Senior Application Security Engineer

Guild Mortgage,
$109,000 - $156,000Remote

About The Position

The Senior Application Security Engineer at Guild Mortgage will play a lead role in strengthening the security of our applications, including AI-enabled applications and services. They will set secure development standards, conduct code reviews, and integrate security into our CI/CD pipelines. Their expertise in vulnerability management will be essential for identifying, triaging, and resolving application vulnerabilities through both automated tools and manual testing. They’ll lead Shift Left initiatives, guiding software engineering teams in implementing robust security measures. As the application security Subject Matter Expert (SME), they will support developers in reproducing vulnerabilities, understanding their risks, and applying effective mitigations. They will also serve as the organization’s technical authority on securing AI and LLM-enabled applications, defining guardrail requirements, leading AI red team exercises, and setting standards for the safe handling of nonpublic personal information in AI systems. Collaboration is key—they will work closely with product, engineering, DevOps, and compliance teams to design secure applications from the outset and align security practices with business goals. They will also partner with the incident response team to investigate and resolve application-related security incidents.

Requirements

  • Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred.
  • Minimum five years' experience as a Software Developer or similar.
  • Ability to organize and manage multiple priorities simultaneously.
  • Ability to work well independently or within a team.
  • Must be able to handle confidential matters with discretion.
  • Excellent interpersonal communication skills required.
  • Excellent verbal and written communication skills required.
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment required.
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required.
  • Commitment to company
  • Customer Service - Proactive attention to each person
  • Integrity - Do and say what's right
  • Respect - Treat others with dignity
  • Collaboration - Listen and work together
  • Learning - Seek knowledge and strive for improvement
  • Excellence – Deliver the unexpected

Responsibilities

  • Define and implement secure development practices, including code reviews and CI/CD pipeline integration.
  • Identify application vulnerabilities through automated and manual testing.
  • Lead Shift Left initiatives to embed security early in the development lifecycle.
  • Train and liaise with Security Champions on development teams.
  • Serve as the SME for application security, assisting developers with vulnerability reproduction, risk analysis, and mitigation strategies.
  • Operate and optimize all tools within the Application Security program, including open-source solutions.
  • Collaborate with product, engineering, DevOps, and compliance teams to ensure security is integrated with business objectives.
  • Partner with incident response teams to investigate and remediate application-related security incidents.
  • Proven track record of driving long-term security initiatives to completion.
  • Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications.
  • Collaborate with development teams during the planning and requirements phase to define and integrate security requirements into system and application design.
  • Conduct regular security audits, vulnerability assessments, and maintain security controls and documentation.
  • Stay informed about emerging threats, ensure compliance with regulations, and champion a culture of security awareness and improvement across the organization.
  • Secure AI Development: Define and maintain security standards, secure design patterns, and secure-by-default requirements for AI-enabled applications, including large language model (LLM) integrations, retrieval-augmented generation (RAG) pipelines, agentic workflows, and model tool-use interfaces.
  • AI Guardrails: Design, implement, and validate technical guardrails for AI systems, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, rate and cost controls, and data loss prevention across model inputs and outputs.
  • AI Red Teaming: Lead adversarial testing of AI and LLM applications covering direct and indirect prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, excessive agency, and model and plugin supply chain risk; map findings to the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • AI Security Review and Governance: Serve as the application security authority for new AI use cases and third-party AI features; assess model providers, data flows, and retention practices; maintain the application security view of the AI application inventory; and enforce requirements for the handling of nonpublic personal information (NPI) in AI systems.
  • AI-Assisted Development: Establish and enforce secure usage standards for AI coding assistants, including human review requirements, scanning coverage for AI-generated code, and controls against secret and intellectual property exposure.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • AD&D
  • LTD
  • 401(k) with employer match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service