Application Security Engineer

Healthhero
Bristol, UK
3 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Code Review Continuous Integration Open Web Application Security Secure Coding Security Software Security Information and Event Management Software Engineering Software Vulnerability Management Information Security Management System Software Security Gitlab-ci
+5 more
Prisma Cloud Platform Splunk Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams. As an experienced Application Security Engineer, your working day will include but not be limited to: DevSecOps & Pipeline Security

  • Implement and maintain security testing in GitLab CI pipelines
  • Configure and tune SAST, DAST, dependency scanning, and secrets detection
  • Build automated security gates that balance rigour with delivery velocity
  • Enable self-serve security tooling for development teams
  • Contribute code and patches to security tooling and configurations

Secure Development

  • Define and enforce secure coding standards
  • Conduct security-focused code reviews and threat modelling for new features
  • Provide remediation guidance for application vulnerabilities
  • Train and support developers on secure coding practices

Vulnerability Management

  • Triage, patch and track application vulnerabilities through to remediation
  • Manage dependency vulnerabilities and upgrade cycles
  • Report on application security posture to senior leadership

Risk & Compliance

  • Embed GDPR and healthcare regulatory requirements into development processes
  • Support DCB0129 clinical safety compliance for software changes
  • Support customer security due diligence and audits
  • Support ISO27001:2022 ISMS controls and audit process

Requirements

Essential:

  • 3+ years in application security, DevSecOps, and secure software development
  • Hands-on experience with CI/CD security integration (GitLab CI or similar)
  • Familiarity with SAST/DAST tooling and dependency scanning
  • Understanding of common vulnerabilities (OWASP Top 10) and remediation
  • Previous experience working as a back end or full stack developer
  • Knowledge of GDPR and data protection legislation
  • Strong communicator; able to translate security requirements for developers

Desirable:

  • Development background with security focus
  • Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel)
  • Experience with CSPM tooling (Wiz, Prisma Cloud, or similar)
  • Penetration testing or bug bounty experience
  • Experience in regulated environments (healthcare, financial services)
  • Familiarity with threat modelling frameworks (STRIDE, PASTA)

Benefits & conditions

  • Auto-enrolment pension scheme.
  • Health Scheme and access to our Employee Assistance Programme.
  • Life Insurance Scheme.

About the company

We are HealthHero, Europe’s largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Application Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week., We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe’s largest digital health provider, delivering 4 million consultations per year. But we’re just getting started. We’ve built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world’s leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of digital-native pioneers, management consultants, creatives and industry-leading clinical experts. We aren’t just digitising appointments; we’re building the next generation of healthcare. We’re creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. We’re proud to be recognised as a which reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person-centred care, we invest in people, resources and technology to continuously improve the quality of its services and organisational culture. Why us? Our values guide us, every day we strive to ) - and we’re rewarded when we do. What we offer

  • A full induction training programme, which will be undertaken via Microsoft Teams.
  • An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic.
  • 25 days leave.
  • Bank Holidays and your birthday off as leave.
  • Regular 1-2-1s with your line Manager.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careerjet.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all