Senior Application Security Engineer

New BalanceBoston, MA
Hybrid

About The Position

As a member of the New Balance Information Security Team, the Senior Application Security Engineer will be responsible for protecting New Balance applications, APIs, cloud-native services, and software development platforms from current and emerging security threats. This role serves as the primary Application Security Engineering resource partnering with development, cloud, architecture, infrastructure, and vulnerability management teams to embed security throughout the Software Development Lifecycle (SDLC). The position will work closely with the Principal Application Security Engineer to mature New Balance's Application Security Program while driving automation and operational efficiencies through Security Orchestration, Automation and Response (SOAR) technologies. This role is designed as approximately: 70% Application Security and 30% Vulnerability Management Engineering & Automation The successful candidate will help establish secure development practices, support PCI DSS compliance initiatives, improve developer enablement, and create automated workflows that reduce risk and accelerate remediation across the enterprise.

Requirements

  • 5+ years of Application Security, Software Security, Cloud Security, Security Engineering, or related experience.
  • Experience integrating security controls into modern SDLC and DevSecOps environments.
  • Experience building security automation and orchestration workflows.
  • Experience securing cloud-native applications within Azure environments.
  • Hands-on experience with: Python, JavaScript, .NET/C#, Azure, CI/CD technologies, Akamai, Salesforce Commerce Cloud, Atlassian Stack, and PKI technologies.
  • Strong knowledge of: OWASP Top 10, OWASP ASVS, Threat Modeling, Secure SDLC, Application Security Testing, API Security, DevSecOps, Cloud Security, Container Security, Vulnerability Prioritization, PCI DSS 4.0
  • Bachelor of Science in Computer Science, Engineering, Information Technology, or related discipline, or equivalent experience.
  • Relevant certifications and/or experience: CSSLP, CISSP, GWEBm GWAPT, AZ-500.

Responsibilities

  • Partner with development teams to implement secure-by-design principles throughout the SDLC.
  • Conduct application security assessments for internally developed and customer-facing applications.
  • Perform threat modeling and secure architecture reviews for cloud and hybrid environments.
  • Review application, API, and cloud security findings and provide remediation guidance.
  • Establish and maintain application security policies, standards, and procedures.
  • Mentor developers and technical teams on secure development practices and secure coding techniques.
  • Collaborate with DevOps teams to integrate security controls into CI/CD pipelines.
  • Support implementation, administration, and optimization of: SAST, SCA, DAST, API Security, Container Security, CNAPP/CSPM/CWPP solutions, WAF technologies, PKI services, and automated attack protections.
  • Lead development and implementation of SOAR workflows supporting Application Security and Vulnerability Management functions.
  • Design automated processes for: vulnerability intake, risk prioritization, ticket creation, ownership assignment, remediation tracking, SLA monitoring, compliance reporting.
  • Integrate security tools, cloud platforms, CI/CD pipelines, and ticketing systems into automated workflows.
  • Develop scripts and automation using APIs and modern automation frameworks.
  • Support risk-based vulnerability prioritization activities.
  • Review application and cloud vulnerabilities requiring advanced technical analysis.
  • Partner with Vulnerability Management personnel to improve remediation effectiveness.
  • Identify automation opportunities that streamline vulnerability lifecycle management processes.
  • Support PCI DSS compliance activities related to application security and secure software development.
  • Perform PCI-focused application security reviews and validation activities.
  • Assist with collection of evidence and documentation for PCI assessments and audits.
  • Support secure coding, segmentation, authentication, logging, and vulnerability management requirements within PCI-scoped environments.
  • Partner with compliance and audit teams to maintain PCI DSS application security controls.
  • Mature and expand New Balance's Application Security Program.
  • Improve developer adoption of secure coding and application security practices.
  • Reduce application security risk through proactive assessment and remediation.
  • Increase automation capabilities through SOAR integrations and workflow development.
  • Support cloud security initiatives within Azure and hybrid environments.
  • Maintain and improve PCI DSS application security controls.
  • Support annual PCI assessments, remediation efforts, and audit activities.

Benefits

  • Three options for medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • 401K
  • Online learning and development courses
  • Tuition reimbursement
  • $100 monthly student loan support
  • Various mentorship programs
  • Yearly $1,000 lifestyle reimbursement
  • 4 weeks of vacations
  • 12 holidays
  • Generous parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service