Summary
Guild Mortgage Company is a mortgage banking firm dedicated to providing affordable home financing. The Application Security Engineer secures applications, including AI-enabled applications and services, through code reviews, security testing, vulnerability management, secure development initiatives, and collaboration with engineering and compliance teams.
Responsibilities
- Apply and help maintain secure development practices, including code review and security testing integrated into CI/CD pipelines
- Identify, validate, and triage application vulnerabilities through automated and manual testing
- Support Shift Left initiatives by helping development teams adopt secure coding practices and remediate findings
- Support the Security Champions program on development teams, including training delivery and day-to-day questions
- Assist developers with vulnerability reproduction, risk analysis, and remediation guidance, escalating complex or high-risk issues to senior staff
- Operate, tune, and maintain tools within the Application Security program, including open-source solutions
- Collaborate with product, engineering, DevOps, and compliance teams to integrate security requirements into application design
- Assist incident response teams in investigating and remediating application-related security incidents
- Threat Modeling & Risk Assessment: Participate in threat modeling exercises and security design reviews for new and existing applications under the direction of senior staff
- Perform recurring security testing and vulnerability assessments and maintain security control documentation and evidence
- Secure AI Development: Apply established security standards and secure design patterns to AI-enabled applications, including LLM integrations, retrieval-augmented generation (RAG) pipelines, and agentic workflows
- AI Guardrails: Implement, configure, test, and monitor AI guardrails, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, and data loss prevention across model inputs and outputs
- AI Red Teaming: Execute adversarial test cases against AI and LLM applications covering prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, and excessive agency; document findings and remediation guidance using the OWASP Top 10 for LLM Applications and MITRE ATLAS as references
- Support security reviews of new AI use cases and third-party AI features, including verification of controls over nonpublic personal information used by AI systems
- Follow and help enforce secure usage standards for AI coding assistants, including human review and scanning requirements for AI-generated code
- Stay informed about emerging application and AI security threats, support compliance requirements, and contribute to a culture of security awareness across the organization
Skills
- A combination of education and experience may be considered in lieu of the Bachelor's degree
- Minimum three years' experience as a software developer or similar experience
- Ability to organize and manage multiple priorities simultaneously
- Ability to work well independently or within a team
- Must be able to handle confidential matters with discretion
- Excellent interpersonal communication skills required
- Excellent verbal and written communication skills
- Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
- Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required
- Physical: Work is primarily sedentary; mobility in an office setting
- Manual Dexterity: Ability to operate standard office equipment and keyboards
- Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media
- Environmental: Work from home
- Travel: 5% or less
- Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow
- Schedules: Work is primarily performed during the business week, Monday - Friday
- Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred
- Preferred qualifications: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP)
Qualifications
Must Haves
- A combination of education and experience may be considered in lieu of the Bachelor's degree
- Minimum three years' experience as a software developer or similar experience
- Ability to organize and manage multiple priorities simultaneously
- Ability to work well independently or within a team
- Must be able to handle confidential matters with discretion
- Excellent interpersonal communication skills required
- Excellent verbal and written communication skills
- Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
- Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required
- Physical: Work is primarily sedentary; mobility in an office setting
- Manual Dexterity: Ability to operate standard office equipment and keyboards
- Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media
- Environmental: Work from home
- Travel: 5% or less
- Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow
- Schedules: Work is primarily performed during the business week, Monday - Friday
Nice to Haves
- Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred
- Preferred qualifications: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP)
Benefits
- Medical insurance
- Dental insurance
- Vision insurance
- Life insurance
- AD&D insurance
- LTD insurance
- 401(k) with employer match
- Work from home