Create Alert
Email me similar jobs

Senior Application Security Engineer

Guild Mortgage Company, closing loans and opening doors since 1960. As a mortgage banking firm we are dedicated to serving the home owner/buyer. Our goal is to provide affordable home financing for our customers, utilizing the best terms available while providing a level of professionalism and service unsurpassed in the lending industry.

Position Summary

The Senior Application Security Engineer at Guild Mortgage will play a lead role in strengthening the security of our applications, including AI-enabled applications and services. They will set secure development standards, conduct code reviews, and integrate security into our CI/CD pipelines. Their expertise in vulnerability management will be essential for identifying, triaging, and resolving application vulnerabilities through both automated tools and manual testing.

They’ll lead Shift Left initiatives, guiding software engineering teams in implementing robust security measures. As the application security Subject Matter Expert (SME), they will support developers in reproducing vulnerabilities, understanding their risks, and applying effective mitigations. They will also serve as the organization’s technical authority on securing AI and LLM-enabled applications, defining guardrail requirements, leading AI red team exercises, and setting standards for the safe handling of nonpublic personal information in AI systems.

Collaboration is key—they will work closely with product, engineering, DevOps, and compliance teams to design secure applications from the outset and align security practices with business goals. They will also partner with the incident response team to investigate and resolve application-related security incidents.

Compensation

This role is an exempt position with a Targeted Salary Range of $109,000 to $156,000 annually.

Compensation at Guild is influenced by a wide array of factors including but not limited to local and federal minimum wage requirements, education, level of experience, and applicant’s geographical location.

Essential Functions

  • Define and implement secure development practices, including code reviews and CI/CD pipeline integration.
  • Identify application vulnerabilities through automated and manual testing.
  • Lead Shift Left initiatives to embed security early in the development lifecycle.
  • Train and liaise with Security Champions on development teams.
  • Serve as the SME for application security, assisting developers with vulnerability reproduction, risk analysis, and mitigation strategies.
  • Operate and optimize all tools within the Application Security program, including open-source solutions.
  • Collaborate with product, engineering, DevOps, and compliance teams to ensure security is integrated with business objectives.
  • Partner with incident response teams to investigate and remediate application-related security incidents.
  • Proven track record of driving long-term security initiatives to completion.
  • Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications.
  • Collaborate with development teams during the planning and requirements phase to define and integrate security requirements into system and application design.
  • Conduct regular security audits, vulnerability assessments, and maintain security controls and documentation.
  • Stay informed about emerging threats, ensure compliance with regulations, and champion a culture of security awareness and improvement across the organization.
  • Secure AI Development: Define and maintain security standards, secure design patterns, and secure-by-default requirements for AI-enabled applications, including large language model (LLM) integrations, retrieval-augmented generation (RAG) pipelines, agentic workflows, and model tool-use interfaces.
  • AI Guardrails: Design, implement, and validate technical guardrails for AI systems, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, rate and cost controls, and data loss prevention across model inputs and outputs.
  • AI Red Teaming: Lead adversarial testing of AI and LLM applications covering direct and indirect prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, excessive agency, and model and plugin supply chain risk; map findings to the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • AI Security Review and Governance: Serve as the application security authority for new AI use cases and third-party AI features; assess model providers, data flows, and retention practices; maintain the application security view of the AI application inventory; and enforce requirements for the handling of nonpublic personal information (NPI) in AI systems.
  • AI-Assisted Development: Establish and enforce secure usage standards for AI coding assistants, including human review requirements, scanning coverage for AI-generated code, and controls against secret and intellectual property exposure.

Qualifications

  • Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred.
  • Minimum five years' experience as a Software Developer or similar.
  • Ability to organize and manage multiple priorities simultaneously.
  • Ability to work well independently or within a team.
  • Ability to organize and manage multiple priorities simultaneously.
  • Ability to work well independently or within a team.
  • Must be able to handle confidential matters with discretion.
  • Excellent interpersonal communication skills required.
  • Excellent verbal and written communication skills required.
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment required.
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required.
  • Commitment to company
  • Customer Service - Proactive attention to each person
  • Integrity - Do and say what's right
  • Respect - Treat others with dignity
  • Collaboration - Listen and work together
  • Learning - Seek knowledge and strive for improvement
  • Excellence – Deliver the unexpected

Supervision

  • Job Scope: Plays a key role in area by generating insights and ideas on policies, processes, procedures, and efficiency; contributes ideas to strategic and operational plans to ensure alignment
  • Complexity: Problems encountered are often complex and may involve significant resource coordination and availability, evaluating and resolving discrepancies with data, analyses, processes, etc. using own expertise and judgment
  • Impact: Decisions and actions have a major impact on the strategic and operational outcomes of the area/unit; Has a direct and significant impact on the business and/or operations of the organization as a whole

  • Interaction/Supervision: Works under broad direction with some latitude for independent actions; guided by professional standards, desired outcomes and unit/project/program specifications

Requirements

Physical: Work is primarily sedentary; mobility in an office setting.

Manual Dexterity: Ability to operate standard office equipment and keyboards.

Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media.

Environmental: Work from home

Travel: 5% or less

Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow.

Schedules: Work is primarily performed during the business week, Monday - Friday.

Guild offers a pleasant work environment, competitive compensation and excellent benefits package; including medical, dental, vision, life insurance, AD&D, LTD and 401(k) with employer match.

Guild Mortgage Company is an Equal Opportunity Employer.

REQ#: SENIO018427

Similar jobs