SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Form Energy is a climate-tech company manufacturing long-duration iron-air battery systems for grid-scale energy storage. As Senior Staff DevSecOps Engineer on the IT Engineering & Platforms team, you will define and lead secure-development practices across integrations, automations, ETL/data pipelines, and custom-built tools—including MCP servers and AI-agent tooling.
You will own application-layer security strategy, including SAST/DAST, dependency and supply-chain vulnerability management, and secrets detection. A key focus is securing AI and agentic tooling: credential scoping, least-privilege access for MCP servers, safe LLM data handling, and defenses against prompt injection and data exfiltration.
You will harden CI/CD pipelines with least-privilege service accounts, secrets management, signed artifacts, and gated deployments. You'll build security observability into team deliverables—audit logging, anomaly alerting, and incident telemetry—and maintain a risk-based inventory of integrations and automations with documented data flows and access scopes.
You will serve as the senior technical security liaison between IT Engineering & Platforms and Information Security & GRC, informing policy and control design with implementation-level context. You'll lead security incident response for integrations and automations, own related runbooks, and mentor other engineers on secure-development practices.
Required: 9+ years in application security, DevSecOps, or security engineering, including enterprise IT integrations, automations, or data pipelines. Demonstrated experience setting secure-development standards and mentoring engineers. Strong scripting/programming (Python, JavaScript/TypeScript, PowerShell), REST APIs, JSON. Deep hands-on experience with SAST/DAST, SCA, secrets management. Strong cloud and identity security fundamentals (IAM, SSO, credential management). Experience securing CI/CD pipelines end-to-end, Git, modern deployment practices.
Preferred: AI/LLM tooling security (MCP servers, agentic systems), iPaaS platforms (Workato, Boomi, MuleSoft), SOX/audit compliance frameworks, cloud platforms (Azure preferred), infrastructure-as-code, manufacturing or high-growth tech environment experience.
Relocation assistance available.