At a Glance
- Tasks: Own security in the software development lifecycle and enable secure code delivery.
- Company: Join HealthHero, Europe's largest digital clinic, shaping the future of healthcare.
- Benefits: Enjoy 25 days leave, health schemes, and a supportive team environment.
- Other info: Dynamic work culture with excellent career growth opportunities.
- Why this job: Make a real impact in a fast-growing, AI-driven business focused on improving lives.
- Qualifications: 3+ years in application security and experience with CI/CD security integration.
The predicted salary is between 60000 - 75000 £ per year.
We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe — giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Application Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent – based in either our London or Bristol office two days per week.
About the role
You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams.
As an experienced Application Security Engineer, your working day will include but not be limited to:
- DevSecOps & Pipeline Security
- Implement and maintain security testing in GitLab CI pipelines
- Configure and tune SAST, DAST, dependency scanning, and secrets detection
- Build automated security gates that balance rigour with delivery velocity
- Enable self-serve security tooling for development teams
- Contribute code and patches to security tooling and configurations
- Secure Development
- Define and enforce secure coding standards
- Conduct security-focused code reviews and threat modelling for new features
- Provide remediation guidance for application vulnerabilities
- Train and support developers on secure coding practices
- Vulnerability Management
- Triage, patch and track application vulnerabilities through to remediation
- Manage dependency vulnerabilities and upgrade cycles
- Report on application security posture to senior leadership
- Risk & Compliance
- Embed GDPR and healthcare regulatory requirements into development processes
- Support DCB0129 clinical safety compliance for software changes
- Support customer security due diligence and audits
- Support ISO27001:2022 ISMS controls and audit process
Key Skills and Experience
Essential:
- 3+ years in application security, DevSecOps, and secure software development
- Hands-on experience with CI/CD security integration (GitLab CI or similar)
- Familiarity with SAST/DAST tooling and dependency scanning
- Understanding of common vulnerabilities (OWASP Top 10) and remediation
- Previous experience working as a back end or full stack developer
- Knowledge of GDPR and data protection legislation
- Strong communicator; able to translate security requirements for developers
Desirable:
- Development background with security focus
- Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel)
- Experience with CSPM tooling (Wiz, Prisma Cloud, or similar)
- Penetration testing or bug bounty experience
- Experience in regulated environments (healthcare, financial services)
- Familiarity with threat modelling frameworks (STRIDE, PASTA)
About us
We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider, delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together — from GP appointments and mental health support to long-term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it.
We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts.
What we offer
- A full induction training programme, which will be undertaken via Microsoft Teams.
- An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic.
- 25 days leave.
- Bank Holidays and your birthday off as leave.
- Regular 1-2-1s with your line Manager.
- 24/7 on-call staff support.
- Auto-enrolment pension scheme.
- Health Scheme and access to our Employee Assistance Programme.
- Life Insurance Scheme.
If you are interested in making a difference and believe this role is a good fit for you, we would love to hear from you. If you have any questions, please contact our Recruitment Team.
Hybrid: London or Bristol (There is a requirement to work in the office for a minimum of two days per week)
Closing date for applications: Friday 29 May (5pm)
Application Security Engineer in London employer: Health Hero
At HealthHero, we pride ourselves on being a leading employer in the digital healthcare sector, offering a dynamic and supportive work culture that fosters innovation and collaboration. With opportunities for professional growth, comprehensive training, and a commitment to employee well-being, our London and Bristol offices provide an ideal environment for Application Security Engineers to thrive while contributing to meaningful advancements in healthcare. Join us and be part of a team that is shaping the future of health with cutting-edge technology and a human touch.
StudySmarter Expert Advice🤫
We think this is how you could land Application Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at meetups. A friendly chat can open doors that a CV just can't.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your projects, especially those related to application security. It’s a great way to demonstrate your expertise.
✨Tip Number 3
Prepare for interviews by brushing up on common vulnerabilities and secure coding practices. We want to see you shine when discussing how you tackle security challenges!
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love hearing from passionate candidates like you!
We think you need these skills to ace Application Security Engineer in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Application Security Engineer role. Highlight your experience with CI/CD security integration and any relevant tools you've used. We want to see how your skills align with our needs!
Showcase Your Experience:In your cover letter, don’t just list your qualifications; tell us about specific projects where you’ve implemented security measures. We love hearing about real-world applications of your skills!
Be Clear and Concise:Keep your application clear and to the point. Use bullet points for easy reading and make sure to address all key skills mentioned in the job description. We appreciate straightforward communication!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re keen on joining our team!
How to prepare for a job interview at Health Hero
✨Know Your Stuff
Make sure you brush up on your application security knowledge, especially around the OWASP Top 10 vulnerabilities. Be ready to discuss how you've implemented security in CI/CD pipelines and any tools you've used like SAST or DAST.
✨Showcase Your Experience
Prepare to share specific examples from your past roles where you've successfully embedded security practices into development processes. Highlight any experience with vulnerability management and how you've guided teams in secure coding.
✨Communicate Clearly
Since you'll be translating security requirements for developers, practice explaining complex security concepts in simple terms. This will show that you can bridge the gap between technical and non-technical team members.
✨Ask Insightful Questions
Come prepared with questions about HealthHero's approach to security and how they integrate it into their digital healthcare platform. This shows your genuine interest in the role and helps you understand their priorities better.