ForgeApply
Try it free

ForgeApply · Job listing

Sr. Vulnerability Management & SOAR Engineer

New Balance

Boston, MA Headquarters - (NB) | Lawrence, US$105k – $130konsite

See all 185 open roles at New Balance

Tailor your resume for this New Balance job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for New Balance's site. Free trial, no card required.

About this role

Who We Are:   Since 1906, New Balance has empowered people through sport and craftsmanship to create positive change in communities around the world. We innovate fearlessly, guided by our core values and driven by the belief that conventions were meant to be challenged. We foster a culture in which every associate feels welcomed and respected, where leaders and creatives are inspired to shape the world of tomorrow by taking bold action today.

This role is open to REMOTE work.

Job Mission As a member of the Information Security Team, the Senior Vulnerability Management & SOAR Engineer will lead and mature the organization's enterprise Vulnerability Management Program, protecting applications, infrastructure, cloud services, endpoints, containers, and technology platforms from current and emerging threats. This role serves as the primary technical authority for vulnerability discovery, validation, prioritization, remediation coordination, exception management, and security automation. The position partners closely with Infrastructure, Cloud Engineering, Application Development, DevOps, Architecture, Security Operations, and Technology teams to continuously reduce cyber risk through effective vulnerability lifecycle management and operational excellence. Drive accountability across technical teams, improve vulnerability remediation processes, and leverage automation and SOAR technologies to scale program effectiveness, reporting, and risk reduction efforts. This individual contributor role requires both deep technical expertise and strong program ownership, balancing hands-on vulnerability operations with strategic leadership to continuously strengthen the organization's security posture. Role Allocation: 90% Vulnerability Management | 10 % SOAR Engineering & Security Note: Off-hour support and travel may be required. Major Accountabilities Vulnerability Management & Risk Reduction • Own and continuously mature the enterprise Vulnerability Management Program across on-premises, cloud, containerized, endpoint, network, embedded, and application environments. • Manage the end-to-end vulnerability lifecycle, including discovery, validation, prioritization, remediation tracking, exception management, verification, and reporting. • Operate and optimize vulnerability assessment technologies to ensure comprehensive asset coverage and accurate risk visibility. • Correlate and prioritize findings from vulnerability scanners, application security tools, cloud and container security platforms, attack surface management solutions, and threat intelligence sources. • Apply risk-based methodologies leveraging CVSS, CISA KEV, exploitability, asset criticality, exposure, and business impact to identify and prioritize the most significant threats. • Integrate vulnerability management processes with CI/CD pipelines and software delivery workflows to identify and address security weaknesses earlier in the development lifecycle. • Partner with asset management teams to improve asset inventory accuracy, security coverage, and risk visibility across the enterprise. Remediation Leadership & Governance • Coordinate and drive remediation efforts across technical teams to ensure vulnerabilities are addressed within established service-level objectives and/or sensitivity. • Lead response activities for critical vulnerabilities, zero-day threats, and actively exploited CVEs • Manage vulnerability exceptions, compensating controls, risk acceptance processes, and periodic exception reviews. • Develop and maintain vulnerability management policies, standards, procedures, runbooks, and reporting frameworks. • Create executive and operational metrics measuring risk reduction, remediation, performance, vulnerability trends, asset coverage, SLA adherence, and MTTR. • Support audits, compliance assessments, and risk management activities through accurate documentation and evidence collection. • Monitor emerging threats, vulnerabilities, exploit trends, and industry best practices to continuously improve program effectiveness. SOAR Engineering & Security Automation (10%) • Design, develop, and maintain SOAR playbooks that automate vulnerability intake, triage, enrichment, ticket creation, remediation tracking, exception handling, and reporting. • Develop integrations between vulnerability management platforms, SOAR, SIEM, ITSM, CMDB, DevOps, and collaboration platforms. • Build scripts, APIs, and automated workflows using technologies such as Python, PowerShell, Bash, and REST APIs to improve operational efficiency and reduce manual effort. • Measure automation effectiveness and recommend technology enhancements that strengthen vulnerability management and security operations capabilities.

Preferred Qualifications • 5+ years of experience in Vulnerability Management, Security Operations, Security Engineering, Cybersecurity Risk Management, or related security disciplines. • 3+ years of directly managing or owning enterprise vulnerability management programs in hybrid cloud and on-premises environments. • Experience administering enterprise vulnerability management platforms such as Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent solutions. • Strong expertise in vulnerability assessment, credentialed scanning, vulnerability validation, risk prioritization, and remediation management. • Deep understanding of CVE, CVSS, CISA KEV, exploit intelligence, threat intelligence, attack surface management, and risk scoring methodologies. • Experience with cloud platforms and cloud security technologies including Azure, AWS, or GCP. • Experience managing vulnerabilities across cloud-native, containerized, and modern application environments. • Scripting and automation experience using Python, PowerShell, Bash, REST APIs, or similar technologies. • Experience building security automations using Microsoft Sentinel, Cortex XSOAR, Splunk SOAR, Swimlane, Tines, or similar platforms. • Familiarity with appl

Salary insight

The midpoint of this range ($117k) is about 25% below the median disclosed salary for Boston roles listed on ForgeApply ($156k across 2,197 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this New Balance role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)