Senior Staff DevSecOps Engineer
Form Energy · Somerville, MA · Today
On-siteEngineering$170k–$213k/yrFull-time
Role Description
Form Energy is scaling quickly across research, engineering, and manufacturing, and the integrations, automations, and AI-enabled tools that connect our systems need to be built securely from the start. As Senior Staff DevSecOps Engineer on the IT Engineering & Platforms team, you will define and lead how the team embeds security into the design, build, and operation of integrations, ETL/data pipelines, automations, and custom-built tools — including MCP servers and other AI-agent tooling. You will set secure-development standards for the team, work hands-on building and configuring systems yourself, and serve as the senior technical voice on security for everything the team ships.
What You'll Do
- Define and lead secure-SDLC practices for integrations, automations, ETL/data pipelines, and custom-built tools — including secure design review, dependency and secrets scanning, and secure coding standards — and mentor other engineers on their application.
- Own application-layer security strategy for the team’s deliverables: static and dynamic analysis (SAST/DAST), dependency and supply-chain vulnerability management, and secrets detection across the codebase and CI/CD pipelines.
- Set the architecture and guardrails for securing AI and agentic tooling specifically — credential scoping and least-privilege access for MCP servers and AI integrations, safe handling of data passed to and from LLM-based tools, and defenses against prompt-injection and data-exfiltration risk in custom AI workflows.
- Harden CI/CD pipelines — least-privilege service accounts, secrets management, signed or verified artifacts, and gated deployments — and establish standards other engineers build against.
- Build and configure integrations, automations, and tooling alongside the DevOps team as needed, modeling the secure-development practices you define.
- Build security observability into what the team ships: audit logging, anomaly alerting, and incident-relevant telemetry for integrations and automations.
- Own a risk-based inventory of the team’s integrations, automations, and custom tools, with documented data flows and access scopes.
- Serve as the senior technical security liaison between IT Engineering & Platforms and the Information Security & GRC vertical — informing policy and control design with implementation-level context.
- Lead response for security-related incidents in integrations and automations, and own the related incident response runbooks.
What You'll Bring
- 9+ years in application security, DevSecOps, or security engineering, including experience building or supporting integrations, automations, or data pipelines in an enterprise IT environment.
- Demonstrated experience setting secure-development standards and mentoring other engineers, not just applying existing standards.
- Strong scripting and programming skills (e.g., Python, JavaScript / TypeScript, or PowerShell) and hands-on experience with REST APIs and JSON.
- Deep, hands-on experience with SAST/DAST tooling, dependency and software composition analysis (SCA), and secrets-management practices.
- Strong command of cloud and identity security fundamentals — least-privilege IAM design, SSO (SAML / OIDC), and secrets/credential management.
- Experience securing CI/CD pipelines end to end and familiarity with version control (Git) and modern deployment practices.
- A pragmatic, detail-oriented approach to building reliable, secure systems in a fast-paced environment, and comfort operating as a peer to both engineering leadership and security/compliance stakeholders.
Preferred Qualifications
- Experience securing AI/LLM-based tooling or agentic systems, including MCP servers, AI integrations, or similar emerging architectures.
- Experience with iPaaS / integration platforms (e.g., Workato, Boomi, MuleSoft, Zapier) or custom-built integrations.
- Familiarity with compliance frameworks relevant to a SOX or audit-controlled environment (e.g., segregation of duties, change management, access review).
- Experience with cloud platforms (Microsoft Azure preferred, Google Cloud, or AWS) and infrastructure-as-code or configuration-management tooling.
- Experience in a manufacturing, hardware, laboratory, or high-growth technology environment.