> Markdown version of [/jobs/ext/1843473-senior-staff-devsecops-engineerinformation-technology-somerville-ma-full-time-on-site](https://www.wearedevelopers.com/jobs/ext/1843473-senior-staff-devsecops-engineerinformation-technology-somerville-ma-full-time-on-site). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Staff DevSecOps EngineerInformation Technology * Somerville, MA * Full time * On-site - **Company:** Form Energy - **Location:** Somerville, MA, United States - **Experience:** Expert - **Salary:** $170,246.0 - $212,813.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Systems Engineering, Audit Trail, Microsoft Azure, Cloud Computing, Configuration Management, Cyber Security, Extract Transform Load (ETL), DevOps, Identity and Access Management, JSON, Python (Programming Language), Key Management, OpenID, Windows PowerShell, Program Analysis, Systems Development Life Cycle, Security Assertion Markup Language (SAML), Data Streaming, Systems Integration, TypeScript, Software Vulnerability Management, Google Cloud, Large Language Models, Multi-Agent Systems, Boomi, Software Security, Zapier, Git, Integration Frameworks, Restful APIs, Software Version Control, Data Pipelines, Automation Anywhere, Devsecops, Mulesoft, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 30, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17760908?backUrl=%2Fcareer%2F17760908%2FSenior-Staff-Devsecops-Engineerinformation-Technology-Somerville-Ma-Full-Time-On-Site-Massachusetts-Somerville ## About the Role * 9+ years in application security, DevSecOps, or security engineering, including experience building or supporting integrations, automations, or data pipelines in an enterprise IT environment. * Demonstrated experience setting secure-development standards and mentoring other engineers, not just applying existing standards. * Strong scripting and programming skills (e.g., Python, JavaScript / TypeScript, or PowerShell) and hands-on experience with REST APIs and JSON. * Deep, hands-on experience with SAST/DAST tooling, dependency and software composition analysis (SCA), and secrets-management practices. * Strong command of cloud and identity security fundamentals - least-privilege IAM design, SSO (SAML / OIDC), and secrets/credential management. * Experience securing CI/CD pipelines end to end and familiarity with version control (Git) and modern deployment practices. * A pragmatic, detail-oriented approach to building reliable, secure systems in a fast-paced environment, and comfort operating as a peer to both engineering leadership and security/compliance stakeholders., * Experience securing AI/LLM-based tooling or agentic systems, including MCP servers, AI integrations, or similar emerging architectures. * Experience with iPaaS / integration platforms (e.g., Workato, Boomi, MuleSoft, Zapier) or custom-built integrations. * Familiarity with compliance frameworks relevant to a SOX or audit-controlled environment (e.g., segregation of duties, change management, access review). * Experience with cloud platforms (Microsoft Azure preferred, Google Cloud, or AWS) and infrastructure-as-code or configuration-management tooling. * Experience in a manufacturing, hardware, laboratory, or high-growth technology environment. ## Description Form Energy is scaling quickly across research, engineering, and manufacturing, and the integrations, automations, and AI-enabled tools that connect our systems need to be built securely from the start. As Senior Staff DevSecOps Engineer on the IT Engineering & Platforms team, you will define and lead how the team embeds security into the design, build, and operation of integrations, ETL/data pipelines, automations, and custom-built tools - including MCP servers and other AI-agent tooling. You will set secure-development standards for the team, work hands-on building and configuring systems yourself, and serve as the senior technical voice on security for everything the team ships. Relocation assistance is available. What you'll do: * Define and lead secure-SDLC practices for integrations, automations, ETL/data pipelines, and custom-built tools - including secure design review, dependency and secrets scanning, and secure coding standards - and mentor other engineers on their application. * Own application-layer security strategy for the team's deliverables: static and dynamic analysis (SAST/DAST), dependency and supply-chain vulnerability management, and secrets detection across the codebase and CI/CD pipelines. * Set the architecture and guardrails for securing AI and agentic tooling specifically - credential scoping and least-privilege access for MCP servers and AI integrations, safe handling of data passed to and from LLM-based tools, and defenses against prompt-injection and data-exfiltration risk in custom AI workflows. * Harden CI/CD pipelines - least-privilege service accounts, secrets management, signed or verified artifacts, and gated deployments - and establish standards other engineers build against. * Build and configure integrations, automations, and tooling alongside the DevOps team as needed, modeling the secure-development practices you define. * Build security observability into what the team ships: audit logging, anomaly alerting, and incident-relevant telemetry for integrations and automations. * Own a risk-based inventory of the team's integrations, automations, and custom tools, with documented data flows and access scopes. * Serve as the senior technical security liaison between IT Engineering & Platforms and the Information Security & GRC vertical - informing policy and control design with implementation-level context. * Lead response for security-related incidents in integrations and automations, and own the related incident response runbooks. ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)