Skip to content
← Back to job listings

Senior Staff DevSecOps Engineer

Form Energy · Somerville, United States

External listingfull-time2 days ago

About The Role

Join Form Energy, a rapidly growing company in the energy sector. As a Senior Staff DevSecOps Engineer, you will lead the integration of security into the design, build, and operation of various systems. You will set secure-development standards, own the application-layer security strategy, and build security observability into the team's deliverables. Additionally, you will serve as the senior technical security liaison and lead response for security-related incidents. Enjoy a comprehensive benefits package, including health insurance, generous PTO, and stock options.

  • Definir y liderar cómo el equipo incorpora la seguridad en el diseño, construcción y operación de integraciones, automatizaciones, tuberías de ETL/datos y herramientas personalizadas.
  • Establecer estándares de desarrollo seguro para el equipo, trabajar de manera práctica en la construcción y configuración de sistemas, y servir como la voz técnica senior en seguridad.
  • Definir y liderar las prácticas de SDLC seguro para integraciones, automatizaciones, tuberías de ETL/datos y herramientas personalizadas, y mentorear a otros ingenieros en su aplicación.
  • Strong scripting and programming skills (e.g., Python, JavaScript / TypeScript, or PowerShell) and hands-on experience with REST APIs and JSON
  • Strong command of cloud and identity security fundamentals — least-privilege IAM design, SSO (SAML / OIDC), and secrets/credential management
  • Experience securing CI/CD pipelines end to end and familiarity with version control (Git) and modern deployment practices
  • A pragmatic, detail-oriented approach to building reliable, secure systems in a fast-paced environment, and comfort operating as a peer to both engineering leadership and security/compliance stakeholders
  • Demonstrated experience setting secure-development standards and mentoring other engineers, not just applying existing standards
  • Deep, hands-on experience with SAST/DAST tooling, dependency and software composition analysis (SCA), and secrets-management practices
  • 9+ years in application security, DevSecOps, or security engineering, including experience building or supporting integrations, automations, or data pipelines in an enterprise IT environment
  • Experience securing AI/LLM-based tooling or agentic systems, including MCP servers, AI integrations, or similar emerging architectures
  • Familiarity with compliance frameworks relevant to a SOX or audit-controlled environment (e.g., segregation of duties, change management, access review)
  • Experience with iPaaS / integration platforms (e.g., Workato, Boomi, MuleSoft, Zapier) or custom-built integrations
  • Experience with cloud platforms (Microsoft Azure preferred, Google Cloud, or AWS) and infrastructure-as-code or configuration-management tooling
  • Experience in a manufacturing, hardware, laboratory, or high-growth technology environment

This is an external listing. JobSpring does not represent or verify the employer. Report this listing