Senior Staff DevSecOps EngineerInformation Technology * Somerville, MA * Full time * On-site
Listed on 2026-08-03
-
IT/Tech
Cybersecurity, Systems Engineer
Are you ready to build America's energy future? Form Energy is an American manufacturing and energy technology company. We're revolutionizing energy storage with cost-effective, multi-day technology designed to keep the electric grid secure and reliable, even during extended periods of stress. By strengthening the electric system and reimagining what's possible, we're giving clean energy a whole new form!
In recent years, Form Energy has earned a number of accolades, including being named by TIME as a 'Best Invention', MIT Technology Review as a 'Top Climate Tech Company To Watch', and Fast Company as 'One of the Next Big Things In Tech'. We are making rapid progress on our mission of delivering energy storage for a better world, and our team is growing just as rapidly to meet demand.
We have signed contracts with leading electric utilities across the United States and production of our iron-air batteries is underway at our first high-volume manufacturing facility in West Virginia.
Working for Form Energy is more than just a job, it's a chance to be part of something extraordinary. And now - right as we significantly scale up battery manufacturing - might be the most exciting moment in the company's history to join. We are assembling a team of highly talented and driven individuals across the country. Driven by our core values of humanity, excellence, and creativity, our team is determined to deliver on our mission and transform the energy landscape for the better.
Feeling energized to make a meaningful impact on the world? Then keep reading - you've come to the right place.
Role DescriptionForm Energy is scaling quickly across research, engineering, and manufacturing, and the integrations, automations, and AI-enabled tools that connect our systems need to be built securely from the start. As Senior Staff Dev Sec Ops Engineer on the IT Engineering & Platforms team, you will define and lead how the team embeds security into the design, build, and operation of integrations, ETL/data pipelines, automations, and custom-built tools - including MCP servers and other AI-agent tooling.
You will set secure-development standards for the team, work hands-on building and configuring systems yourself, and serve as the senior technical voice on security for everything the team ships.
Relocation assistance is available.
What you'll do:- Define and lead secure-SDLC practices for integrations, automations, ETL/data pipelines, and custom-built tools - including secure design review, dependency and secrets scanning, and secure coding standards - and mentor other engineers on their application.
- Own application-layer security strategy for the team's deliverables: static and dynamic analysis (SAST/DAST), dependency and supply-chain vulnerability management, and secrets detection across the codebase and CI/CD pipelines.
- Set the architecture and guardrails for securing AI and agentic tooling specifically - credential scoping and least-privilege access for MCP servers and AI integrations, safe handling of data passed to and from LLM-based tools, and defenses against prompt-injection and data-exfiltration risk in custom AI workflows.
- Harden CI/CD pipelines - least-privilege service accounts, secrets management, signed or verified artifacts, and gated deployments - and establish standards other engineers build against.
- Build and configure integrations, automations, and tooling alongside the Dev Ops team as needed, modeling the secure-development practices you define.
- Build security observability into what the team ships: audit logging, anomaly alerting, and incident-relevant telemetry for integrations and automations.
- Own a risk-based inventory of the team's integrations, automations, and custom tools, with documented data flows and access scopes.
- Serve as the senior technical security liaison between IT Engineering & Platforms and the Information Security & GRC vertical - informing policy and control design with implementation-level context.
- Lead response for security-related incidents in integrations and automations, and own the related incident response runbooks.
- 9+ years in application security, Dev Sec Ops , or security engineering, including experience building or supporting integrations, automations, or data pipelines in an enterprise IT environment.
- Demonstrated experience setting secure-development standards and mentoring other engineers, not just applying existing standards.
- Strong scripting and programming skills (e.g., Python, JavaScript / Type Script, or Power Shell) and hands-on experience with REST APIs and JSON.
- Deep, hands-on experience with SAST/DAST tooling, dependency and software composition analysis (SCA), and secrets-management practices.
- Strong command of cloud and identity security fundamentals - least-privilege IAM design, SSO (SAML / OIDC), and secrets/credential management.
- Experience securing CI/CD pipelines end to end and familiarity with version control (Git) and modern deployment practices.
- A pragmatic,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).