Application Security Engineer
Joining Qare means embarking on a human and technological adventure where every day counts towards improving the lives of millions of people. Whether you're passionate about tech, healthcare, or innovation, you'll find a playing field here that matches your ambitions!
About the role
You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams.
As an experienced Application Security Engineer, your working day will include but not be limited to:
DevSecOps & Pipeline Security
Implement and maintain security testing in GitLab CI pipelines
Configure and tune SAST, DAST, dependency scanning, and secrets detection
Build automated security gates that balance rigour with delivery velocity
Enable self-serve security tooling for development teams
Contribute code and patches to security tooling and configurations
Secure Development
Define and enforce secure coding standards
Conduct security-focused code reviews and threat modelling for new features
Provide remediation guidance for application vulnerabilities
Train and support developers on secure coding practices
Vulnerability Management
Triage, patch and track application vulnerabilities through to remediation
Manage dependency vulnerabilities and upgrade cycles
Report on application security posture to senior leadership
Risk & Compliance
Embed GDPR and healthcare regulatory requirements into development processes
Support DCB0129 clinical safety compliance for software changes
Support customer security due diligence and audits
Support ISO27001:2022 ISMS controls and audit process
Key Skills and Experience
Essential:
3+ years in application security, DevSecOps, and secure software development
Hands-on experience with CI/CD security integration (GitLab CI or similar)
Familiarity with SAST/DAST tooling and dependency scanning
Understanding of common vulnerabilities (OWASP Top 10) and remediation
Previous experience working as a back end or full stack developer
Knowledge of GDPR and data protection legislation
Strong communicator; able to translate security requirements for developers
Desirable:
Development background with security focus
Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel)
Experience with CSPM tooling (Wiz, Prisma Cloud, or similar)
Penetration testing or bug bounty experience
Experience in regulated environments (healthcare, financial services)
Familiarity with threat modelling frameworks (STRIDE, PASTA)
About Qare
Qare, the leading telemedicine platform in France, handles 8 million consultations, or 230,000 per month, and works with 2,300 doctors. Qare's service is available 7 days a week, from 6a.m. to midnight, via a mobile app or online for all French citizens nationwide. Since its inception, Qare has championed a high-quality, professional, and regulated telemedicine model.
Qare monitors 15 key medical quality indicators daily, focusing on patient care and follow-up. According to a post-teleconsultation survey, 96% of patients reported being satisfied with the service. Qare is also specifically available to 23 groups of higher education institutions, including schools and universities. Qare is the initiator and founding member of the MentalTech collective.
In 2021, Qare joined the European e-health group HealthHero. Qare obtained accreditation for teleconsultation companies from the Ministry of Health in 2024.
Why us?
Our values guide us, every day we strive to Simplify, Own, Aspire and Respect (SOAR) – and we're rewarded when we do.
What we offer
A full induction training programme, which will be undertaken via Microsoft Teams.
An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic.
Internal actions put in place to preserve the mental and physical health of employees.
A balance between professional and private life.
A hybrid working arrangement: the possibility of working remotely up to three days a week in a flexible manner.
An eco-friendly workspace where it's pleasant to work.
Apply
If you are interested in making a difference and believe this role is a good fit for you, we would love to hear from you. If you have any questions, please contact our Recruitment Team at recruitment-team@healthhero.com
Hybrid: Paris (There is a requirement to work in the office for a minimum of two days per week)
Closing date for applications: Friday 29 May (5pm)
- Localisations
- Paris
- Statut à distance
- Hybride
À propos de Qare
Qare, leader de la téléconsultation en France, comptabilise 8 millions de téléconsultations, soit 230 000 par mois, et 2300 médecins. Le service de Qare est accessible 7j/7 et de 6h à minuit, via une application mobile ou internet pour tous les Français sur tout le territoire. Depuis ses débuts, Qare défend un modèle de téléconsultation de qualité, professionnelle et encadrée.
Qare suit ainsi quotidiennement 15 indicateurs de qualité médicale sur la prise en charge et le suivi des patients. Selon un sondage post-téléconsultation, 96% des patients se déclarent satisfaits du service. Qare est également spécifiquement disponible dans 23 groupes d’établissements de l’enseignement supérieur, écoles et universités. Qare est l’initiateur et membre fondateur du collectif MentalTech.
En 2021, Qare rejoint le groupe de e-santé européen HealthHero. Qare a obtenu l’agrément des sociétés de téléconsultation par le ministère de la Santé en 2024.