Job Summary:
Twenty is focused on defending democracies in the digital age through revolutionary technologies. The Senior / Staff DevSecOps Engineer will build and own the security infrastructure that ensures the safety of engineering systems while facilitating efficient workflows for developers.
Responsibilities:
• Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
• Design and enforce identity and access management (IAM) across AWS and internal systems — least-privilege by default.
• Own secrets and credentials management: policies, tooling, rotation, and developer workflows that make doing the right thing easy.
• Lead security incident response: detection, containment, root cause analysis, and durable remediation.
• Manage AWS Organization structure, account boundaries, SCPs, and guardrails.
• Harden and maintain CI/CD pipelines, embedding security scanning and policy enforcement into the software delivery lifecycle.
• Drive compliance efforts — own the evidence, controls, and remediation work to meet and maintain relevant frameworks.
• Build and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.
• Reduce friction through automation: certificate issuance, secrets access, policy-as-code, and developer-facing tooling.
• Produce lightweight, practical security guidance that engineers actually use.
• Shape the direction of the DSO function as it scales, and contribute to hiring and team-building as we grow.
Qualifications:
Required:
• 8+ years in DevSecOps, platform security, or a closely related security engineering role.
• Deep hands-on experience with AWS — IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail, etc.).
• Strong IaC experience with Terraform; you've used it to enforce security controls, not just provision infrastructure — and you've layered in policy-as-code tooling (e.g., OPA, Checkov, tfsec) or continuous compliance checks (e.g., AWS Config Rules) to catch drift and misconfigurations.
• Experience owning secrets management end-to-end in a production engineering environment.
• Proven track record designing and hardening CI/CD pipelines (we use GitHub Actions).
• Hands-on experience with container security, including image scanning and runtime controls.
• Experience leading or meaningfully contributing to a compliance program; CMMC Level 2 (or NIST SP 800-171) experience strongly preferred.
• You've run incident response — you've been on call, you've led the post-mortem, and you've shipped the fix.
• Strong communication skills and the ability to drive security adoption through enablement, not mandates.
Preferred:
• Experience growing a DSO or security engineering function — expanding scope, tooling, and team.
• Familiarity with observability tooling and using it for security signal (we use the LGTM stack).
• Background in configuration management tooling (Ansible or similar).
• Experience with developer-facing security platforms or internal tooling that improved engineering workflows.
• Interest in growing into a lead or manager role as the team scales.
Company:
We apply world-class software engineering to a warfighting domain of persistent conflict. Founded in 2024, the company is headquartered in Arlington, USA, with a team of 11-50 employees. The company is currently Early Stage.