×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Engineer

Job in Lawrence, Essex County, Massachusetts, 01842, USA
Listing for: New Balance
Full Time position
Listed on 2026-07-28
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 104500 - 155500 USD Yearly USD 104500.00 155500.00 YEAR
Job Description & How to Apply Below

Who We Are:Since 1906, New Balance has empowered people through sport and craftsmanship to create positive change in communities around the world. We innovate fearlessly, guided by our core values and driven by the belief that conventions were meant to be challenged. We foster a culture in which every associate feels welcomed and respected, where leaders and creatives are inspired to shape the world of tomorrow by taking bold action today.

Who We Are:Since 1906, New Balance has empowered people through sport and craftsmanship to create positive change in communities around the world. We innovate fearlessly, guided by our core values and driven by the belief that conventions were meant to be challenged. We foster a culture in which every associate feels welcomed and respected, where leaders and creatives are inspired to shape the world of tomorrow by taking bold action today.

JOB MISSION:As a member of the New Balance Information Security Team, the Senior Application Security Engineer will be responsible for protecting New Balance applications, APIs, cloud-native services, and software development platforms from current and emerging security threats. This role serves as the primary Application Security Engineering resource partnering with development, cloud, architecture, infrastructure, and vulnerability management teams to embed security throughout the Software Development Lifecycle (SDLC).

The position will work closely with the Principal Application Security Engineer to mature New Balance's Application Security Program while driving automation and operational efficiencies through Security Orchestration, Automation and Response (SOAR) technologies. This role is designed as approximately: 70% Application Security and 30% Vulnerability Management Engineering & Automation. The successful candidate will help establish secure development practices, support PCI DSS compliance initiatives, improve developer enablement, and create automated workflows that reduce risk and accelerate remediation across the enterprise.

MAJOR ACCOUNTABILITIES:

Application Security

  • Partner with development teams to implement secure-by-design principles throughout the SDLC.
  • Conduct application security assessments for internally developed and customer-facing applications.
  • Perform threat modeling and secure architecture reviews for cloud and hybrid environments.
  • Review application, API, and cloud security findings and provide remediation guidance.
  • Establish and maintain application security policies, standards, and procedures.
  • Mentor developers and technical teams on secure development practices and secure coding techniques.
  • Collaborate with Dev Ops teams to integrate security controls into CI/CD pipelines.
  • Support implementation, administration, and optimization of: SAST, SCA, DAST, API Security, Container Security, CNAPP/CSPM/CWPP solutions, WAF technologies, PKI services, and automated attack protections.

Security Automation & SOAR

  • Lead development and implementation of SOAR workflows supporting Application Security and Vulnerability Management functions.
  • Design automated processes for: vulnerability intake, risk prioritization, ticket creation, ownership assignment, remediation tracking, SLA monitoring, compliance reporting.
  • Integrate security tools, cloud platforms, CI/CD pipelines, and ticketing systems into automated workflows.
  • Develop scripts and automation using APIs and modern automation frameworks.

Vulnerability Management Support

  • Support risk-based vulnerability prioritization activities.
  • Review application and cloud vulnerabilities requiring advanced technical analysis.
  • Partner with Vulnerability Management personnel to improve remediation effectiveness.
  • Identify automation opportunities that streamline vulnerability lifecycle management processes.

PCI Compliance Support

  • Support PCI DSS compliance activities related to application security and secure software development.
  • Perform PCI-focused application security reviews and validation activities.
  • Assist with collection of evidence and documentation for PCI assessments and audits.
  • Support secure coding, segmentation, authentication, logging, and vulnerability management requirements…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary