SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Forma.ai is a Series B startup revolutionizing sales compensation design and management, handling billions in annual managed commissions for enterprise clients like Edmentum, Stryker, and Autodesk.
As Senior Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices. You'll work closely with Engineering, DevOps, IT, Product, Legal, and Privacy teams to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software.
Key responsibilities span five areas:
**Cloud and Infrastructure Security:** Design and implement security controls across AWS environments (IAM, least-privilege access, service identities, account boundaries). Embed security into Terraform and Infrastructure as Code. Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
**Application, Data, and AI Security:** Run threat modeling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations. Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls. Protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, and analytics services. Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions. Identify and remediate application vulnerabilities.
**DevSecOps and Secure Delivery:** Embed security testing into CI/CD (static analysis, dependency scanning, secrets detection, IaC scanning, dynamic testing). Define practical vulnerability-severity and remediation standards. Improve software supply-chain security including build permissions, artifact integrity, and dependency governance.
**Detection, Monitoring, and Incident Response:** Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems. Lead investigations and coordinate containment and remediation. Run tabletop exercises and track security metrics.
**Identity, Governance, and Enablement:** Strengthen SSO, MFA, privileged access, and access-review processes across AWS, GitHub, Microsoft 365, and production systems. Automate provisioning and entitlement reviews.
Security is currently shared across Engineering and DevOps; you'll have real room to shape how Forma approaches security as it grows, with potential to develop into a deeper individual-contributor position or help build a dedicated security team.