Skip to content

Senior Staff DevSecOps Engineer

Form Energy, IncSomerville, MA, USJuly 30, 2026
On-site
Full-time
DevSecOps
Staff · 9+ yrs

Are you ready to build America’s energy future? Form Energy is an American manufacturing and energy technology company. We’re revolutionizing energy storage with cost-effective, multi-day technology designed to keep the electric grid secure and reliable, even during extended periods of stress. By strengthening the electric system and reimagining what’s possible, we’re giving clean energy a whole new form! 

In recent years, Form Energy has earned a number of accolades, including being named by TIME as a “Best Invention”, MIT Technology Review as a “Top Climate Tech Company To Watch”, and Fast Company as “One of the Next Big Things In Tech”. We are making rapid progress on our mission of delivering energy storage for a better world, and our team is growing just as rapidly to meet demand. We have signed contracts with leading electric utilities across the United States and production of our iron-air batteries is underway at our first high-volume manufacturing facility in West Virginia.

Working for Form Energy is more than just a job, it’s a chance to be part of something extraordinary. And now - right as we significantly scale up battery manufacturing -  might be the most exciting moment in the company’s history to join. We are assembling a team of highly talented and driven individuals across the country. Driven by our core values of humanity, excellence, and creativity, our team is determined to deliver on our mission and transform the energy landscape for the better.

Feeling energized to make a meaningful impact on the world? Then keep reading - you’ve come to the right place.

Role Description

Form Energy is scaling quickly across research, engineering, and manufacturing, and the integrations, automations, and AI-enabled tools that connect our systems need to be built securely from the start. As Senior Staff DevSecOps Engineer on the IT Engineering & Platforms team, you will define and lead how the team embeds security into the design, build, and operation of integrations, ETL/data pipelines, automations, and custom-built tools — including MCP servers and other AI-agent tooling. You will set secure-development standards for the team, work hands-on building and configuring systems yourself, and serve as the senior technical voice on security for everything the team ships.

Relocation assistance is available.

What you'll do:

  • Define and lead secure-SDLC practices for integrations, automations, ETL/data pipelines, and custom-built tools — including secure design review, dependency and secrets scanning, and secure coding standards — and mentor other engineers on their application.

  • Own application-layer security strategy for the team’s deliverables: static and dynamic analysis (SAST/DAST), dependency and supply-chain vulnerability management, and secrets detection across the codebase and CI/CD pipelines.

  • Set the architecture and guardrails for securing AI and agentic tooling specifically — credential scoping and least-privilege access for MCP servers and AI integrations, safe handling of data passed to and from LLM-based tools, and defenses against prompt-injection and data-exfiltration risk in custom AI workflows.

  • Harden CI/CD pipelines — least-privilege service accounts, secrets management, signed or verified artifacts, and gated deployments — and establish standards other engineers build against.

  • Build and configure integrations, automations, and tooling alongside the DevOps team as needed, modeling the secure-development practices you define.

  • Build security observability into what the team ships: audit logging, anomaly alerting, and incident-relevant telemetry for integrations and automations.

  • Own a risk-based inventory of the team’s integrations, automations, and custom tools, with documented data flows and access scopes.

  • Serve as the senior technical security liaison between IT Engineering & Platforms and the Information Security & GRC vertical — informing policy and control design with implementation-level context.

  • Lead response for security-related incidents in integrations and automations, and own the related incident response runbooks.

What you'll bring:

  • 9+ years in application security, DevSecOps, or security engineering, including experience building or supporting integrations, automations, or data pipelines in an enterprise IT environment.

  • Demonstrated experience setting secure-development standards and mentoring other engineers, not just applying existing standards.

  • Strong scripting and programming skills (e.g., Python, JavaScript / TypeScript, or PowerShell) and hands-on experience with REST APIs and JSON.

  • Deep, hands-on experience with SAST/DAST tooling, dependency and software composition analysis (SCA), and secrets-management practices.

  • Strong command of cloud and identity security fundamentals — least-privilege IAM design, SSO (SAML / OIDC), and secrets/credential management.

  • Experience securing CI/CD pipelines end to end and familiarity with version control (Git) and modern deployment practices.

  • A pragmatic, detail-oriented approach to building reliable, secure systems in a fast-paced environment, and comfort operating as a peer to both engineering leadership and security/compliance stakeholders.

Preferred Qualifications:

  • Experience securing AI/LLM-based tooling or agentic systems, including MCP servers, AI integrations, or similar emerging architectures.

  • Experience with iPaaS / integration platforms (e.g., Workato, Boomi, MuleSoft, Zapier) or custom-built integrations.

  • Familiarity with compliance frameworks relevant to a SOX or audit-controlled environment (e.g., segregation of duties, change management, access review).

  • Experience with cloud platforms (Microsoft Azure preferred, Google Cloud, or AWS) and infrastructure-as-code or configuration-management tooling.

  • Experience in a manufacturing, hardware, laboratory, or high-growth technology environment.

#LI-Onsite

Humanity is a cornerstone of Form Energy’s culture, and we make sure our compensation and benefits reflect that. Form Energy offers competitive salaries, stock options, and a holistic benefits package to ensure all employees have what they need to thrive while working here. 

When it comes to you and your family’s health, we cover 100% of medical, dental, and vision premiums for full-time employees - and 80% of healthcare premiums for dependents. This starts from day one. We also offer at least 12 weeks of paid leave for new parents (up to 20 weeks for birthing parents), and generous vacation policies to give employees time to recharge when needed. 

To build America’s energy future, we need everyone at the table. We are proud to be an equal opportunity employer, and encourage candidates from all backgrounds to apply to our open jobs.

If you may require reasonable accommodations to participate in our interview process, please contact [email protected]. Requests for accommodations will be treated with discretion.

Form Energy is committed to maintaining the privacy of our applicants. Please be aware that we will never solicit sensitive personal information such as Social Security numbers or bank account details during the recruiting or hiring process.

Job Details

Salary

$170,246 – $212,813/yr

Experience

Staff · 9+ yrs

Tools & Tech

AWS
Azure
GCP
Git
JavaScript
PowerShell
Python
TypeScript