Application Security Engineer

Health Hero
W1T1Af, W1T 1AF, United Kingdom
6 days ago
Job Type
Contract
Work Pattern
Part-time
Work Location
Hybrid
Seniority
Mid
Education
Degree
Posted
26 May 2026 (6 days ago)

Benefits

25 days holiday Pension Private healthcare Equity

Application Security Engineer (London or Bristol)

We are HealthHero, Europe’s largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe — giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Application Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent – based in either our London or Bristol office two days per week.

About the role

You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams.

As an experienced Application Security Engineer, your working day will include but not be limited to:

DevSecOps & Pipeline Security

  • Implement and maintain security testing in GitLab CI pipelines
  • Configure and tune SAST, DAST, dependency scanning, and secrets detection
  • Build automated security gates that balance rigour with delivery velocity
  • Enable self-serve security tooling for development teams
  • Contribute code and patches to security tooling and configurations

Secure Development

  • Define and enforce secure coding standards
  • Conduct security-focused code reviews and threat modelling for new features
  • Provide remediation guidance for application vulnerabilities
  • Train and support developers on secure coding practices

Vulnerability Management

  • Triage, patch and track application vulnerabilities through to remediation
  • Manage dependency vulnerabilities and upgrade cycles
  • Report on application security posture to senior leadership

Risk & Compliance

  • Embed GDPR and healthcare regulatory requirements into development processes
  • Support DCB0129 clinical safety compliance for software changes
  • Support customer security due diligence and audits
  • Support ISO27001:2022 ISMS controls and audit process

Key Skills and Experience

Essential:

  • 3+ years in application security, DevSecOps, and secure software development
  • Hands-on experience with CI/CD security integration (GitLab CI or similar)
  • Familiarity with SAST/DAST tooling and dependency scanning
  • Understanding of common vulnerabilities (OWASP Top 10) and remediation
  • Previous experience working as a back end or full stack developer
  • Knowledge of GDPR and data protection legislation
  • Strong communicator; able to translate security requirements for developers

Desirable:

  • Development background with security focus
  • Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel)
  • Experience with CSPM tooling (Wiz, Prisma Cloud, or similar)
  • Penetration testing or bug bounty experience
  • Experience in regulated environments (healthcare, financial services)
  • Familiarity with threat modelling frameworks (STRIDE, PASTA)

About us

We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human.

HealthHero is Europe’s largest digital health provider, delivering 4 million consultations per year. But we’re just getting started. We’ve built a seamless digital clinic that brings body and mind together — from GP appointments and mental health support to long-term condition management. By sitting behind the world’s leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it.

We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts.

We aren’t just digitising appointments; we’re building the next generation of healthcare. We’re creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts.

Join us, and help build a next generation health system the world is waiting for.

We’re proud to be recognised as a which reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person-centred care, we invest in people, resources and technology to continuously improve the quality of its services and organisational culture.

What we offer

  • A full induction training programme, which will be undertaken via Microsoft Teams.
  • An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic.
  • 25 days leave.
  • Bank Holidays and your birthday off as leave.
  • Regular 1-2-1s with your line Manager.
  • 24/7 on-call staff support.
  • Auto-enrolment pension scheme.
  • Health Scheme and access to our Employee Assistance Programme.
  • Life Insurance Scheme.

Apply

If you are interested in making a difference and believe this role is a good fit for you, we would love to hear from you. If you have any questions, please contact our Recruitment Team at

Hybrid:London or Bristol (There is a requirement to work in the office for a minimum of two days per week)

Closing date for applications: Friday 29 May (5pm)

Additional information

*We reserve the right to close this job in the event we receive a sufficient number of applications.

**Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.

Related Jobs

View all jobs

Senior Application Security Engineer

REVYBE IT RECRUITMENT LIMITED Manchester, United Kingdom
£80,000 – £95,000 pa Hybrid

Security Engineer, Amazon Application Security

Amazon London, United Kingdom
Permanent

Security Engineering Manager, SDO Application Security

Amazon London, United Kingdom
Permanent

Senior Security Cloud Engineer

Health Hero W1T1Af, W1T 1AF, United Kingdom
Hybrid

Security Engineer, SDO AppSec

Amazon London, United Kingdom
On-site

Senior Cyber Security Engineer

Proactive Appointments Reading, United Kingdom
£65,000 – £75,000 pa Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cloud Computing Jobs in the UK (2026 Guide)

Where to advertise cloud computing jobs UK in 2026: the specialist boards and channels that reach AWS, Azure, GCP and cloud-native engineering talent. The candidate pool is large relative to other deep tech disciplines but highly segmented — cloud architects, DevOps engineers, platform engineers, FinOps specialists and cloud security professionals each occupy distinct communities with different job search behaviours, certification profiles and salary expectations. General job boards reach a broad audience but struggle to differentiate between these disciplines, producing high application volumes but low candidate quality for specialist cloud roles. This guide, published by CloudComputingJobs.co.uk, covers where to advertise cloud computing roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cloud Computing Jobs UK 2026: What to Expect Over the Next 3 Years

Cloud Computing Jobs UK 2026: salaries, hiring trends and the AWS, Azure and GCP skills shaping UK cloud careers over the next three years. Cloud computing is the infrastructure layer on which the modern digital economy runs — and the jobs market that has grown around it is one of the largest, most sustained, and most structurally resilient in the entire technology sector. But the cloud computing jobs market of 2026 looks quite different from the one that existed three years ago, and the next three years will bring further change at a pace that rewards those who understand the direction of travel. The migration phase that defined cloud hiring for much of the previous decade is largely complete for enterprise organisations. The question for most UK businesses is no longer whether to move to the cloud but how to operate, optimise, and secure what they have already built there — and how to integrate the wave of AI capability that is now being delivered primarily through cloud infrastructure. That shift has profound implications for which cloud skills are in demand, which roles are growing, and which are beginning to plateau. At the same time, new architectural patterns — multi-cloud, cloud-native, serverless, and the growing integration of edge computing with centralised cloud infrastructure — are creating entirely new categories of specialist expertise that employers are actively competing to hire. The cloud computing jobs market of 2026 is not contracting. It is evolving, and evolving in ways that create significant opportunity for job seekers who are building the right skills. This article breaks down what the UK cloud computing jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.