> Markdown version of [/jobs/ext/1449952-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1449952-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** New Balance Athletics, Inc. - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $104,500.0 - $130,000.0 - **Contract:** Temporary contract - **Skills:** Kubernetes Security, JavaScript (Programming Language), .NET Framework, Application Programming Interfaces (APIs), User Authentication, Microsoft Azure, C Sharp (Programming Language), Cloud Computing, Cloud Computing Security, Cyber Security, DevOps, Issue Tracking Systems, Information Systems Security Architecture Professional, Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Public Key Infrastructure, Systems Development Life Cycle, Akamai, Secure Coding, Software Engineering, Software Vulnerability Management, Data Logging, Spring Cloud, Software Security, GWAPT, Information Technology, Atlassian Tools, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 26, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17700154?backUrl=%2Fcareer%2F17700154%2FSenior-Application-Security-Engineer-Massachusetts-Brighton ## About the Role * 5+ years of Application Security, Software Security, Cloud Security, Security Engineering, or related experience. * Experience integrating security controls into modern SDLC and DevSecOps environments. * Experience building security automation and orchestration workflows. * Experience securing cloud-native applications within Azure environments. * Hands-on experience with: Python, JavaScript, .NET/C#, Azure, CI/CD technologies, Akamai, Salesforce Commerce Cloud, Atlassian Stack, and PKI technologies. * Strong knowledge of: OWASP Top 10, OWASP ASVS, Threat Modeling, Secure SDLC, Application Security Testing, API Security, DevSecOps, Cloud Security, Container Security, Vulnerability Prioritization, PCI DSS 4.0 * Bachelor of Science in Computer Science, Engineering, Information Technology, or related discipline, or equivalent experience. * Relevant certifications and/or experience: CSSLP, CISSP, GWEBm GWAPT, AZ-500. ## Description As a member of the New Balance Information Security Team, the Senior Application Security Engineer will be responsible for protecting New Balance applications, APIs, cloud-native services, and software development platforms from current and emerging security threats. This role serves as the primary Application Security Engineering resource partnering with development, cloud, architecture, infrastructure, and vulnerability management teams to embed security throughout the Software Development Lifecycle (SDLC). The position will work closely with the Principal Application Security Engineer to mature New Balance's Application Security Program while driving automation and operational efficiencies through Security Orchestration, Automation and Response (SOAR) technologies. This role is designed as approximately: 70% Application Security and 30% Vulnerability Management Engineering & Automation The successful candidate will help establish secure development practices, support PCI DSS compliance initiatives, improve developer enablement, and create automated workflows that reduce risk and accelerate remediation across the enterprise., Application Security * Partner with development teams to implement secure-by-design principles throughout the SDLC. * Conduct application security assessments for internally developed and customer-facing applications. * Perform threat modeling and secure architecture reviews for cloud and hybrid environments. * Review application, API, and cloud security findings and provide remediation guidance. * Establish and maintain application security policies, standards, and procedures. * Mentor developers and technical teams on secure development practices and secure coding techniques. * Collaborate with DevOps teams to integrate security controls into CI/CD pipelines. * Support implementation, administration, and optimization of: SAST, SCA, DAST, API Security, Container Security, CNAPP/CSPM/CWPP solutions, WAF technologies, PKI services, and automated attack protections. Security Automation & SOAR * Lead development and implementation of SOAR workflows supporting Application Security and Vulnerability Management functions. * Design automated processes for: vulnerability intake, risk prioritization, ticket creation, ownership assignment, remediation tracking, SLA monitoring, compliance reporting. * Integrate security tools, cloud platforms, CI/CD pipelines, and ticketing systems into automated workflows. * Develop scripts and automation using APIs and modern automation frameworks. Vulnerability Management Support * Support risk-based vulnerability prioritization activities. * Review application and cloud vulnerabilities requiring advanced technical analysis. * Partner with Vulnerability Management personnel to improve remediation effectiveness. * Identify automation opportunities that streamline vulnerability lifecycle management processes. PCI Compliance Support * Support PCI DSS compliance activities related to application security and secure software development. * Perform PCI-focused application security reviews and validation activities. * Assist with collection of evidence and documentation for PCI assessments and audits. * Support secure coding, segmentation, authentication, logging, and vulnerability management requirements within PCI-scoped environments. * Partner with compliance and audit teams to maintain PCI DSS application security controls. * Mature and expand New Balance's Application Security Program. * Improve developer adoption of secure coding and application security practices. * Reduce application security risk through proactive assessment and remediation. * Increase automation capabilities through SOAR integrations and workflow development. * Support cloud security initiatives within Azure and hybrid environments. * Maintain and improve PCI DSS application security controls. * Support annual PCI assessments, remediation efforts, and audit activities. ## Related Videos - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)