Application Security Engineer

Guild Mortgage,
$82,000 - $118,000Remote

About The Position

The Application Security Engineer at Guild Mortgage supports the security of our applications, including AI-enabled applications and services. Working within established secure development standards, they perform code reviews, run and tune security testing in our CI/CD pipelines, and identify, triage, and resolve application vulnerabilities using both automated tools and manual testing techniques. They contribute to Shift Left initiatives by helping software engineering teams adopt secure development practices, and they support developers in reproducing vulnerabilities, understanding their risks, and applying effective mitigations. Complex, ambiguous, or high-risk issues are escalated to the Senior Application Security Engineer. Collaboration is key—they work closely with product, engineering, DevOps, and compliance teams so that security is built into applications from the outset. They also assist the incident response team in investigating and resolving application-related security incidents.

Requirements

  • Minimum three years' experience as a software developer or similar experience.
  • Ability to organize and manage multiple priorities simultaneously.
  • Ability to work well independently or within a team.
  • Must be able to handle confidential matters with discretion.
  • Excellent interpersonal communication skills required.
  • Excellent verbal and written communication skills
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required.

Nice To Haves

  • Burp Suite Certified Practitioner
  • Hack the Box Certified Web Exploitation Specialist (HTB CWES)
  • Practical Web Pentest Professional (PWPP)

Responsibilities

  • Apply and help maintain secure development practices, including code review and security testing integrated into CI/CD pipelines.
  • Identify, validate, and triage application vulnerabilities through automated and manual testing.
  • Support Shift Left initiatives by helping development teams adopt secure coding practices and remediate findings.
  • Support the Security Champions program on development teams, including training delivery and day-to-day questions.
  • Assist developers with vulnerability reproduction, risk analysis, and remediation guidance, escalating complex or high-risk issues to senior staff.
  • Operate, tune, and maintain tools within the Application Security program, including open-source solutions.
  • Collaborate with product, engineering, DevOps, and compliance teams to integrate security requirements into application design.
  • Assist incident response teams in investigating and remediating application-related security incidents.
  • Participate in threat modeling exercises and security design reviews for new and existing applications under the direction of senior staff.
  • Perform recurring security testing and vulnerability assessments and maintain security control documentation and evidence.
  • Apply established security standards and secure design patterns to AI-enabled applications, including LLM integrations, retrieval-augmented generation (RAG) pipelines, and agentic workflows.
  • Implement, configure, test, and monitor AI guardrails, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, and data loss prevention across model inputs and outputs.
  • Execute adversarial test cases against AI and LLM applications covering prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, and excessive agency; document findings and remediation guidance using the OWASP Top 10 for LLM Applications and MITRE ATLAS as references.
  • Support security reviews of new AI use cases and third-party AI features, including verification of controls over nonpublic personal information used by AI systems.
  • Follow and help enforce secure usage standards for AI coding assistants, including human review and scanning requirements for AI-generated code.
  • Stay informed about emerging application and AI security threats, support compliance requirements, and contribute to a culture of security awareness across the organization.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • AD&D
  • LTD
  • 401(k) with employer match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service