Twenty Twenty Therapeutics

Twenty Twenty Therapeutics

Senior / Staff DevSecOps Engineer

Arlington, VA · Staff+ · Full-time

Sponsorship not specified$171k-$800kDetected 98 days ago
GitAWSDockerTerraformAnsibleCI/CDGitHub ActionsGrafana

About the role

  • ABOUT THE COMPANY America is under sustained cyber attack.
  • Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on.
  • They've learned-correctly-that those attacks rarely produce consequences.

Responsibilities

  • Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
  • Design and enforce identity and access management (IAM) across AWS and internal systems - least-privilege by default.
  • Own secrets and credentials management: policies, tooling, rotation, and developer workflows that make doing the right thing easy.
  • Lead security incident response: detection, containment, root cause analysis, and durable remediation.
  • Manage AWS Organization structure, account boundaries, SCPs, and guardrails.
  • Harden and maintain CI/CD pipelines, embedding security scanning and policy enforcement into the software delivery lifecycle.
  • Drive compliance efforts - own the evidence, controls, and remediation work to meet and maintain relevant frameworks.
  • Build and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.
  • Shape the direction of the DSO function as it scales, and contribute to hiring and team-building as we grow.
  • You hold a high bar for reliability and auditability in the systems you build.

Requirements

  • You bring high judgment to tradeoffs - you know when to enforce hard controls and when friction kills adoption.
  • 8+ years in DevSecOps, platform security, or a closely related security engineering role.
  • Deep hands-on experience with AWS - IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail, etc.).
  • Strong IaC experience with Terraform
  • Proven track record designing and hardening CI/CD pipelines (we use GitHub Actions).
  • Hands-on experience with container security, including image scanning and runtime controls.

Nice to have

  • Experience growing a DSO or security engineering function - expanding scope, tooling, and team.
  • Familiarity with observability tooling and using it for security signal (we use the LGTM stack).
  • Background in configuration management tooling (Ansible or similar).
  • Experience with developer-facing security platforms or internal tooling that improved engineering workflows.
  • Cloud: AWS (primary), Terraform for IaC, Ansible for configuration management
  • Containers: Docker, Docker Compose
  • CI/CD: GitHub Actions
  • Vulnerability scanning: Trivy

Skills

  • AWS (primary), Terraform for IaC, Ansible for configuration management

Compensation

  • $171k-$800k

Benefits

  • Medical, dental, and vision plan options.
  • Life / AD&D, disability coverage options.
  • Paid parental leave for eligible full-time employees.
  • Paid holidays and flexible PTO.
  • HSA/FSA options, dependent care FSA.
  • Commuter benefits.
  • Building fitness center.
  • Desk setup stipend.
  • We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status.
  • Benefits vary by location, role, and eligibility.

Company info

  • America is under sustained cyber attack.
  • Twenty was founded to change that, by making our adversaries think twice before they attack us.
  • Our vision is American and allied primacy in cyberspace-a future where they cannot contest us, deterrence is assured, and the free world remains secure.
  • Founded in 2024, Twenty Technologies (www.twenty.io http://www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies.
  • Headquartered in Arlington, Virginia, Twenty has raised $138M from Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.
  • You'll build and own the security infrastructure that keeps Twenty's engineering systems safe without slowing engineers down.
  • This role spans runtime security, access control, secrets management, compliance, and CI/CD hardening - but it's equally about making security the path of least resistance.
  • You'll embed with our engineering teams, design secure-by-default foundations, and build the tooling and automation that lets developers move fast without cutting corners.
  • You'll report directly to the VP of Engineering and operate as a shared function across our product teams.

Equal opportunity

  • equal opportunity employer.
  • If you need a reasonable accommodation during the hiring process, let us know and we will work with you.

Visa & Work Authorization

  • Government security clearance

This listing is sourced directly from Twenty Twenty Therapeutics's careers page and normalized into a canonical job model.