Twenty Twenty Therapeutics
Senior / Staff DevSecOps Engineer
Arlington, VA · Staff+ · Full-time
Sponsorship not specified$171k-$800kDetected 98 days ago
GitAWSDockerTerraformAnsibleCI/CDGitHub ActionsGrafana
About the role
- ABOUT THE COMPANY America is under sustained cyber attack.
- Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on.
- They've learned-correctly-that those attacks rarely produce consequences.
Responsibilities
- Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
- Design and enforce identity and access management (IAM) across AWS and internal systems - least-privilege by default.
- Own secrets and credentials management: policies, tooling, rotation, and developer workflows that make doing the right thing easy.
- Lead security incident response: detection, containment, root cause analysis, and durable remediation.
- Manage AWS Organization structure, account boundaries, SCPs, and guardrails.
- Harden and maintain CI/CD pipelines, embedding security scanning and policy enforcement into the software delivery lifecycle.
- Drive compliance efforts - own the evidence, controls, and remediation work to meet and maintain relevant frameworks.
- Build and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.
- Shape the direction of the DSO function as it scales, and contribute to hiring and team-building as we grow.
- You hold a high bar for reliability and auditability in the systems you build.
Requirements
- You bring high judgment to tradeoffs - you know when to enforce hard controls and when friction kills adoption.
- 8+ years in DevSecOps, platform security, or a closely related security engineering role.
- Deep hands-on experience with AWS - IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail, etc.).
- Strong IaC experience with Terraform
- Proven track record designing and hardening CI/CD pipelines (we use GitHub Actions).
- Hands-on experience with container security, including image scanning and runtime controls.
Nice to have
- Experience growing a DSO or security engineering function - expanding scope, tooling, and team.
- Familiarity with observability tooling and using it for security signal (we use the LGTM stack).
- Background in configuration management tooling (Ansible or similar).
- Experience with developer-facing security platforms or internal tooling that improved engineering workflows.
- Cloud: AWS (primary), Terraform for IaC, Ansible for configuration management
- Containers: Docker, Docker Compose
- CI/CD: GitHub Actions
- Vulnerability scanning: Trivy
Skills
- AWS (primary), Terraform for IaC, Ansible for configuration management
Compensation
- $171k-$800k
Benefits
- Medical, dental, and vision plan options.
- Life / AD&D, disability coverage options.
- Paid parental leave for eligible full-time employees.
- Paid holidays and flexible PTO.
- HSA/FSA options, dependent care FSA.
- Commuter benefits.
- Building fitness center.
- Desk setup stipend.
- We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status.
- Benefits vary by location, role, and eligibility.
Company info
- America is under sustained cyber attack.
- Twenty was founded to change that, by making our adversaries think twice before they attack us.
- Our vision is American and allied primacy in cyberspace-a future where they cannot contest us, deterrence is assured, and the free world remains secure.
- Founded in 2024, Twenty Technologies (www.twenty.io http://www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies.
- Headquartered in Arlington, Virginia, Twenty has raised $138M from Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.
- You'll build and own the security infrastructure that keeps Twenty's engineering systems safe without slowing engineers down.
- This role spans runtime security, access control, secrets management, compliance, and CI/CD hardening - but it's equally about making security the path of least resistance.
- You'll embed with our engineering teams, design secure-by-default foundations, and build the tooling and automation that lets developers move fast without cutting corners.
- You'll report directly to the VP of Engineering and operate as a shared function across our product teams.
Equal opportunity
- equal opportunity employer.
- If you need a reasonable accommodation during the hiring process, let us know and we will work with you.
Visa & Work Authorization
- Government security clearance
Apply directly at Twenty Twenty Therapeutics →Create a free account for alerts like thisView Twenty Twenty Therapeutics immigration profile
This listing is sourced directly from Twenty Twenty Therapeutics's careers page and normalized into a canonical job model.