Application Security Engineer (London or Bristol)

{ “@context”: “http://schema.org”, “@type”: “JobPosting”, “title”: “Application Security Engineer (London or Bristol)”, “description”: “

About the Role

We are recruiting an Application Security Engineer on an initial 12‑month fixed‑term contract, with a view to becoming permanent. The role is based in either our London or Bristol office, requiring presence in the office two days per week.

Responsibilities

  • Own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly.
  • Implement and maintain security testing in GitLab CI pipelines.
  • Configure and tune SAST, DAST, dependency scanning, and secrets detection.
  • Build automated security gates that balance rigour with delivery velocity.
  • Enable self‑serve security tooling for development teams.
  • Contribute code and patches to security tooling and configurations.
  • Define and enforce secure coding standards.
  • Conduct security‑focused code reviews and threat modelling for new features.
  • Provide remediation guidance for application vulnerabilities.
  • Train and support developers on secure coding practices.
  • Triage, patch and track application vulnerabilities through to remediation.
  • Manage dependency vulnerabilities and upgrade cycles.
  • Report on application security posture to senior leadership.
  • Embed GDPR and healthcare regulatory requirements into development processes.
  • Support DCB0129 clinical safety compliance for software changes.
  • Support customer security due diligence and audits.
  • Support ISO27001:2022 ISMS controls and audit process.

Key Skills and Experience

Essential

  • 3+ years in application security, DevSecOps, and secure software development.
  • Hands‑on experience with CI/CD security integration (GitLab CI or similar).
  • Familiarity with SAST/DAST tooling and dependency scanning.
  • Understanding of common vulnerabilities (OWASP Top 10) and remediation.
  • Previous experience working as a back‑end or full‑stack developer.
  • Knowledge of GDPR and data protection legislation.
  • Strong communicator; able to translate security requirements for developers.

Desirable

  • Development background with security focus.
  • Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel).
  • Experience with CSPM tooling (Wiz, Prisma Cloud, or similar).
  • Penetration testing or bug bounty experience.
  • Experience in regulated environments (healthcare, financial services).
  • Familiarity with threat modelling frameworks (STRIDE, PASTA).

Benefits

  • Full induction training programme delivered via Microsoft Teams.
  • Opportunity to work as part of an experienced, supportive, diverse and dynamic team.
  • 25 days leave.
  • Bank holidays and birthday off as leave.
  • Regular 1‑2‑1s with line manager.
  • 24/7 on‑call staff support.
  • Auto‑enrolment pension scheme.
  • Health scheme and access to Employee Assistance Programme.
  • Life Insurance Scheme.

Location

Hybrid: London or Bristol (minimum two days per week in the office).

Equal Opportunity & Diversity

In line with our commitment to Equality, Inclusivity and Diversity, we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are a certified Disability Confident Employer and are committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process, please let us know.

#J-18808-Ljbffr”, “datePosted”: “2026-05-18”, “hiringOrganization”: { “@type”: “Organization”, “name”: “HealthHero”, “sameAs”: “https://uk.whatjobs.com/pub_api__cpl__435626368__4861?utm_campaign=publisher&utm_medium=api&utm_source=4861&geoID=22” }, “jobLocation”: { “@type”: “Place”, “address”: { “@type”: “PostalAddress”, “addressLocality”: “Bristol” } } }
Company: HealthHero
Apply for the Application Security Engineer (London or Bristol)
Location: Bristol
Job Description:

About the Role

We are recruiting an Application Security Engineer on an initial 12‑month fixed‑term contract, with a view to becoming permanent. The role is based in either our London or Bristol office, requiring presence in the office two days per week.

Responsibilities

  • Own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly.
  • Implement and maintain security testing in GitLab CI pipelines.
  • Configure and tune SAST, DAST, dependency scanning, and secrets detection.
  • Build automated security gates that balance rigour with delivery velocity.
  • Enable self‑serve security tooling for development teams.
  • Contribute code and patches to security tooling and configurations.
  • Define and enforce secure coding standards.
  • Conduct security‑focused code reviews and threat modelling for new features.
  • Provide remediation guidance for application vulnerabilities.
  • Train and support developers on secure coding practices.
  • Triage, patch and track application vulnerabilities through to remediation.
  • Manage dependency vulnerabilities and upgrade cycles.
  • Report on application security posture to senior leadership.
  • Embed GDPR and healthcare regulatory requirements into development processes.
  • Support DCB0129 clinical safety compliance for software changes.
  • Support customer security due diligence and audits.
  • Support ISO27001:2022 ISMS controls and audit process.

Key Skills and Experience

Essential

  • 3+ years in application security, DevSecOps, and secure software development.
  • Hands‑on experience with CI/CD security integration (GitLab CI or similar).
  • Familiarity with SAST/DAST tooling and dependency scanning.
  • Understanding of common vulnerabilities (OWASP Top 10) and remediation.
  • Previous experience working as a back‑end or full‑stack developer.
  • Knowledge of GDPR and data protection legislation.
  • Strong communicator; able to translate security requirements for developers.

Desirable

  • Development background with security focus.
  • Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel).
  • Experience with CSPM tooling (Wiz, Prisma Cloud, or similar).
  • Penetration testing or bug bounty experience.
  • Experience in regulated environments (healthcare, financial services).
  • Familiarity with threat modelling frameworks (STRIDE, PASTA).

Benefits

  • Full induction training programme delivered via Microsoft Teams.
  • Opportunity to work as part of an experienced, supportive, diverse and dynamic team.
  • 25 days leave.
  • Bank holidays and birthday off as leave.
  • Regular 1‑2‑1s with line manager.
  • 24/7 on‑call staff support.
  • Auto‑enrolment pension scheme.
  • Health scheme and access to Employee Assistance Programme.
  • Life Insurance Scheme.

Location

Hybrid: London or Bristol (minimum two days per week in the office).

Equal Opportunity & Diversity

In line with our commitment to Equality, Inclusivity and Diversity, we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are a certified Disability Confident Employer and are committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process, please let us know.

#J-18808-Ljbffr…

Posted: May 18th, 2026