Full-Time

Senior / Staff DevSecOps Engineer

Updated on 8/21/2026

Twenty

Twenty

11-50 employees

Autonomous offensive cyber operations platform

Compensation Overview

$159k - $263k/yr

No H1B Sponsorship

Arlington County, Arlington, VA, USA

In Person

On-site in Arlington, Virginia.

US Citizenship, US Top Secret Clearance Required

Category
DevOps & Infrastructure (1)
Required Skills
Python
Grafana
Incident Response
React.js
GitHub Actions
Infrastructure as Code (IaC)
Docker
TypeScript
Vulnerability Analysis
AWS
Go
Terraform
Ansible
Grafana Loki
DevOps

Get referred to Twenty

See people who can refer or advise you

Requirements
  • At least 8 years of experience in DevSecOps, platform security, or a closely related security engineering role.
  • Deep hands-on experience with Amazon Web Services, including Identity and Access Management, Service Control Policies, Organizations, GuardDuty, Security Hub, and CloudTrail.
  • Strong infrastructure-as-code experience with Terraform, including enforcing security controls and using policy-as-code tooling such as Open Policy Agent, Checkov, or tfsec, or continuous compliance checks such as AWS Config Rules.
  • Experience owning secrets management end-to-end in a production engineering environment.
  • A proven track record designing and hardening continuous integration and continuous delivery pipelines, including GitHub Actions.
  • Hands-on experience with container security, including image scanning and runtime controls.
  • Experience leading or meaningfully contributing to a compliance program.
  • Experience running incident response, including on-call participation, leading post-mortems, and shipping fixes.
  • Strong communication skills and the ability to drive security adoption through enablement rather than mandates.
  • U.S. citizenship is required.
  • Eligibility to obtain and maintain a U.S. government security clearance is required.
Responsibilities
  • Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
  • Design and enforce identity and access management across Amazon Web Services and internal systems using least privilege by default.
  • Own secrets and credentials management, including policies, tooling, rotation, and developer workflows.
  • Lead security incident response, including detection, containment, root cause analysis, and durable remediation.
  • Manage Amazon Web Services Organization structure, account boundaries, Service Control Policies, and guardrails.
  • Harden and maintain continuous integration and continuous delivery pipelines by embedding security scanning and policy enforcement into the software delivery lifecycle.
  • Drive compliance efforts by owning evidence, controls, and remediation work to meet and maintain relevant frameworks.
  • Build and maintain secure-by-default templates for repositories, pipelines, and infrastructure modules.
  • Reduce friction through automation for certificate issuance, secrets access, policy-as-code, and developer-facing tooling.
  • Produce practical security guidance for engineers.
  • Shape the direction of the DevSecOps function as it scales and contribute to hiring and team-building as the company grows.
Desired Qualifications
  • Experience with Cybersecurity Maturity Model Certification Level 2 or National Institute of Standards and Technology Special Publication 800-171.
  • Experience growing a DevSecOps or security engineering function by expanding its scope, tooling, and team.
  • Familiarity with observability tooling and using it for security signals, including the LGTM stack.
  • Background in configuration management tooling such as Ansible.
  • Experience with developer-facing security platforms or internal tooling that improved engineering workflows.
  • Interest in growing into a lead or manager role as the team scales.

Twenty builds and deploys intelligent, autonomous systems for offensive cyber operations used by the U.S. military and Intelligence Community. Its software automates the offensive cyber lifecycle across hundreds of targets, turning multi-week workflows into continuous operations. The company emphasizes enterprise-grade, scalable cyber power to move beyond defensive postures and support active cyber conflicts, supported by government contracts and investors. Its goal is to provide faster, more reliable automated tools that give operators an information edge for national security missions.

Company Size

11-50

Company Stage

Series B

Total Funding

$168M

Headquarters

Arlington, Virginia

Founded

2024

Get referred to Twenty

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Khosla led a $30 million extension on July 20, 2026, valuing Twenty at $1.2 billion.
  • Twenty raised $100 million from Accel in June 2026, bringing total funding to $138 million.
  • Twenty lists 36 open roles on July 31, 2026, signaling rapid product expansion.

What critics are saying

  • Twenty depends heavily on U.S. Cyber Command and Navy procurement cycles.
  • Offensive AI cyber tools face congressional scrutiny; Lin testified on January 13, 2026.
  • A U.S. policy reversal or classified incident could freeze contracts and kill Twenty.

What makes Twenty unique

  • Twenty sells end-to-end offensive cyber automation, not point tools, for U.S. missions.
  • Joe Lin testified to Congress on January 13, 2026, framing measurable cyber deterrence.
  • The team combines ex-Palo Alto, Expanse, Army SIGINT, and U.S. Cyber Command operators.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Parental Leave

Unlimited Paid Time Off

Paid Holidays

401(k) Retirement Plan

Health Savings Account/Flexible Spending Account

Commuter Benefits

Growth & Insights and Company News

Headcount

6 month growth

10%

1 year growth

26%

2 year growth

26%
Citybiz
Jul 20th, 2026
Twenty secures $30M from Khosla Ventures at $1.2B valuation for AI cyber warfare tech

Cybersecurity startup Twenty has raised an additional $30 million from Khosla Ventures, bringing its valuation to $1.2 billion. The investment follows the company's recent $100 million Series B led by Accel, which valued it at $1 billion. Founded in 2024, Twenty has now raised a total of $168 million from investors including Khosla Ventures, Accel, General Catalyst, In-Q-Tel, Point72 Ventures, Caffeinated Capital and Friends & Family Capital. The company develops AI-enabled offensive cyber capabilities for the US military and intelligence agencies. Its technology combines artificial intelligence, automation and human oversight to support cyber operations whilst maintaining human decision-making throughout mission execution. Chief executive Joe Lin said the funding will support investment in engineering and product development as the company expands its technical workforce.

Accel
Jun 18th, 2026
Our Investment in Twenty: Industrial-Scale Cyber Operations

Twenty is the modern, end-to-end offensive cybersecurity platform for US agencies.

GovCon Wire
Jun 18th, 2026
Cyber warfare startup Twenty raises $100M in Series B funding round.

Cyber warfare startup Twenty raises $100M in Series B funding round. * Twenty has closed a $100 million Series B funding round * Series B has brought Twenty's total funding to $138 million * The Potomac Officers Club's 2026 DOW summits will feature discussions about AI, cyber resilience and more Cybersecurity company Twenty has secured $100 million in a round of Series B financing led by Accel to expand its artificial intelligence-enabled offensive cyber capabilities for the U.S. military and intelligence Community. As investment accelerates across cyber warfare and defense technologies, broader momentum is also building around digital modernization and national security innovation. Two upcoming Potomac Officers Club events will bring together senior leaders to explore these priorities in depth. Register now for the 2026 Air and Space Summit on July 30, followed by the 2026 Navy Summit on Aug. 27, with sessions focused on AI, cyber resilience and digital modernization. The company said Wednesday it has reached a $1 billion valuation with the latest funding round. What are the details of the Series B funding round? Friends & Family Capital, Point72 Ventures and Caffeinated Capital participated in the Series B funding round, which has brought Twenty's total funding to $138 million. Series B builds on earlier financing rounds led by Caffeinated Capital and Tim Junio, co-founder and CEO of Expanse, which was acquired by Palo Alto Networks for $1.25 billion in 2020. Additional early support came from investors, including In-Q-Tel and General Catalyst. What did Twenty CEO joe Lin say about the funding round? Joe Lin, co-founder and CEO of Twenty, said the company is developing AI-enabled capabilities designed to help warfighters disrupt cyberthreats at their origin. "This round is extraordinary validation from some of the world's foremost investors, and we are pouring this funding directly into research and engineering," added Lin. What does Twenty do? Twenty is a venture capital-backed cybersecurity startup focused on building AI-enabled, end-to-end cyber warfare systems for the U.S. and its allies. Established in 2024, the company works to industrialize offensive cyber capabilities by combining AI and automation with controlled deployment, evaluation and mission alignment.

PR Newswire
Nov 20th, 2025
Twenty Raises $38M to Transform Cyber Warfare at Industrial Scale

/PRNewswire/ -- Twenty, the company leading the industrial-scale transformation of cyber warfare technologies, today announced that it has raised $38 million...