Guild Mortgage logo
Guild Mortgage
Posted 46 days agoVerified live 15h ago

Application Security Engineer

Brief overview

Remote
$82k–$118k/yrStated range
3+ yrsMinimum
Application SecuritySecure CodingCode ReviewCI/CD Security TestingVulnerability AssessmentWeb Penetration TestingThreat ModelingIncident ResponseAI/LLM SecurityPrompt Injection DefenseOWASP Top 10 for LLM ApplicationsMITRE ATLAS

About the company

Guild Mortgage logo
Guild Mortgageguildmortgage.com

Guild Mortgage is a growing mortgage company that offers residential mortgage products as well as local in-house origination and servicing.

Job description

Summary

Guild Mortgage Company is a mortgage banking firm dedicated to providing affordable home financing. The Application Security Engineer secures applications, including AI-enabled applications and services, through code reviews, security testing, vulnerability management, secure development initiatives, and collaboration with engineering and compliance teams.

Responsibilities

  • Apply and help maintain secure development practices, including code review and security testing integrated into CI/CD pipelines
  • Identify, validate, and triage application vulnerabilities through automated and manual testing
  • Support Shift Left initiatives by helping development teams adopt secure coding practices and remediate findings
  • Support the Security Champions program on development teams, including training delivery and day-to-day questions
  • Assist developers with vulnerability reproduction, risk analysis, and remediation guidance, escalating complex or high-risk issues to senior staff
  • Operate, tune, and maintain tools within the Application Security program, including open-source solutions
  • Collaborate with product, engineering, DevOps, and compliance teams to integrate security requirements into application design
  • Assist incident response teams in investigating and remediating application-related security incidents
  • Threat Modeling & Risk Assessment: Participate in threat modeling exercises and security design reviews for new and existing applications under the direction of senior staff
  • Perform recurring security testing and vulnerability assessments and maintain security control documentation and evidence
  • Secure AI Development: Apply established security standards and secure design patterns to AI-enabled applications, including LLM integrations, retrieval-augmented generation (RAG) pipelines, and agentic workflows
  • AI Guardrails: Implement, configure, test, and monitor AI guardrails, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, and data loss prevention across model inputs and outputs
  • AI Red Teaming: Execute adversarial test cases against AI and LLM applications covering prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, and excessive agency; document findings and remediation guidance using the OWASP Top 10 for LLM Applications and MITRE ATLAS as references
  • Support security reviews of new AI use cases and third-party AI features, including verification of controls over nonpublic personal information used by AI systems
  • Follow and help enforce secure usage standards for AI coding assistants, including human review and scanning requirements for AI-generated code
  • Stay informed about emerging application and AI security threats, support compliance requirements, and contribute to a culture of security awareness across the organization

Skills

  • A combination of education and experience may be considered in lieu of the Bachelor's degree
  • Minimum three years' experience as a software developer or similar experience
  • Ability to organize and manage multiple priorities simultaneously
  • Ability to work well independently or within a team
  • Must be able to handle confidential matters with discretion
  • Excellent interpersonal communication skills required
  • Excellent verbal and written communication skills
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required
  • Physical: Work is primarily sedentary; mobility in an office setting
  • Manual Dexterity: Ability to operate standard office equipment and keyboards
  • Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media
  • Environmental: Work from home
  • Travel: 5% or less
  • Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow
  • Schedules: Work is primarily performed during the business week, Monday - Friday
  • Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred
  • Preferred qualifications: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP)

Qualifications

Must Haves

  • A combination of education and experience may be considered in lieu of the Bachelor's degree
  • Minimum three years' experience as a software developer or similar experience
  • Ability to organize and manage multiple priorities simultaneously
  • Ability to work well independently or within a team
  • Must be able to handle confidential matters with discretion
  • Excellent interpersonal communication skills required
  • Excellent verbal and written communication skills
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required
  • Physical: Work is primarily sedentary; mobility in an office setting
  • Manual Dexterity: Ability to operate standard office equipment and keyboards
  • Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media
  • Environmental: Work from home
  • Travel: 5% or less
  • Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow
  • Schedules: Work is primarily performed during the business week, Monday - Friday

Nice to Haves

  • Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred
  • Preferred qualifications: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP)

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • AD&D insurance
  • LTD insurance
  • 401(k) with employer match
  • Work from home

More jobs like this