{"id":1426922,"url":"https://alion.io/job/twenty-seniorstaff-devsecops-engineer","title":"Senior/Staff DevSecOps Engineer","company":{"id":685785,"name":"Twenty","domain":"twenty.io","url":"https://alion.io/company/twenty-2","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"C","score":56,"open_postings":26,"ghost_share":0.731,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-28T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":159000,"max":263000,"currency":"USD","period":"year","gross":null,"usd_annual":263000},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Checkov","optional":false},{"name":"CI/CD","optional":false},{"name":"GitHub Actions","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Terraform","optional":false},{"name":"tfsec","optional":false},{"name":"Ansible","optional":true},{"name":"Configuration Management","optional":true},{"name":"Docker","optional":true},{"name":"Docker Compose","optional":true},{"name":"Go","optional":true},{"name":"Grafana","optional":true},{"name":"Loki","optional":true},{"name":"Mimir","optional":true},{"name":"PagerDuty","optional":true},{"name":"Python","optional":true},{"name":"Trivy","optional":true},{"name":"TypeScript","optional":true}],"status":"live","first_seen_at":"2026-09-28T17:39:54Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-29T03:26:28Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"About the Company\nAmerica is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned-correctly-that those attacks rarely produce consequences.\nTwenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace-a future where they cannot contest us, deterrence is assured, and the free world remains secure.\nFounded in 2024, Twenty Technologies (www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.\nMission | On Site | Full Time | U.S. Citizenship Required / No Active Clearance Required\nRole Summary\nYou'll build and own the security infrastructure that keeps Twenty's engineering systems safe without slowing engineers down. This role spans runtime security, access control, secrets management, compliance, and CI/CD hardening - but it's equally about making security the path of least resistance. You'll embed with our engineering teams, design secure-by-default foundations, and build the tooling and automation that lets developers move fast without cutting corners. You'll report directly to the VP of Engineering and operate as a shared function across our product teams.\nWhat You'll Do\nOwn runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.\n\nDesign and enforce identity and access management (IAM) across AWS and internal systems - least-privilege by default.\n\nOwn secrets and credentials management: policies, tooling, rotation, and developer workflows that make doing the right thing easy.\n\nLead security incident response: detection, containment, root cause analysis, and durable remediation.\n\nManage AWS Organization structure, account boundaries, SCPs, and guardrails.\n\nHarden and maintain CI/CD pipelines, embedding security scanning and policy enforcement into the software delivery lifecycle.\n\nDrive compliance efforts - own the evidence, controls, and remediation work to meet and maintain relevant frameworks.\n\nBuild and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.\n\nReduce friction through automation: certificate issuance, secrets access, policy-as-code, and developer-facing tooling.\n\nProduce lightweight, practical security guidance that engineers actually use.\n\nShape the direction of the DSO function as it scales, and contribute to hiring and team-building as we grow.\n\nWho You Are\nYou believe security should be a force multiplier for engineering, not a gatekeeper.\n\nYou take ownership end-to-end: from identifying a risk to designing the control to shipping the fix.\n\nYou bring high judgment to tradeoffs - you know when to enforce hard controls and when friction kills adoption.\n\nYou communicate clearly with both engineers and non-technical stakeholders, and you translate risk into plain language.\n\nYou prefer automation over policy: if an engineer has to do something manually to stay secure, you see that as a bug.\n\nYou hold a high bar for reliability and auditability in the systems you build.\n\nYou're self-directed and thrive in an environment where the function is new and you're defining it.\n\nMust Have\n8+ years in DevSecOps, platform security, or a closely related security engineering role.\n\nDeep hands-on experience with AWS - IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail, etc.).\n\nStrong IaC experience with Terraform; you've used it to enforce security controls, not just provision infrastructure - and you've layered in policy-as-code tooling (e.g., OPA, Checkov, tfsec) or continuous compliance checks (e.g., AWS Config Rules) to catch drift and misconfigurations.\n\nExperience owning secrets management end-to-end in a production engineering environment.\n\nProven track record designing and hardening CI/CD pipelines (we use GitHub Actions).\n\nHands-on experience with container security, including image scanning and runtime controls.\n\nExperience leading or meaningfully contributing to a compliance program; CMMC Level 2 (or NIST SP 800-171) experience strongly preferred.\n\nYou've run incident response - you've been on call, you've led the post-mortem, and you've shipped the fix.\n\nStrong communication skills and the ability to drive security adoption through enablement, not mandates.\n\nNice to Have\nExperience growing a DSO or security engineering function - expanding scope, tooling, and team.\n\nFamiliarity with observability tooling and using it for security signal (we use the LGTM stack).\n\nBackground in configuration management tooling (Ansible or similar).\n\nExperience with developer-facing security platforms or internal tooling that improved engineering workflows.\n\nInterest in growing into a lead or manager role as the team scales.\n\nTech Environment (You Might Work With)\nCloud: AWS (primary), Terraform for IaC, Ansible for configuration management\n\nContainers: Docker, Docker Compose\n\nCI/CD: GitHub Actions\n\nVulnerability scanning: Trivy\n\nObservability: Grafana, Loki, Tempo, Mimir (LGTM stack)\n\nAlerting / on-call: PagerDuty\n\nLanguages in use across engineering: Go, TypeScript/Node, React, Python\n\nSecurity / Work Environment\nThis role requires eligibility to obtain and maintain a U.S. Government security clearance. This role may involve work in a controlled environment.\nBenefits\nWhat's on the table:\nHealth. Medical, dental, and vision plan options. Life / AD&D, disability coverage options.\n\nFamily. Paid parental leave for eligible full-time employees. 12 weeks for birthing parents, 4 for non-birthing parents, 6 weeks for adoptive, foster, or intended parents through surrogacy.\n\nVacation. Paid holidays and flexible PTO. Take what you need.\n\nRetirement. 401(k) with pre-tax and Roth options. HSA/FSA options, dependent care FSA.\n\nBenefits vary by location, role, and eligibility. Full plan details provided during the interview and offer process.\nIf this role sounds like you, apply and share with us your interest\nDue to U.S. government contract and security requirements, this role is limited to U.S. citizens. Some positions may also require eligibility to obtain and maintain a U.S. Government security clearance. Any active clearance requirement will be listed in the role description.\nTwenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status, consistent with applicable law.\nIf you need a reasonable accommodation during the hiring process, let us know and we will work with you.","description_format":"text","description_chars":6926,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Parental leave"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","Military","Cyber Warfare"],"lifecycle":[{"event":"open","at":"2026-09-29T00:02:27Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":54,"reasons":["conf:1","win:early"],"computed_at":"2026-09-29T04:48:57Z"},"pay":{"stated_usd_annual":263000,"is_top_pay":true},"html_url":"https://alion.io/job/twenty-seniorstaff-devsecops-engineer","json_url":"https://alion.io/job/twenty-seniorstaff-devsecops-engineer.json","meta":{"generated_at":"2026-09-29T04:48:57Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4622,"day_limit":5000,"remaining_today":378,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}