About the Company
America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They've learned-correctly-that those attacks rarely produce consequences.
Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace-a future where they cannot contest us, deterrence is assured, and the free world remains secure.
Founded in 2024, Twenty Technologies (www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.
Role Summary
You'll be based in Twenty's New York City office, building and operating the data integrations that feed Twenty's mission-critical platform. Twenty builds software for cyber operations, and the applications this role feeds are used by operators and analysts working against hard national security problems. This is a hands-on engineering role with real production ownership: you'll build the pipelines that retrieve, process, and integrate new data sources into our applications, monitor the health of the data flowing through the systems you can reach, and debug production issues when they surface. Where your work runs in environments you can't access, you'll partner with Twenty's forward deployed engineers, who operate on-site at customer facilities, to get it deployed and keep it healthy. You'll join the data platform team, reporting to its engineering manager. The data integration tooling you'll build on is young and under active development. You'll be among its first production users, and what you learn in operation will directly shape how it evolves.
If you're an experienced data engineer who wants your work in the hands of operators the same week you build it, and you'd rather own a production system end to end than ship features into a backlog, this role is for you.
Who You Are
- You independently identify the right solution to ambiguous, open-ended problems. New data sources arrive undocumented and messy; you investigate, form a design, and deliver without waiting for a spec.
- You respond with urgency to operational issues and own resolution within your sphere. You're unafraid to call an incident when the signal warrants it.
- You proactively create and update runbooks and documentation for the components you own. Some of the environments your code runs in are ones you'll never touch, and what you write down is what the engineers there have to work with.
- You make informed decisions by consulting the right stakeholders and balancing detail with the big picture, and you execute against the spirit of the requirement, not just the letter.
- You actively seek out and eliminate sources of toil. Repetitive manual work is a design problem, and you treat it like one.
- You understand the customer and the mission well enough to know which work has the greatest impact, and you redirect your focus when what you're doing isn't moving the needle.
- You tailor your communication to your audience, whether that's a forward deployed engineer at a customer site, a product engineer in Arlington, or a teammate across the desk, and you proactively share information so the right people stay informed and aligned.
- You're comfortable building for restricted environments where deployment is gated, feedback loops are longer than you'd like, and disciplined engineering practice is the price of admission.
What You'll Do
Data Source Integration & Pipeline Development
- Design and build data pipelines that retrieve, parse, transform, and load new data sources into Twenty's applications, primarily as AWS Glue jobs written in PySpark.
- Investigate unfamiliar source systems and data formats, working with Twenty's engineers to understand semantics, access patterns, and constraints before writing code.
- Design schemas and data models that fit the platform's performance characteristics and the shape of the data, including analytical models in ClickHouse.
- Write code that is testable, debuggable, and maintainable by engineers operating it in environments you can't access. Tests carry unusual weight here: they're how the field trusts a change you'll never see run.
- Write integration code that meets the security standards of classified environments: no hardcoded secrets, disciplined credential handling, and audit-ready practices throughout, so your work moves through customer approval processes without friction.
Deployment & Field Support
- Deploy, operate, and iterate on integrations against the systems reachable from the office, end to end.
- Package pipelines and integrations destined for restricted environments so forward deployed engineers and customer deployment teams can install, verify, and operate them without you in the room.
- Support field deployments remotely: reproduce issues, cut fixes, and move them through the pipeline quickly when an on-site engineer is blocked.
- Operate and improve pipelines built elsewhere on the team, and feed operational learnings back into their design.
Production Health & Monitoring
- Monitor the health of data pipelines and platform services using the LGTM stack (Grafana, Loki, Tempo, Mimir).
- Track data quality, throughput, and freshness; identify anomalies and degradations before they become incidents.
- Build and improve the dashboards and alerts that make pipeline health visible to the team and to the forward deployed engineers who depend on it.
Incident Response & Debugging
- Diagnose and resolve production issues in the data path: failed ingests, malformed source data, pipeline stalls, performance degradation.
- Own resolution of incidents within your sphere of responsibility, escalating with a clear picture of what you found, not just what triggered the alert.
- Drive root cause analysis and post-incident reviews, and turn findings into runbooks, fixes, or upstream design changes.
- Participate in on-call rotation using PagerDuty, with clear escalation paths across the engineering team.
Field & Platform Collaboration
- Work closely with forward deployed engineers on-site at customer facilities, sharing context in both directions so field reality and platform design stay connected.
- Turn operational observations, data source opportunities, and recurring patterns from the field into platform capabilities rather than one-off fixes.
Must Have
- 5+ years of experience in data engineering, or software engineering with a substantial data infrastructure focus.
- Expert Python skills, with a track record of designing and maintaining production-grade codebases that other engineers extend and depend on.
- Hands-on experience building and operating ETL/ELT pipelines with Spark (PySpark), ideally as AWS Glue jobs.
- Strong SQL and schema design skills, including the ability to analyze access patterns and make sound partitioning and indexing decisions.
- Experience with column-oriented analytical databases (example technologies: ClickHouse, Redshift, BigQuery).
- Experience debugging production data systems: reading logs, tracing failures across components, and root-causing issues under time pressure.
- Demonstrated ability to work independently on production systems, including sound judgment about when to decide and when to escalate.
- Ability to work on-site full-time at Twenty's New York City office, with an initial onboarding period at our Arlington, VA office and occasional travel there afterward.
Nice To Have
- Experience with data lake and large-scale query technologies (example technologies: Apache Iceberg, Delta Lake, Trino, Presto, Athena).
- Experience with streaming and message queue technologies (example technologies: Kafka, NATS, Kinesis, RabbitMQ).
- Hands-on experience with observability tooling (Grafana, Datadog, Splunk, or similar).
- Experience deploying and operating software in air-gapped, classified, or otherwise restricted environments.
- Familiarity with containerized environments (Docker and container orchestration) and CI/CD concepts.
Tech Environment (You Might Work With)
- Cloud: AWS (EC2, ECS, RDS, CloudWatch), including deployments into closed enclave environments
- Data processing: AWS Glue jobs running PySpark
- Analytics: ClickHouse, with ClickPipes for ingestion
- Containers: Docker, orchestrated on Amazon ECS
- Observability: Grafana, Loki, Tempo, Mimir (LGTM stack)
- Alerting / on-call: PagerDuty
- Messaging: NATS
- Databases: PostgreSQL
- Data integration: Twenty's purpose-built data platform and integration layer (in active development)
- Languages in use across engineering: Go, TypeScript, Python
Security / Work Environment
This role requires U.S. citizenship and eligibility to obtain a U.S. Government security clearance; no active clearance is required to start. Work is performed at Twenty's New York City office. Onboarding begins with a stint of roughly two weeks at Twenty's Arlington, VA office, and travel to Arlington after that is occasional and as needed. Some of the systems this role builds for are restricted, and tooling constraints apply when working with them.
Benefits
What's on the table:
- Health. Medical, dental, and vision plan options. Life / AD&D, disability coverage options.
- Family. Paid parental leave for eligible full-time employees. 12 weeks for birthing parents, 4 for non-birthing parents, 6 weeks for adoptive, foster, or intended parents through surrogacy.
- Vacation. Paid holidays and flexible PTO. Take what you need.
- Retirement. 401(k) with pre-tax and Roth options. HSA/FSA options, dependent care FSA.
Benefits vary by location, role, and eligibility. Full plan details provided during the interview and offer process.
If this role sounds like you, apply and share with us your interest
Due to U.S. government contract and security requirements,
this role is limited to U.S. citizens. Some positions may also require eligibility to obtain and maintain a U.S. Government security clearance. Any active clearance requirement
will be listed in the role description.
Twenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status, consistent with applicable law.
If you need a reasonable accommodation during the hiring process, let us know and we will work with you.