> Markdown version of [/jobs/ext/98893-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/98893-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Healthhero - **Location:** Bristol, UK - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Software System Penetration Testing, Code Review, Continuous Integration, Open Web Application Security, Secure Coding, Security Software, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Information Security Management System, Software Security, Gitlab-ci, Prisma Cloud Platform, Splunk, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 18, 2026 - **Apply:** https://www.careerjet.co.uk/jobad/gb296d24d93199fa377ccfd5b72bab54e7 ## About the Role Essential: * 3+ years in application security, DevSecOps, and secure software development * Hands-on experience with CI/CD security integration (GitLab CI or similar) * Familiarity with SAST/DAST tooling and dependency scanning * Understanding of common vulnerabilities (OWASP Top 10) and remediation * Previous experience working as a back end or full stack developer * Knowledge of GDPR and data protection legislation * Strong communicator; able to translate security requirements for developers Desirable: * Development background with security focus * Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel) * Experience with CSPM tooling (Wiz, Prisma Cloud, or similar) * Penetration testing or bug bounty experience * Experience in regulated environments (healthcare, financial services) * Familiarity with threat modelling frameworks (STRIDE, PASTA) ## Description You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams. As an experienced Application Security Engineer, your working day will include but not be limited to: DevSecOps & Pipeline Security * Implement and maintain security testing in GitLab CI pipelines * Configure and tune SAST, DAST, dependency scanning, and secrets detection * Build automated security gates that balance rigour with delivery velocity * Enable self-serve security tooling for development teams * Contribute code and patches to security tooling and configurations Secure Development * Define and enforce secure coding standards * Conduct security-focused code reviews and threat modelling for new features * Provide remediation guidance for application vulnerabilities * Train and support developers on secure coding practices Vulnerability Management * Triage, patch and track application vulnerabilities through to remediation * Manage dependency vulnerabilities and upgrade cycles * Report on application security posture to senior leadership Risk & Compliance * Embed GDPR and healthcare regulatory requirements into development processes * Support DCB0129 clinical safety compliance for software changes * Support customer security due diligence and audits * Support ISO27001:2022 ISMS controls and audit process ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)