Guild Mortgage logo
Guild Mortgage

In neighborhoods and communities everywhere, we deliver the promise of home.

Manager, Application Security

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 1,001-5,000Since 1960H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

7 days ago

Salary

$124.1K - $181.6K / year

Seniority

Lead

Bachelor Degree7 yrs expExperience acceptedEnglishCloudCyber Security

Job Description

Manager, Application Security

Guild Mortgage

• Develop and execute application security strategy, including threat modeling, secure code review practices, and vulnerability management • Establish and maintain secure software development lifecycle practices and standards across all engineering teams • Oversee vulnerability management programs including triage, remediation tracking, and executive reporting • Manage the application security tool portfolio including SAST, DAST, and software composition analysis platforms • Lead threat modeling and architectural security reviews for critical systems and new initiatives • Coordinate third-party security assessments, penetration testing, and code reviews • Drive security awareness and training programs tailored to developer and architect audiences • Establish KPIs and executive dashboards to communicate application security posture and risk trends • Partner with Engineering, DevOps, and Product leadership to embed security into CI/CD pipelines and release processes • Define and enforce application security policies, standards, and control frameworks • Evaluate and respond to emerging threats, CVEs, and industry developments relevant to application security • Lead, mentor, and grow a team of application security engineers

Job Requirements

  • Bachelor's Degree in Computer Science, Cybersecurity, Information Technology, or related field, or equivalent professional experience
  • Minimum seven years experience in application security, software development, or related security engineering roles
  • Minimum three years supervisory or leadership experience
  • Demonstrated knowledge of secure coding principles, OWASP vulnerabilities, and threat modeling methodologies
  • Proficiency with application security tools including SAST, DAST, and software composition analysis platforms
  • Strong communication skills – equally comfortable presenting risk to executives or walking engineers through code fixes
  • Excellent verbal and written communication skills
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • AD&D insurance
  • Long-term disability insurance
  • 401(k) with employer match

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+H1B Sponsor

• As a Senior Account Manager here at Honeywell, you will be responsible for managing and growing key customer accounts, ensuring customer satisfaction, and driving revenue growth. • You will act as the primary point of contact for clients, developing strong relationships and understanding their business needs to provide tailored solutions. • In this role, you will impact Honeywell’s market presence and revenue by fostering long-term partnerships with clients and delivering exceptional account management and business development strategies. • Note that this role requires travel up to 50% domestically.

Ohio
Backblaze logo

Senior AI Security Engineer

Backblaze

Backblaze is the cloud storage innovator delivering a modern alternative to traditional cloud providers.

Full TimeRemoteTeam 201-500Since 2007H1B Sponsor

• Architect and implement guardrails for tool-using AI systems, including: • Tool access controls and allowlists • Context and memory isolation • Step-level validation of agent actions • Apply mitigations aligned to the OWASP Agentic AI Top 10 (e.g., prompt injection, unsafe tool use, data leakage, excessive autonomy) • Build enforcement mechanisms that govern AI behavior at execution time: • Interceptors, proxies, or middleware for tool/API calls • Policy decision and enforcement layers • Rate limits, execution bounds, and kill-switches • Design and implement identity and access controls for agents and automation, including: • Short-lived credentials and scoped permissions • Clear separation between human and non-human access • Strong binding of identity to task context and execution • Ensure all AI actions are attributable and auditable • Implement logging and tracing for AI activity: • Prompts, tool usage, and decision flows • Build detection capabilities using: • Behavioral baselining and anomaly detection techniques • Identify and alert on: • Abnormal tool usage • Suspicious prompt patterns • Unexpected data access • Perform agentic system threat modeling using MAESTRO, including: • Mapping agent capabilities, trust boundaries, and attack paths • Modeling misuse and adversarial scenarios • Translate findings into practical safeguards and detection logic • Protect developers using AI tools by: • Preventing sensitive data exposure • Validating AI-generated code and actions • Constraining unsafe automation

Argentina
Full TimeRemoteTeam 10,001+H1B Sponsor

• Lead threat modeling, hardening and operation of security services • Define and implement security standards and automated security controls • Partner with cross-functional teams to embed secure design practices • Lead technical direction and roadmap execution for assigned area • Maintain high Operational Excellence to minimize downtime • Participate in on-call rotation to respond to events • Manage lifecycle of product and cloud security vulnerabilities • Influence secure adoption of LLMs and AI tools • Mentor and coach earlier career engineers

Florida
$193.8K - $285K / year
Full TimeRemoteTeam 10,001+H1B Sponsor

• Implement and tune core security controls that protect employees across three global brands • Operate the day-to-day security stack, spanning endpoint detection and response (EDR), zero-trust network access, identity-aware proxies, browser security, and data loss prevention (DLP) • Use AI-assisted coding tools to automate security workflows, incident response, and compliance evidence collection • Address modern SaaS risk such as shadow IT, OAuth token sprawl, and high-risk application reviews • Help teams adopt secure-by-default baselines

United States
$130.6K - $192K / year