Full-Time

Offensive Cyber Research Engineer

Twenty

Twenty

51-200 employees

Autonomous offensive cyber operations platform

Compensation Overview

$159k - $263k/yr

No H1B Sponsorship

Arlington County, Arlington, VA, USA

In Person

This is an in-office role in Arlington, Virginia.

US Citizenship, US Top Secret Clearance Required

Bachelor's, Master's

Category
Cybersecurity (1)
Required Skills
Kubernetes
Malware Analysis
Microsoft Azure
Agile
Python
Incident Response
Reverse Engineering
Machine Learning
Docker
Cybersecurity
Vulnerability Analysis
AWS
Go
Cryptography
Penetration Testing
Google Cloud Platform

Get referred to Twenty

See people who can refer or advise you

Requirements
  • 6-8 years of threat research, offensive cyber operations, and software development experience.
  • Expert-level operational cybersecurity experience in Digital Network Exploitation Analysis within U.S. Government military or intelligence organizations, Exploitation Analyst operations, advanced penetration testing or red teaming, or senior-level threat hunting and threat intelligence analysis.
  • Demonstrated technical leadership experience mentoring offensive cyber engineers and leading research initiatives.
  • Deep expertise in the MITRE ATT&CK framework and experience developing and implementing advanced adversary tactics, techniques, and procedures across multiple tactics.
  • Expert-level experience operating and extending Cobalt Strike, Metasploit, and custom command-and-control frameworks, including developing custom payloads, modules, and evasion techniques.
  • Extensive experience integrating and analyzing commercial feeds, open-source intelligence, and government intelligence sources.
  • Advanced proficiency implementing persistence mechanisms, defense evasion, counter-forensics, and anti-analysis methods.
  • Expert containerization and orchestration experience using Docker and Kubernetes.
  • Advanced programming and software architecture skills in Python and Golang, including building maintainable, production-grade security tools and automation frameworks.
  • Expert-level experience writing complex graph queries and developing graph-based analytical tools using Neo4j or similar graph databases.
  • Comprehensive knowledge of network security, application security, secure coding, cryptography, and security architecture.
  • Extensive practical experience with payload development, post-exploitation frameworks, command-and-control infrastructure, and multi-stage attack chains.
  • Expert knowledge of red team methodologies, campaign planning, operational security, adversary simulation, and intelligence-driven threat emulation.
  • Proven ability to lead technical projects and mentor engineering teams.
  • Experience conducting thorough code reviews and establishing development standards for security tools.
  • A bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field, or equivalent practical experience.
  • Must be eligible to obtain a U.S. Government security clearance.
Responsibilities
  • Lead the architecture and design of attack path frameworks that emulate advanced persistent threat behaviors and nation-state tactics, techniques, and procedures.
  • Establish technical standards and best practices for offensive cyber tool development across the organization.
  • Evaluate and recommend engineering courses of action for new offensive capabilities and system enhancements.
  • Drive technical decision-making for complex offensive cyber integrations and performance optimizations.
  • Architect scalable, modular frameworks for attack technique automation and adversary emulation.
  • Conduct advanced research into emerging adversary techniques, zero-day exploitation strategies, and novel attack vectors.
  • Develop proof-of-concept tools and techniques for offensive cyber capabilities.
  • Translate emerging threat actor tactics, techniques, and procedures into defensive and offensive capabilities.
  • Publish internal research findings and contribute to the broader cybersecurity research community.
  • Identify capability gaps and lead initiatives to develop new offensive tools and methodologies.
  • Mentor and provide technical guidance to offensive cyber engineers and researchers, including conducting code reviews and knowledge transfer.
  • Lead technical discussions and facilitate strategic planning sessions for offensive capability development.
  • Organize research efforts and coordinate collaboration with data engineering, backend, and intelligence analysis teams.
  • Establish and maintain engineering best practices, secure coding standards, and operational security procedures.
  • Guide junior engineers in understanding adversary behaviors and translating them into technical implementations.
  • Design and implement advanced attack paths that emulate sophisticated adversary campaigns across multiple domains.
  • Create reusable, production-grade components for credential harvesting, lateral movement, and defense evasion.
  • Develop custom tooling and automation frameworks for large-scale adversary emulation.
  • Lead the design of ETL pipelines for threat intelligence, security logs, and operational data at scale.
  • Architect standardized schemas for cyber operations datasets supporting graph-based analysis and artificial intelligence and machine learning workflows.
  • Implement data enrichment pipelines integrating diverse threat intelligence sources.
  • Design efficient storage and retrieval systems for large-scale security-relevant data.
  • Work with government customers and operational teams to understand mission requirements and capability gaps.
  • Translate operational feedback into technical requirements and development priorities.
  • Lead technical demonstrations of offensive cyber capabilities to stakeholders.
  • Provide subject matter expertise for customer engagements and strategic planning sessions.
Desired Qualifications
  • Previous technical leadership experience in government cyber operations units or intelligence organizations conducting Digital Network Exploitation Analysis or Exploitation Analyst operations.
  • Experience leading offensive cyber capability development programs or research initiatives.
  • A track record of developing novel offensive techniques or tools adopted by operational units.
  • Advanced certifications such as OSCP, OSCE, OSEE, GXPN, or government-recognized advanced offensive security credentials.
  • Experience with artificial intelligence and machine learning integration in offensive cyber operations and automated threat emulation.
  • Extensive background in malware analysis, reverse engineering, exploit development, or vulnerability research.
  • Experience with multi-domain intelligence analysis correlating cyber, signals intelligence, electronic intelligence, and other intelligence sources.
  • Publications or conference presentations on offensive cyber research or techniques.
  • Contributions to open-source offensive security tools or frameworks.
  • Experience with Agile development methodologies and leading Agile teams.
  • Advanced system architecture and design experience for large-scale security systems.
  • Performance optimization and scalability experience for high-throughput data processing.
  • Experience with cloud security using AWS, Azure, or Google Cloud Platform and cloud-native attack techniques.
  • Deep knowledge of wireless security, Internet of Things protocols, and electromagnetic spectrum operations.
  • Expertise with forensics tools, incident response procedures, and defensive cyber operations.
  • Understanding of government acquisition processes and requirements development.

Twenty builds and deploys intelligent, autonomous systems for offensive cyber operations used by the U.S. military and Intelligence Community. Its software automates the offensive cyber lifecycle across hundreds of targets, turning multi-week workflows into continuous operations. The company emphasizes enterprise-grade, scalable cyber power to move beyond defensive postures and support active cyber conflicts, supported by government contracts and investors. Its goal is to provide faster, more reliable automated tools that give operators an information edge for national security missions.

Company Size

51-200

Company Stage

Series B

Total Funding

$168M

Headquarters

Arlington, Virginia

Founded

2024

Get referred to Twenty

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Reuters reported June 17, 2026 that Twenty raised $100 million at a $1 billion valuation.
  • The round brought $138 million total funding, extending runway for engineering hires and product hardening.
  • Cyber Command's $12.6 million ceiling and Navy research work provide reference customers and credibility.

What critics are saying

  • Twenty depends on federal procurement; a budget pause or protest stalls revenue immediately.
  • Offensive cyber products invite congressional scrutiny, legal restrictions, and public backlash after any mishap.
  • Crowded defense-AI rivals like Accel-backed startups and Prime targeting similar agency buyers compress differentiation.

What makes Twenty unique

  • Joe Lin and Leo Olson pair Palo Alto Networks product chops with U.S. military tradecraft.
  • Twenty won a sole-source U.S. Cyber Command OTA in June 2025, validating mission fit.
  • The platform targets autonomous offensive workflows, compressing weeks of cyber ops into continuous execution.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Parental Leave

Unlimited Paid Time Off

Paid Holidays

401(k) Retirement Plan

Health Savings Account/Flexible Spending Account

Commuter Benefits

Growth & Insights and Company News

Headcount

6 month growth

6%

1 year growth

23%

2 year growth

23%
Citybiz
Jul 20th, 2026
Twenty secures $30M from Khosla Ventures at $1.2B valuation for AI cyber warfare tech

Cybersecurity startup Twenty has raised an additional $30 million from Khosla Ventures, bringing its valuation to $1.2 billion. The investment follows the company's recent $100 million Series B led by Accel, which valued it at $1 billion. Founded in 2024, Twenty has now raised a total of $168 million from investors including Khosla Ventures, Accel, General Catalyst, In-Q-Tel, Point72 Ventures, Caffeinated Capital and Friends & Family Capital. The company develops AI-enabled offensive cyber capabilities for the US military and intelligence agencies. Its technology combines artificial intelligence, automation and human oversight to support cyber operations whilst maintaining human decision-making throughout mission execution. Chief executive Joe Lin said the funding will support investment in engineering and product development as the company expands its technical workforce.

Accel
Jun 18th, 2026
Our Investment in Twenty: Industrial-Scale Cyber Operations

Twenty is the modern, end-to-end offensive cybersecurity platform for US agencies.

GovCon Wire
Jun 18th, 2026
Cyber warfare startup Twenty raises $100M in Series B funding round.

Cyber warfare startup Twenty raises $100M in Series B funding round. * Twenty has closed a $100 million Series B funding round * Series B has brought Twenty's total funding to $138 million * The Potomac Officers Club's 2026 DOW summits will feature discussions about AI, cyber resilience and more Cybersecurity company Twenty has secured $100 million in a round of Series B financing led by Accel to expand its artificial intelligence-enabled offensive cyber capabilities for the U.S. military and intelligence Community. As investment accelerates across cyber warfare and defense technologies, broader momentum is also building around digital modernization and national security innovation. Two upcoming Potomac Officers Club events will bring together senior leaders to explore these priorities in depth. Register now for the 2026 Air and Space Summit on July 30, followed by the 2026 Navy Summit on Aug. 27, with sessions focused on AI, cyber resilience and digital modernization. The company said Wednesday it has reached a $1 billion valuation with the latest funding round. What are the details of the Series B funding round? Friends & Family Capital, Point72 Ventures and Caffeinated Capital participated in the Series B funding round, which has brought Twenty's total funding to $138 million. Series B builds on earlier financing rounds led by Caffeinated Capital and Tim Junio, co-founder and CEO of Expanse, which was acquired by Palo Alto Networks for $1.25 billion in 2020. Additional early support came from investors, including In-Q-Tel and General Catalyst. What did Twenty CEO joe Lin say about the funding round? Joe Lin, co-founder and CEO of Twenty, said the company is developing AI-enabled capabilities designed to help warfighters disrupt cyberthreats at their origin. "This round is extraordinary validation from some of the world's foremost investors, and we are pouring this funding directly into research and engineering," added Lin. What does Twenty do? Twenty is a venture capital-backed cybersecurity startup focused on building AI-enabled, end-to-end cyber warfare systems for the U.S. and its allies. Established in 2024, the company works to industrialize offensive cyber capabilities by combining AI and automation with controlled deployment, evaluation and mission alignment.

PR Newswire
Nov 20th, 2025
Twenty Raises $38M to Transform Cyber Warfare at Industrial Scale

/PRNewswire/ -- Twenty, the company leading the industrial-scale transformation of cyber warfare technologies, today announced that it has raised $38 million...