Location
London or Bristol (Hybrid: minimum two days per week in office)
Hours
Full Time
Salary
Not specified
About the Role
Join HealthHero, Europe’s largest digital clinic, at a pivotal moment as we scale our digital healthcare platform across Europe. This is an exciting opportunity to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an Application Security Engineer on an initial 12-month fixed term contract, with a view to becoming permanent. You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams.
Key responsibilities include:
- Implementing and maintaining security testing in GitLab CI pipelines
- Configuring and tuning SAST, DAST, dependency scanning, and secrets detection
- Building automated security gates balancing rigour with delivery velocity
- Enabling self-serve security tooling for development teams
- Contributing code and patches to security tooling and configurations
- Defining and enforcing secure coding standards
- Conducting security-focused code reviews and threat modelling
- Providing remediation guidance for application vulnerabilities
- Training and supporting developers on secure coding practices
- Triaging, patching, and tracking application vulnerabilities through to remediation
- Managing dependency vulnerabilities and upgrade cycles
- Reporting on application security posture to senior leadership
- Embedding GDPR and healthcare regulatory requirements into development processes
- Supporting clinical safety compliance, customer security due diligence, and ISO27001:2022 ISMS controls and audits
About HealthHero
We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. Delivering 4 million consultations per year, we are building the next generation of healthcare with an AI-powered, always-on ecosystem that shifts the focus from reactive treatment to proactive, sustainable health. We are a high-growth, capital-backed business with a diverse team of digital experts, clinicians, and creatives. Recognised as a Great Place to Work and featured in the Sunday Times 100 Tech list, we are committed to innovation, excellence, and a supportive culture.
Why Us?
Our values guide us daily: Simplify, Own, Aspire and Respect (SOAR). We offer a full induction training programme via Microsoft Teams, a passionate and supportive team, 25 days leave plus bank holidays and your birthday off, regular 1-2-1s with your manager, 24/7 on-call staff support, auto-enrolment pension scheme, health scheme with Employee Assistance Programme, and life insurance.
Experience
- Minimum 3 years in application security, DevSecOps, and secure software development
- Hands-on experience with CI/CD security integration (GitLab CI or similar)
- Familiarity with SAST/DAST tooling and dependency scanning
- Understanding of common vulnerabilities (OWASP Top 10) and remediation
- Previous experience as a back end or full stack developer
- Knowledge of GDPR and data protection legislation
- Strong communication skills to translate security requirements for developers
About You
- Experienced and proactive security professional with a development background preferred
- Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel) and CSPM tooling (Wiz, Prisma Cloud, or similar) is desirable
- Experience in penetration testing or bug bounty programs is a plus
- Comfortable working in regulated environments such as healthcare or financial services
- Knowledge of threat modelling frameworks (STRIDE, PASTA) is advantageous
Qualifications
Not explicitly specified; relevant experience and skills are essential.

