Senior Dev SecOps Engineer

NextEra EnergySaint Paul, MN
Onsite

About The Position

NextEra Analytics offers energy consulting services using industry-leading scientific analysis for planning, siting, forecasting and optimizing all forms of energy projects. Our optimization and analytics platforms integrate open-source technologies to leverage massive, diverse sets of utility operating data. This enables rapid development of operational solutions. Applying expertise in advanced mathematics, data and physical sciences, we solve some of the hardest problems facing the energy industry. We are seeking a high-caliber Senior DevSecOps Engineer to embed security throughout the software development lifecycle and strengthen the security of our cloud platforms, development pipelines, and software supply chain. This role is designed for an experienced security engineer who combines deep technical expertise with a strong understanding of modern software engineering and developer workflows. You will partner closely with software engineering, cloud, platform, cybersecurity, and governance teams to build scalable security controls that reduce risk without creating unnecessary friction. You will operate with a high degree of autonomy, establishing secure-by-default patterns, influencing system design, and implementing measurable controls across traditional and AI-assisted development environments.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Technology, or equivalent practical experience.
  • 7+ years of experience in DevSecOps, application security, cloud security, platform engineering, software engineering, or a related technical discipline.
  • Hands-on experience designing and securing enterprise CI/CD pipelines and software development workflows.
  • Experience implementing and operating security testing capabilities such as SAST, SCA, DAST, secret scanning, infrastructure-as-code scanning, and container or image scanning.
  • Strong knowledge of software supply chain security concepts, including SBOMs, artifact signing, software provenance, dependency governance, and SLSA-aligned practices.
  • Hands-on experience implementing cloud security controls across AWS, GCP, or comparable public cloud platforms.
  • Experience with infrastructure-as-code and policy-as-code technologies such as Terraform, Open Policy Agent, or comparable toolsets.
  • Strong understanding of identity and access management, least privilege, network segmentation, secure logging, secrets management, and cloud-native security architecture.
  • Experience assessing or governing AI coding assistants, autonomous development agents, AI-generated code, or agent tool integrations.
  • Proven ability to collaborate with software engineering, cybersecurity, risk, compliance, and platform teams in a fast-paced development environment.
  • Strong written and verbal communication skills, including the ability to explain complex security risks and technical decisions in clear, outcome-oriented terms.
  • High School Grad / GED
  • Bachelor's or Equivalent Experience
  • Experience: 4+ years

Responsibilities

  • Build and maintain secure CI/CD pipelines with automated security gates, including static application security testing, software composition analysis, dynamic application security testing, secret scanning, infrastructure-as-code scanning, and container or image scanning.
  • Configure and tune security tooling using exploitability and reachability-based prioritization to minimize false positives and reduce unnecessary developer friction.
  • Lead threat modeling, security design reviews, and the adoption of secure architecture patterns early in the development lifecycle.
  • Promote architectural and systemic security improvements that prevent recurring issues rather than relying on short-term or symptom-based fixes.
  • Develop reusable pipeline templates, hardened base images, security guardrails, and secure-by-default development patterns that shift security left without slowing delivery.
  • Establish security standards and governance for AI coding assistants, agentic development tools, and AI-generated code.
  • Implement least-agency permission models, human review requirements, code provenance standards, and controls governing autonomous agent access to tools, data, and environments.
  • Evaluate and secure agent tool integrations, including Model Context Protocol integrations, while ensuring appropriate authentication, authorization, isolation, and oversight.
  • Implement identity and access management, least-privilege access, network boundaries, centralized logging, and secure configuration standards across AWS and GCP environments.
  • Establish software and AI bills of materials, dependency governance, artifact signing, and software provenance aligned with frameworks such as SLSA.
  • Protect the software delivery pipeline through OIDC-based publishing, ephemeral runners, controlled network egress, secure secrets management, and hardened build environments.
  • Implement infrastructure-as-code and policy-as-code controls that provide consistent enforcement, immutable logging, and automated evidence generation.
  • Lead vulnerability triage, exploitability-informed risk ranking, remediation service-level objectives, exception management, and recurrence prevention.
  • Define and track meaningful measures such as mean time to remediate, scan coverage, policy compliance, vulnerability recurrence, and developer adoption of security guardrails.
  • Use security findings, operational data, and engineering feedback to continuously improve tooling, processes, and preventative controls.
  • Demonstrate risk reduction over time through clear reporting, actionable metrics, and transparent communication with technical and business stakeholders.
  • Collaborate with application security, engineering, cloud, platform, cybersecurity, risk, and compliance teams to integrate security into technical delivery.
  • Feed pipeline evidence, security findings, software inventories, and control results into application security reviews, third-party risk assessments, and compliance activities.
  • Support penetration testing, application assessments, audit requests, and remediation efforts by providing accurate technical evidence and tracking corrective actions.
  • Clearly communicate security risks, technical tradeoffs, and remediation priorities to engineering teams, cybersecurity leadership, and business stakeholders.
  • Managing, monitoring and deploying a highly available, highly scalable production application.
  • Responsible for one or more environments and/or systems and interface directly with the Development and Operations team on a daily basis for the maintenance, expansion, and documentation of these environments, providing assistance and review of proposed architectures, as needed.
  • Responsible for vetting emerging technologies and guides the direction of the teams that support software development.
  • Drives the automation and continuous improvement of the software delivery process.
  • Manages the continuous integration services maintenance and configuration, ensuring the build environment is meeting the needs of the software developers.
  • Leads the maintenance and creation of automatic deployment of software builds to the test and production environments, enabling the operations team to easily and consistently deploy new software products.
  • Monitors system development and maintenance and ensures that staff at all technical levels are informed of the health of our systems.
  • Evaluates Operation teams processes and automates repetitive and temporary solutions.
  • Improves the product environment and practices used by the software developers.
  • Sets up back-up mechanisms for production environments and test disaster recovery mechanisms.
  • Performs other job-related duties as assigned.

Benefits

  • Relocation Provided: Yes, if applicable
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service