Senior Application Security Engineer
About the role
Job Mission: As a member of the New Balance Information Security Team, the Senior Application Security Engineer will be responsible for protecting New Balance applications, APIs, cloud-native services, and software development platforms from current and emerging security threats. This role serves as the primary Application Security Engineering resource partnering with development, cloud, architecture, infrastructure, and vulnerability management teams to embed security throughout the Software Development Lifecycle (SDLC).
Responsibilities
- Conduct application security assessments for internally developed and customer-facing applications.
- Perform threat modeling and secure architecture reviews for cloud and hybrid environments.
- Review application, API, and cloud security findings and provide remediation guidance.
- Establish and maintain application security policies, standards, and procedures.
- Mentor developers and technical teams on secure development practices and secure coding techniques.
- Collaborate with DevOps teams to integrate security controls into CI/CD pipelines.
- Support implementation, administration, and optimization of: SAST, SCA, DAST, API Security, Container Security, CNAPP/CSPM/CWPP solutions, WAF technologies, PKI services, and automated attack protections.
- Lead development and implementation of SOAR workflows supporting Application Security and Vulnerability Management functions.
- Develop scripts and automation using APIs and modern automation frameworks.
- Support risk-based vulnerability prioritization activities.
- Partner with Vulnerability Management personnel to improve remediation effectiveness.
- Identify automation opportunities that streamline vulnerability lifecycle management processes.
- Support PCI DSS compliance activities related to application security and secure software development.
- Perform PCI-focused application security reviews and validation activities.
- Afford support for secure coding, segmentation, authentication, logging, and vulnerability management requirements within PCI-scoped environments.
- Partner with compliance and audit teams to maintain PCI DSS application security controls.
- Mature and expand New Balance's Application Security Program.
- Improve developer adoption of secure coding and application security practices.
- Reduce application security risk through proactive assessment and remediation.
- Increase automation capabilities through SOAR integrations and workflow development.
- Support cloud security initiatives within Azure and hybrid environments.
- Maintain and improve PCI DSS application security controls.
- Support annual PCI assessments, remediation efforts, and audit activities.
Requirements for Success
- 5+ years of Application Security, Software Security, Cloud Security, Security Engineering, or related experience.
- Experience integrating security controls into modern SDLC and DevSecOps environments.
- Experience building security automation and orchestration workflows.
- Experience securing cloud-native applications within Azure environments.
- Hands-on experience with: Python, JavaScript, .NET/C#, Azure, CI/CD technologies, Akamai, Salesforce Commerce Cloud, Atlassian Stack, and PKI technologies.
- Strong knowledge of: OWASP Top 10, OWASP ASVS, Threat Modeling, Secure SDLC, Application Security Testing, API Security, DevSecOps, Cloud Security, Container Security, Vulnerability Prioritization, PCI DSS 4.0.
- Bachelor of Science in Computer Science, Engineering, Information Technology, or related discipline, or equivalent experience.
- Relevant certifications and/or experience: CSSLP, CISSP, GWEBm GWAPT, AZ-500.
Requirements
Boston, MA Headquarters - (NB) Only Pay Range: $104,500.00 - $130,000.00 - $155,500.00 Annual (actual base pay varying based upon, but not limited to, relevant experience, time in role, internal equity, geographic location, and more.) Regular Associate Benefits Our products are only as good as the people we hire, so we make sure to hire the best and treat them accordingly. New Balance offers a comprehensive traditional benefits package including three options for medical insurance as well as dental, vision, life insurance and 401K. We also proudly offer a slate of more nontraditional perks – opportunities like online learning and development courses, tuition reimbursement, $100 monthly student loan support and various mentorship programs – that encourage our associates to grow personally as they develop professionally. You’ll also enjoy a yearly $1,000 lifestyle reimbursement, 4 weeks of vacations, 12 holidays and generous parental leave, because work-life balance is more than just a buzzword – it’s part of our culture. Temporary associates are provided three options for medical insurance as well as dental and vision insurance and an associate discount. Part time associates are provided 401k, short term disability, a yearly $300 lifestyle reimbursement and an associate discount. Flexible Work Schedule For decades we have fostered a unique culture founded on our values with a particular focus on in-person teamwork and collaboration. Our North American hybrid model encourages rich in-person experiences, showcasing our commitment to teamwork and connection, while maintaining flexibility for associates. New Balance Associates currently work in office three days per week (Tuesday, Wednesday, and Thursday). Our offices are fully open, and amenities are available across our North American office locations. To continue our focus on hybrid work we have introduced “Work from Anywhere” (WFA) for four weeks per calendar year. This model will help us enhance our culture while continuing to maintain elements of flexibility. Equal Opportunity Employer New Balance provides equal opportunities for all current and prospective associates to ensure that employment, training, compensation, transfer, promotion and other terms, conditions and privileges of employment are provided without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, age, handicap, genetic information and/or status as an Armed Forces service medal veteran, recently separated veteran, qualified disabled veteran or other protected veteran, or any other protected status.