New Balance Athletics, Inc.

Sr. Vulnerability Management & SOAR Engineer

New Balance Athletics, Inc.$104K — $155K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in Application Security, Software Security, Cloud Security or related fields.
  • Experience integrating security into SDLC and DevSecOps environments.
  • Proven skills in building automation workflows for security.
  • Hands-on experience with languages and technologies like Python, JavaScript, .NET/C#, and Azure.
  • Strong knowledge of security frameworks including OWASP Top 10 and PCI DSS 4.0.
  • Bachelor's degree in Computer Science, Engineering, or related field, or equivalent experience.
  • Relevant certifications such as CSSLP, CISSP, or AZ-500.

Responsibilities

  • Partner with development teams to implement secure design principles throughout the SDLC.
  • Conduct application security assessments for both internal and customer-facing applications.
  • Perform threat modeling and secure architecture reviews for cloud environments.
  • Provide guidance on remediation for application, API, and cloud security findings.
  • Establish application security policies, standards, and procedures.
  • Mentor teams on secure coding techniques and practices.
  • Collaborate with DevOps to integrate security controls into CI/CD pipelines.

Benefits

  • Comprehensive medical insurance options, including dental and vision coverage.
  • 401K plan with employer contributions.
  • Tuition reimbursement and online learning opportunities.
  • $1,000 yearly lifestyle reimbursement and four weeks of vacation.
  • Flexible hybrid work schedule with 'Work from Anywhere' for four weeks each year.
Full Job Description
This role is open to REMOTE work.

Job Mission
As a member of the Information Security Team, the Senior Vulnerability Management & SOAR Engineer will lead and mature the organization's enterprise Vulnerability Management Program, protecting applications, infrastructure, cloud services, endpoints, containers, and technology platforms from current and emerging threats. This role serves as the primary technical authority for vulnerability discovery, validation, prioritization, remediation coordination, exception management, and security automation.
The position partners closely with Infrastructure, Cloud Engineering, Application Development, DevOps, Architecture, Security Operations, and Technology teams to continuously reduce cyber risk through effective vulnerability lifecycle management and operational excellence. Drive accountability across technical teams, improve vulnerability remediation processes, and leverage automation and SOAR technologies to scale program effectiveness, reporting, and risk reduction efforts.
This individual contributor role requires both deep technical expertise and strong program ownership, balancing hands-on vulnerability operations with strategic leadership to continuously strengthen the organization's security posture.
Role Allocation: 90% Vulnerability Management | 10 % SOAR Engineering & Security
Note: Off-hour support and travel may be required.
Major Accountabilities
Vulnerability Management & Risk Reduction
• Own and continuously mature the enterprise Vulnerability Management Program across on-premises, cloud, containerized, endpoint, network, embedded, and application environments.
• Manage the end-to-end vulnerability lifecycle, including discovery, validation, prioritization, remediation tracking, exception management, verification, and reporting.
• Operate and optimize vulnerability assessment technologies to ensure comprehensive asset coverage and accurate risk visibility.
• Correlate and prioritize findings from vulnerability scanners, application security tools, cloud and container security platforms, attack surface management solutions, and threat intelligence sources.
• Apply risk-based methodologies leveraging CVSS, CISA KEV, exploitability, asset criticality, exposure, and business impact to identify and prioritize the most significant threats.
• Integrate vulnerability management processes with CI/CD pipelines and software delivery workflows to identify and address security weaknesses earlier in the development lifecycle.
• Partner with asset management teams to improve asset inventory accuracy, security coverage, and risk visibility across the enterprise.
Remediation Leadership & Governance
• Coordinate and drive remediation efforts across technical teams to ensure vulnerabilities are addressed within established service-level objectives and/or sensitivity.
• Lead response activities for critical vulnerabilities, zero-day threats, and actively exploited CVEs
• Manage vulnerability exceptions, compensating controls, risk acceptance processes, and periodic exception reviews.
• Develop and maintain vulnerability management policies, standards, procedures, runbooks, and reporting frameworks.
• Create executive and operational metrics measuring risk reduction, remediation, performance, vulnerability trends, asset coverage, SLA adherence, and MTTR.
• Support audits, compliance assessments, and risk management activities through accurate documentation and evidence collection.
• Monitor emerging threats, vulnerabilities, exploit trends, and industry best practices to continuously improve program effectiveness.
SOAR Engineering & Security Automation (10%)
• Design, develop, and maintain SOAR playbooks that automate vulnerability intake, triage, enrichment, ticket creation, remediation tracking, exception handling, and reporting.
• Develop integrations between vulnerability management platforms, SOAR, SIEM, ITSM, CMDB, DevOps, and collaboration platforms.
• Build scripts, APIs, and automated workflows using technologies such as Python, PowerShell, Bash, and REST APIs to improve operational efficiency and reduce manual effort.
• Measure automation effectiveness and recommend technology enhancements that strengthen vulnerability management and security operations capabilities.

Preferred Qualifications
• 5+ years of experience in Vulnerability Management, Security Operations, Security Engineering, Cybersecurity Risk Management, or related security disciplines.
• 3+ years of directly managing or owning enterprise vulnerability management programs in hybrid cloud and on-premises environments.
• Experience administering enterprise vulnerability management platforms such as Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent solutions.
• Strong expertise in vulnerability assessment, credentialed scanning, vulnerability validation, risk prioritization, and remediation management.
• Deep understanding of CVE, CVSS, CISA KEV, exploit intelligence, threat intelligence, attack surface management, and risk scoring methodologies.
• Experience with cloud platforms and cloud security technologies including Azure, AWS, or GCP.
• Experience managing vulnerabilities across cloud-native, containerized, and modern application environments.
• Scripting and automation experience using Python, PowerShell, Bash, REST APIs, or similar technologies.
• Experience building security automations using Microsoft Sentinel, Cortex XSOAR, Splunk SOAR, Swimlane, Tines, or similar platforms.
• Familiarity with application security concepts
• Experience developing metrics, KPIs, dashboards, remediation SLAs, and executive reporting for vulnerability management programs.
• Strong understanding of operating systems, network infrastructure, software development processes, and enterprise technology environments.
• Experience supporting compliance frameworks such as NIST, CIS, ISO 27001, SOC 2, PCI-DSS, CMMC, or similar regulatory requirements is preferred.
• Excellent communication and stakeholder management skills with the ability to influence both technical and business audiences.
• Industry certifications such as CISSP, CySA+, Security+, GSEC, GCSA, OSCP, GIAC certifications, or equivalent experience are preferred.

Boston, MA Headquarters - (NB) Only Pay Range: $104,500.00 - $130,000.00 - $155,500.00 Annual (actual base pay varying based upon, but not limited to, relevant experience, time in role, internal equity, geographic location, and more.)

Regular Associate Benefits

Our products are only as good as the people we hire, so we make sure to hire the best and treat them accordingly. New Balance offers a comprehensive traditional benefits package including three options for medical insurance as well as dental, vision, life insurance and 401K. We also proudly offer a slate of more nontraditional perks - opportunities like online learning and development courses, tuition reimbursement, $100 monthly student loan support and various mentorship programs - that encourage our associates to grow personally as they develop professionally. You'll also enjoy a yearly $1,000 lifestyle reimbursement, 4 weeks of vacations, 12 holidays and generous parental leave, because work-life balance is more than just a buzzword - it's part of our culture.

Temporary associates are provided three options for medical insurance as well as dental and vision insurance and an associate discount.

Part time associates are provided 401k, short term disability, a yearly $300 lifestyle reimbursement and an associate discount.

Flexible Work Schedule

For decades we have fostered a unique culture founded on our values with a particular focus on in-person teamwork and collaboration. Our North American hybrid model encourages rich in-person experiences, showcasing our commitment to teamwork and connection, while maintaining flexibility for associates. New Balance Associates currently work in office three days per week (Tuesday, Wednesday, and Thursday). Our offices are fully open, and amenities are available across our North American office locations. To continue our focus on hybrid work we have introduced "Work from Anywhere" (WFA) for four weeks per calendar year. This model will help us enhance our culture while continuing to maintain elements of flexibility.

About New Balance Athletics, Inc.

New Balance Athletics, Inc. is a footwear company that specializes in athletic shoes and apparel. The company was founded in 1906 by William J. Riley and has since grown to become one of the largest athletic shoe manufacturers in the world. New Balance is known for its focus on quality and innovation, and has been recognized for its commitment to domestic manufacturing. The company operates five factories in the United States and has a reputation for producing high-quality, durable shoes. New Balance offers a wide range of products, including running shoes, walking shoes, and lifestyle shoes, as well as apparel and accessories. The company is committed to sustainability and has implemented a number of initiatives to reduce its environmental impact.
Learn more about New Balance Athletics, Inc.
Size
8,000 employees
Industry

Similar Jobs

More Jobs at New Balance Athletics, Inc.

More Information Technology Jobs

Find similar Sr. Vulnerability Management & SOAR Engineer jobs: