Description
Guild Mortgage Company, closing loans and opening doors since 1960.
As a mortgage banking firm we are dedicated to serving the home owner/buyer.
Our goal is to provide affordable home financing for our customers, utilizing the best terms available while providing a level of professionalism and service unsurpassed in the lending industry.
Position Summary
The Application Security Engineer at Guild Mortgage supports the security of our applications, including AI-enabled applications and services.
Working within established secure development standards, they perform code reviews, run and tune security testing in our CI/CD pipelines, and identify, triage, and resolve application vulnerabilities using both automated tools and manual testing techniques.
They contribute to Shift Left initiatives by helping software engineering teams adopt secure development practices, and they support developers in reproducing vulnerabilities, understanding their risks, and applying effective mitigations.
Complex, ambiguous, or high-risk issues are escalated to the Senior Application Security Engineer.
Collaboration is key—they work closely with product, engineering, DevOps, and compliance teams so that security is built into applications from the outset.
They also assist the incident response team in investigating and resolving application-related security incidents.
Compensation
This role is an exempt position with a Targeted Salary Range of $82,000 to $118,000 annually.
Compensation at Guild is influenced by a wide array of factors including but not limited to local and federal minimum wage requirements, education, level of experience, and applicant’s geographical location.
Essential Functions
Apply and help maintain secure development practices, including code review and security testing integrated into CI/CD pipelines.Identify, validate, and triage application vulnerabilities through automated and manual testing.Support Shift Left initiatives by helping development teams adopt secure coding practices and remediate findings.Support the Security Champions program on development teams, including training delivery and day-to-day questions.Assist developers with vulnerability reproduction, risk analysis, and remediation guidance, escalating complex or high-risk issues to senior staff.Operate, tune, and maintain tools within the Application Security program, including open-source solutions.Collaborate with product, engineering, DevOps, and compliance teams to integrate security requirements into application design.Assist incident response teams in investigating and remediating application-related security incidents.Threat Modeling & Risk Assessment: Participate in threat modeling exercises and security design reviews for new and existing applications under the direction of senior staff.Perform recurring security testing and vulnerability assessments and maintain security control documentation and evidence.Secure AI Development: Apply established security standards and secure design patterns to AI-enabled applications, including LLM integrations, retrieval-augmented generation (RAG) pipelines, and agentic workflows.AI Guardrails: Implement, configure, test, and monitor AI guardrails, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, and data loss prevention across model inputs and outputs.AI Red Teaming: Execute adversarial test cases against AI and LLM applications covering prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, and excessive agency; document findings and remediation guidance using the OWASP Top 10 for LLM Applications and MITRE ATLAS as references.Support security reviews of new AI use cases and third-party AI features, including verification of controls over nonpublic personal information used by AI systems.Follow and help enforce secure usage standards for AI coding assistants, including human review and scanning requirements for AI-generated code.Stay informed about emerging application and AI security threats, support compliance requirements, and contribute to a culture of security awareness across the organization.
Qualifications
Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred.A combination of education and experience may be considered in lieu of the Bachelor’s degree.Minimum three years' experience as a software developer or similar experience.
Preferred qualifications: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP).Ability to organize and manage multiple priorities simultaneously.Ability to work well independently or within a team.Must be able to handle confidential matters with discretion.Excellent interpersonal communication skills required.Excellent verbal and written communication skillsHighly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environmentProficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required.Commitment to companyCustomer Service - Proactive attention to each personIntegrity - Do and say what's rightRespect - Treat others with dignityCollaboration - Listen and work togetherLearning - Seek knowledge and strive for improvementExcellence – Deliver the unexpected
Supervision
Job Scope: Recognized as a developing contributorComplexity: Problems encountered are often complex and may involve significant resource coordination and availability, evaluating and resolving discrepancies with data, analyses, processes, etc.
using own expertise and judgmentImpact: Decisions and actions primarily impact own work with moderate impact on peers in their area; contributes as team member rather than leaderInteraction/Supervision: Works under broad direction with some latitude for independent actions; guided by professional standards, desired outcomes and unit/project/program specifications.
Requirements
Physical: Work is primarily sedentary; mobility in an office setting.
Manual Dexterity: Ability to operate standard office equipment and keyboards.
Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media.
Environmental: Work from home
Travel: 5% or less
Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow.
Schedules: Work is primarily performed during the business week, Monday - Friday.
Guild offers a pleasant work environment, competitive compensation and excellent benefits package; including medical, dental, vision, life insurance, AD&D, LTD and 401(k) with employer match.
Guild Mortgage Company is an Equal Opportunity Employer.
REQ#: APPLI018419