First you’ll want to make sure the relevant rules are included in your profile. Then you need to make sure your Quality Gate fails if you have
unreviewed Security Hotspots
Security rating worse than A*
* In practice you may want to set this higher. The letter ratings correspond to the severity of the worst open issue. If you set the OWASP-related rules to Blocker or Critical in your profile, then you might allow a C to pass
What you actually wanted to add to your Quality Gate is the Security Review Rating. For comparison, here’s our default QG, with attention drawn to all the security-related conditions: