×
Register Here to Apply for Jobs or Post Jobs. X

Senior Dev SecOps Engineer

Job in Saint Paul, Ramsey County, Minnesota, 55199, USA
Listing for: NextEra Energy Resources
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 110000 - 164000 USD Yearly USD 110000.00 164000.00 YEAR
Job Description & How to Apply Below

Select how often (in days) to receive an alert:

Date: Aug 25, 2026

Location(s): St. Paul, MN, US, 55107

Company: Next Era Energy

Requisition : 97058

Next Era Analytics offers energy consulting services using industry-leading scientific analysis for planning, siting, forecasting and optimizing all forms of energy projects. Our optimization and analytics platforms integrate open-source technologies to leverage massive, diverse sets of utility operating data. This enables rapid development of operational solutions. Applying expertise in advanced mathematics, data and physical sciences, we solve some of the hardest problems facing the energy industry.

Position Specific Description

We are seeking a high-caliber Senior Dev Sec Ops  Engineer to embed security throughout the software development lifecycle and strengthen the security of our cloud platforms, development pipelines, and software supply chain. This role is designed for an experienced security engineer who combines deep technical expertise with a strong understanding of modern software engineering and developer workflows.

You will partner closely with software engineering, cloud, platform, cybersecurity, and governance teams to build scalable security controls that reduce risk without creating unnecessary friction. You will operate with a high degree of autonomy, establishing secure-by-default patterns, influencing system design, and implementing measurable controls across traditional and AI-assisted development environments.

1. Secure Software Delivery
  • Secure CI/CD Pipelines: Build and maintain secure CI/CD pipelines with automated security gates, including static application security testing, software composition analysis, dynamic application security testing, secret scanning, infrastructure-as-code scanning, and container or image scanning.
  • Risk-Based Security Controls: Configure and tune security tooling using exploitability and reachability-based prioritization to minimize false positives and reduce unnecessary developer friction.
  • Secure Design Influence: Lead threat modeling, security design reviews, and the adoption of secure architecture patterns early in the development lifecycle.
  • Root-Cause Remediation: Promote architectural and systemic security improvements that prevent recurring issues rather than relying on short-term or symptom-based fixes.
  • Developer Guardrails: Develop reusable pipeline templates, hardened base images, security guardrails, and secure-by-default development patterns that shift security left without slowing delivery.
  • AI-Assisted Development Security: Establish security standards and governance for AI coding assistants, agentic development tools, and AI-generated code.
  • Agentic Security Controls: Implement least-agency permission models, human review requirements, code provenance standards, and controls governing autonomous agent access to tools, data, and environments.
  • Secure Tool Integration: Evaluate and secure agent tool integrations, including Model Context Protocol integrations, while ensuring appropriate authentication, authorization, isolation, and oversight.
3. Cloud, Platform & Software Supply Chain Security
  • Cloud Security Controls: Implement identity and access management, least-privilege access, network boundaries, centralized logging, and secure configuration standards across AWS and GCP environments.
  • Software Supply Chain Security: Establish software and AI bills of materials, dependency governance, artifact signing, and software provenance aligned with frameworks such as SLSA.
  • Pipeline Hardening: Protect the software delivery pipeline through OIDC-based publishing, ephemerl runners, controlled network egress, secure secrets management, and hardened build environments.
  • Infrastructure- and Policy-as-Code: Implement infrastructure-as-code and policy-as-code controls that provide consistent enforcement, immutable logging, and automated evidence generation.
4. Vulnerability Management & Risk Reduction
  • Vulnerability Ownership: Lead vulnerability triage, exploitability-informed risk ranking, remediation service-level objectives, exception management, and recurrence prevention.
  • Security Metrics: Define and track meaningful measures such as mean time to remediate, scan coverage, policy compliance, vulnerability recurrence, and developer adoption of security guardrails.
  • Continuous Improvement: Use security findings, operational data, and engineering feedback to continuously improve tooling, processes, and preventative controls.
  • Measurable Outcomes: Demonstrate risk reduction over time through clear reporting, actionable metrics, and transparent communication with technical and business stakeholders.
5. Cybersecurity, Risk & Compliance Partnership
  • Cross-Functional Partnership: Collaborate with application security, engineering, cloud, platform, cybersecurity, risk, and compliance teams to integrate security into technical delivery.
  • Automated Security Evidence: Feed pipeline evidence, security findings, software inventories, and control results into…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary