Summary
Guild Mortgage Company is a mortgage banking firm serving homeowners and homebuyers through affordable home financing. The Application Security Engineer secures applications, including AI-enabled applications and services, by conducting code reviews, vulnerability testing, threat modeling, and incident response support. The role also helps engineering teams adopt secure development practices and implements security controls and guardrails for AI applications.
Responsibilities
- Apply and help maintain secure development practices, including code review and security testing integrated into CI/CD pipelines
- Identify, validate, and triage application vulnerabilities through automated and manual testing
- Support Shift Left initiatives by helping development teams adopt secure coding practices and remediate findings
- Support the Security Champions program on development teams, including training delivery and day-to-day questions
- Assist developers with vulnerability reproduction, risk analysis, and remediation guidance, escalating complex or high-risk issues to senior staff
- Operate, tune, and maintain tools within the Application Security program, including open-source solutions
- Collaborate with product, engineering, DevOps, and compliance teams to integrate security requirements into application design
- Assist incident response teams in investigating and remediating application-related security incidents
- Threat Modeling & Risk Assessment: Participate in threat modeling exercises and security design reviews for new and existing applications under the direction of senior staff
- Perform recurring security testing and vulnerability assessments and maintain security control documentation and evidence
- Secure AI Development: Apply established security standards and secure design patterns to AI-enabled applications, including LLM integrations, retrieval-augmented generation (RAG) pipelines, and agentic workflows
- AI Guardrails: Implement, configure, test, and monitor AI guardrails, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, and data loss prevention across model inputs and outputs
- AI Red Teaming: Execute adversarial test cases against AI and LLM applications covering prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, and excessive agency; document findings and remediation guidance using the OWASP Top 10 for LLM Applications and MITRE ATLAS as references
- Support security reviews of new AI use cases and third-party AI features, including verification of controls over nonpublic personal information used by AI systems
- Follow and help enforce secure usage standards for AI coding assistants, including human review and scanning requirements for AI-generated code
- Stay informed about emerging application and AI security threats, support compliance requirements, and contribute to a culture of security awareness across the organization
Skills
- A combination of education and experience may be considered in lieu of the Bachelor's degree
- Minimum three years' experience as a software developer or similar experience
- Ability to organize and manage multiple priorities simultaneously
- Ability to work well independently or within a team
- Must be able to handle confidential matters with discretion
- Excellent interpersonal communication skills required
- Excellent verbal and written communication skills
- Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
- Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required
- Physical: Work is primarily sedentary; mobility in an office setting
- Manual Dexterity: Ability to operate standard office equipment and keyboards
- Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media
- Environmental: Work from home
- Travel: 5% or less
- Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow
- Schedules: Work is primarily performed during the business week, Monday - Friday
- Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred
- Preferred qualifications: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP)
Qualifications
Must Haves
- A combination of education and experience may be considered in lieu of the Bachelor's degree
- Minimum three years' experience as a software developer or similar experience
- Ability to organize and manage multiple priorities simultaneously
- Ability to work well independently or within a team
- Must be able to handle confidential matters with discretion
- Excellent interpersonal communication skills required
- Excellent verbal and written communication skills
- Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
- Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required
- Physical: Work is primarily sedentary; mobility in an office setting
- Manual Dexterity: Ability to operate standard office equipment and keyboards
- Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media
- Environmental: Work from home
- Travel: 5% or less
- Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow
- Schedules: Work is primarily performed during the business week, Monday - Friday
Nice to Haves
- Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred
- Preferred qualifications: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP)
Benefits
- Work from home
- Medical insurance
- Dental insurance
- Vision insurance
- Life insurance
- AD&D insurance
- LTD insurance
- 401(k) with employer match