906,899open jobs
55,817companies
150,651added this week
Browse all
Salary
$159k – $263k per year
Location
In office (New York)
Seniority
Staff · 8+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Sep 28, 2026. Twenty scores C on the Alion truth index.

Overview
Company
Impact
Profile match
About Twenty The wars of tomorrow are here. Today.

About the Company

America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned-correctly-that those attacks rarely produce consequences.

Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace-a future where they cannot contest us, deterrence is assured, and the free world remains secure.

Founded in 2024, Twenty Technologies (www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.

Mission | On Site | Full Time | U.S. Citizenship Required / No Active Clearance Required

Role Summary

You'll build and own the security infrastructure that keeps Twenty's engineering systems safe without slowing engineers down. This role spans runtime security, access control, secrets management, compliance, and CI/CD hardening - but it's equally about making security the path of least resistance. You'll embed with our engineering teams, design secure-by-default foundations, and build the tooling and automation that lets developers move fast without cutting corners. You'll report directly to the VP of Engineering and operate as a shared function across our product teams.

What You'll Do

  • Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.

  • Design and enforce identity and access management (IAM) across AWS and internal systems - least-privilege by default.

  • Own secrets and credentials management: policies, tooling, rotation, and developer workflows that make doing the right thing easy.

  • Lead security incident response: detection, containment, root cause analysis, and durable remediation.

  • Manage AWS Organization structure, account boundaries, SCPs, and guardrails.

  • Harden and maintain CI/CD pipelines, embedding security scanning and policy enforcement into the software delivery lifecycle.

  • Drive compliance efforts - own the evidence, controls, and remediation work to meet and maintain relevant frameworks.

  • Build and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.

  • Reduce friction through automation: certificate issuance, secrets access, policy-as-code, and developer-facing tooling.

  • Produce lightweight, practical security guidance that engineers actually use.

  • Shape the direction of the DSO function as it scales, and contribute to hiring and team-building as we grow.

Who You Are

  • You believe security should be a force multiplier for engineering, not a gatekeeper.

  • You take ownership end-to-end: from identifying a risk to designing the control to shipping the fix.

  • You bring high judgment to tradeoffs - you know when to enforce hard controls and when friction kills adoption.

  • You communicate clearly with both engineers and non-technical stakeholders, and you translate risk into plain language.

  • You prefer automation over policy: if an engineer has to do something manually to stay secure, you see that as a bug.

  • You hold a high bar for reliability and auditability in the systems you build.

  • You're self-directed and thrive in an environment where the function is new and you're defining it.

Must Have

  • 8+ years in DevSecOps, platform security, or a closely related security engineering role.

  • Deep hands-on experience with AWS - IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail, etc.).

  • Strong IaC experience with Terraform; you've used it to enforce security controls, not just provision infrastructure - and you've layered in policy-as-code tooling (e.g., OPA, Checkov, tfsec) or continuous compliance checks (e.g., AWS Config Rules) to catch drift and misconfigurations.

  • Experience owning secrets management end-to-end in a production engineering environment.

  • Proven track record designing and hardening CI/CD pipelines (we use GitHub Actions).

  • Hands-on experience with container security, including image scanning and runtime controls.

  • Experience leading or meaningfully contributing to a compliance program; CMMC Level 2 (or NIST SP 800-171) experience strongly preferred.

  • You've run incident response - you've been on call, you've led the post-mortem, and you've shipped the fix.

  • Strong communication skills and the ability to drive security adoption through enablement, not mandates.

Nice to Have

  • Experience growing a DSO or security engineering function - expanding scope, tooling, and team.

  • Familiarity with observability tooling and using it for security signal (we use the LGTM stack).

  • Background in configuration management tooling (Ansible or similar).

  • Experience with developer-facing security platforms or internal tooling that improved engineering workflows.

  • Interest in growing into a lead or manager role as the team scales.

Tech Environment (You Might Work With)

  • Cloud: AWS (primary), Terraform for IaC, Ansible for configuration management

  • Containers: Docker, Docker Compose

  • CI/CD: GitHub Actions

  • Vulnerability scanning: Trivy

  • Observability: Grafana, Loki, Tempo, Mimir (LGTM stack)

  • Alerting / on-call: PagerDuty

  • Languages in use across engineering: Go, TypeScript/Node, React, Python

Security / Work Environment

This role requires eligibility to obtain and maintain a U.S. Government security clearance. This role may involve work in a controlled environment.

Benefits

What's on the table:

  • Health. Medical, dental, and vision plan options. Life / AD&D, disability coverage options.

  • Family. Paid parental leave for eligible full-time employees. 12 weeks for birthing parents, 4 for non-birthing parents, 6 weeks for adoptive, foster, or intended parents through surrogacy.

  • Vacation. Paid holidays and flexible PTO. Take what you need.

  • Retirement. 401(k) with pre-tax and Roth options. HSA/FSA options, dependent care FSA.

Benefits vary by location, role, and eligibility. Full plan details provided during the interview and offer process.

If this role sounds like you, apply and share with us your interest

Due to U.S. government contract and security requirements, this role is limited to U.S. citizens. Some positions may also require eligibility to obtain and maintain a U.S. Government security clearance. Any active clearance requirement will be listed in the role description.

Twenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status, consistent with applicable law.

If you need a reasonable accommodation during the hiring process, let us know and we will work with you.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
906,899 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
New York
≈ $116k – $240k per year (Estimated) • Equity • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • McKinney
Python
Java
PowerShell
C++
DevOps
Rest API
GCP
Azure
AWS
IAM
Cybersecurity
Okta
GDPR
HIPAA
Zero Trust
Microsoft Entra ID
Active Directory
LDAP
QA
Postman
Apply
≈ $102k – $200k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Irving
Python
JavaScript
PowerShell
DevOps
TCP/IP
Apply
≈ $110k – $233k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Irving
Python
Ruby
PowerShell
C++
Cybersecurity
ISO 27001
NIST 800-53
Management
Agile
Apply
$130k – $150k per year • Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Chicago
Python
PowerShell
DevOps
GCP
Azure
AWS
TCP/IP
DNS
Cybersecurity
Active Directory
SIEM
Apply
GRC Security Analyst 6 hours ago
$114k – $139k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree
AI/ML
Galileo
ISO 42001
Cybersecurity
ISO 27001
NIST CSF
SOC 2
GDPR
Apply
$99k – $142k per year • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Boston
SQL
Databases
Snowflake
AI/ML
dbt
DevOps
GCP
Azure
CI/CD
AWS
Analytics
ETL/ELT
Management
Agile
Apply
$112k – $168k per year • In office • 4+ years exp • Bachelor's Degree • Phoenix
Python
C++
C++
TensorFlow C++
PyTorch C++
AI/ML
OpenCV
CUDA Toolkit
Computer Vision
AI Agents
TensorFlow
PyTorch
CUDA
Machine Learning
DevOps
GitLab CI
CI/CD
Jenkins
Docker
Kubernetes
Linux
Robotics
ROS
Sensor Fusion
Apply
≈ $119k – $253k per year (Estimated) • In office • United States
Python
C++
MATLAB
MATLAB
Simulink
DevOps
CI/CD
Apply
$89k – $116k per year • In office • Full-Time • Bachelor's Degree • United States
Python
C++
AI/ML
SciPy
NumPy
DevOps
CI/CD
Linux
Robotics
ROS
ROS2
Sensor Fusion
Analytics
Matplotlib
QA
Sentry
Apply
$80k – $85k per year • Equity • Hybrid • Full-Time • Bachelor's Degree • Madison
Python
JavaScript
AI/ML
Machine Learning
Frontend
React.js
Mobile
React Native
DevOps
Rest API
GCP
Azure
AWS
Cybersecurity
HIPAA
Apply
$159k – $263k per year • In office • Full-Time • 8+ years exp • Arlington
Python
Go
TypeScript
DevOps
Terraform
Ansible
Docker Compose
GitHub Actions
Loki
PagerDuty
CI/CD
AWS
Docker
Grafana
Configuration Management
Mimir
IAM
Cybersecurity
Trivy
Checkov
Least Privilege
tfsec
Apply
IT Security Engineer 2 months ago
$116k – $195k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Arlington
DevOps
Splunk
Terraform
Ansible
GCP
Azure
AWS
Docker
Kubernetes
IAM
TCP/IP
DNS
DHCP
Cybersecurity
Snort
Suricata
OWASP Top 10
PCI DSS
SOC 2
GDPR
SIEM
DLP
Apply
Engineering Manager 8 hours ago
$197k – $354k per year • In office • Full-Time • 5+ years exp • New York
Python
Go
JavaScript
TypeScript
Databases
PostgreSQL
Neo4j
AI/ML
Machine Learning
Frontend
React.js
DevOps
Terraform
Ansible
CI/CD
AWS
Docker
Kubernetes
Apply
$159k – $263k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • New York
JavaScript
TypeScript
Databases
Neo4j
Frontend
Zustand
Redux
Webpack
D3.js
Chart.js
React.js
Vite
React Query
Storybook
Mobile
State Management
DevOps
CI/CD
Git
QA
Cypress
Playwright
Vitest
Apply
$192k – $455k per year • In office • Full-Time • 10+ years exp • Arlington
Python
Go
Java
Rust
Kotlin
C#
C++
Databases
MySQL
PostgreSQL
Neo4j
NATS
MariaDB
Amazon Neptune
Frontend
GraphQL
DevOps
CI/CD
AWS
Docker
Kubernetes
Cybersecurity
Threat Modeling
Apply
$65k – $68k per year • In office • Full-Time • 2+ years exp • PhD • New York
Management
Microsoft Office
Apply
Sales Manager 10 hours ago
≈ $38k – $79k per year (Estimated) • In office • Full-Time • 2+ years exp • PhD • New York
Management
Microsoft Office
Apply
$90k – $132k per year • In office • Full-Time • 6+ years exp • Minneapolis • New York
Marketing
YouTube
Apply
$110k – $160k per year • Equity 0.1–0.2% • In office • Full-Time • 3+ years exp • New York
AI/ML
Claude
Claude Code
Apply
$76k – $161k per year • Remote (United States) • Full-Time • 3+ years exp • Bachelor's Degree • New York • Jersey City • Newark
Apply
See all jobs
This is one of many
906,899 more open roles from verified company boards, updated every day.