> Markdown version of [/jobs/ext/2222284-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2222284-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Guild Mortgage Company LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $109,000.0 - $156,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Artificial Intelligence, Cloud Computing, Code Review, Cyber Security, Continuous Integration, Information Leak Prevention, DevOps, Microsoft Office, Open Source Technology, Open Web Application Security, Proprietary Software, Red Team (Cyber Security), Secure Coding, Software Engineering, Data Streaming, Software Vulnerability Management, Large Language Models, Software Security, Information Technology, Wikis, Vulnerability Analysis - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/979b368d-785c-4ca3-abb4-b42e5214d4d5 ## About the Role * Bachelor's degree in degree in Computer Science, Software Engineering, Cyber Security or equivalent, preferred. * Minimum five years' experience as a Software Developer or similar. * Ability to organize and manage multiple priorities simultaneously. * Ability to work well independently or within a team. * Ability to organize and manage multiple priorities simultaneously. * Ability to work well independently or within a team. * Must be able to handle confidential matters with discretion. * Excellent interpersonal communication skills required. * Excellent verbal and written communication skills required. * Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment required. * Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required. * Commitment to company * Customer Service - Proactive attention to each person * Integrity - Do and say what's right * Respect - Treat others with dignity * Collaboration - Listen and work together * Learning - Seek knowledge and strive for improvement * Excellence - Deliver the unexpected Supervision, Physical: Work is primarily sedentary; mobility in an office setting. Manual Dexterity: Ability to operate standard office equipment and keyboards. Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media. ## Description The Senior Application Security Engineer at Guild Mortgage will play a lead role in strengthening the security of our applications, including AI-enabled applications and services. They will set secure development standards, conduct code reviews, and integrate security into our CI/CD pipelines. Their expertise in vulnerability management will be essential for identifying, triaging, and resolving application vulnerabilities through both automated tools and manual testing. They'll lead Shift Left initiatives, guiding software engineering teams in implementing robust security measures. As the application security Subject Matter Expert (SME), they will support developers in reproducing vulnerabilities, understanding their risks, and applying effective mitigations. They will also serve as the organization's technical authority on securing AI and LLM-enabled applications, defining guardrail requirements, leading AI red team exercises, and setting standards for the safe handling of nonpublic personal information in AI systems. Collaboration is key-they will work closely with product, engineering, DevOps, and compliance teams to design secure applications from the outset and align security practices with business goals. They will also partner with the incident response team to investigate and resolve application-related security incidents., * Define and implement secure development practices, including code reviews and CI/CD pipeline integration. * Identify application vulnerabilities through automated and manual testing. * Lead Shift Left initiatives to embed security early in the development lifecycle. * Train and liaise with Security Champions on development teams. * Serve as the SME for application security, assisting developers with vulnerability reproduction, risk analysis, and mitigation strategies. * Operate and optimize all tools within the Application Security program, including open-source solutions. * Collaborate with product, engineering, DevOps, and compliance teams to ensure security is integrated with business objectives. * Partner with incident response teams to investigate and remediate application-related security incidents. * Proven track record of driving long-term security initiatives to completion. * Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications. * Collaborate with development teams during the planning and requirements phase to define and integrate security requirements into system and application design. * Conduct regular security audits, vulnerability assessments, and maintain security controls and documentation. * Stay informed about emerging threats, ensure compliance with regulations, and champion a culture of security awareness and improvement across the organization. * Secure AI Development: Define and maintain security standards, secure design patterns, and secure-by-default requirements for AI-enabled applications, including large language model (LLM) integrations, retrieval-augmented generation (RAG) pipelines, agentic workflows, and model tool-use interfaces. * AI Guardrails: Design, implement, and validate technical guardrails for AI systems, including prompt injection defenses, input and output filtering and validation, least-privilege scoping of agent tools and data sources, rate and cost controls, and data loss prevention across model inputs and outputs. * AI Red Teaming: Lead adversarial testing of AI and LLM applications covering direct and indirect prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, excessive agency, and model and plugin supply chain risk; map findings to the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework. * AI Security Review and Governance: Serve as the application security authority for new AI use cases and third-party AI features; assess model providers, data flows, and retention practices; maintain the application security view of the AI application inventory; and enforce requirements for the handling of nonpublic personal information (NPI) in AI systems. * AI-Assisted Development: Establish and enforce secure usage standards for AI coding assistants, including human review requirements, scanning coverage for AI-generated code, and controls against secret and intellectual property exposure., * Job Scope: Plays a key role in area by generating insights and ideas on policies, processes, procedures, and efficiency; contributes ideas to strategic and operational plans to ensure alignment * Complexity: Problems encountered are often complex and may involve significant resource coordination and availability, evaluating and resolving discrepancies with data, analyses, processes, etc. using own expertise and judgment * Impact: Decisions and actions have a major impact on the strategic and operational outcomes of the area/unit; Has a direct and significant impact on the business and/or operations of the organization as a whole * Interaction/Supervision: Works under broad direction with some latitude for independent actions; guided by professional standards, desired outcomes and unit/project/program specifications, Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow. Schedules: Work is primarily performed during the business week, Monday - Friday. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Living Documentation That Can't Die](https://www.wearedevelopers.com/videos/2025-living-documentation-that-can-t-die) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)