthcare, financial services)
  • Familiarity with threat modelling frameworks (STRIDE, PASTA)

About the company

Joining Qare means embarking on a human and technological adventure where every day counts towards improving the lives of millions of people. Whether you’re passionate about tech, healthcare, or innovation, you’ll find a playing field here that matches your ambitions!, Qare, the leading telemedicine platform in France, handles 8 million consultations, or 230,000 per month, and works with 2,300 doctors. Qare’s service is available 7 days a week, from 6a.m. to midnight, via a mobile app or online for all French citizens nationwide. Since its inception, Qare has championed a high-quality, professional, and regulated telemedicine model.

Qare monitors 15 key medical quality indicators daily, focusing on patient care and follow-up. According to a post-teleconsultation survey, 96% of patients reported being satisfied with the service. Qare is also specifically available to 23 groups of higher education institutions, including schools and universities. Qare is the initiator and founding member of the MentalTech collective.

In 2021, Qare joined the European e-health group HealthHero. Qare obtained accreditation for teleconsultation companies from the Ministry of Health in 2024.

Why us?

Our values guide us, every day we strive to Simplify, Own, Aspire and Respect (SOAR) - and we’re rewarded when we do.

What we offer

  • A full induction training programme, which will be undertaken via Microsoft Teams.
  • An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic.
  • Internal actions put in place to preserve the mental and physical health of employees.
  • A balance between professional and private life.
  • A hybrid working arrangement: the possibility of working remotely up to three days a week in a flexible manner.
  • An eco-friendly workspace where it’s pleasant to work.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · WWC 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Videos

See all

Related articles

See all