IT Security Engineer

Twenty

Arlington (VA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health plan
Parental leave
Vacation
401(k) plan

Job summary

Twenty Technologies in Arlington, VA is seeking an IT Security Engineer to design and maintain our security infrastructure. You will protect digital assets, embed security into development, and enforce security policies across networks, systems, and applications.

You will conduct vulnerability assessments, monitor 24/7 with SIEM, manage IAM/MFA, and drive incident response. A bachelor’s degree and 5+ years in security are required, with cloud and container skills highly valued.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 5+ years of professional IT security experience with expertise in at least two domains (network, systems, or cybersecurity).
  • Strong knowledge of TCP/IP, DNS, DHCP, and network protocols; experience with firewalls, proxies, and network segmentation.
  • Hands‑on experience with security tools such as Splunk, ELK Stack, Snort, Suricata, or similar SIEM/IDS/IPS.
  • Proficiency in systems security, including endpoint protection and vulnerability management.
  • Experience with cloud security (AWS, Azure, or GCP) and containerized environments (Docker, Kubernetes).
  • Understanding of common attack vectors and security frameworks (NIST, CIS Controls, OWASP Top 10).
  • Excellent problem‑solving and communication skills.

Responsibilities

  • Design, implement, and maintain enterprise network security architecture (firewalls, IDS, VPNs, DMZs).
  • Develop and enforce security policies, standards and procedures across the organization.
  • Conduct security assessments, vulnerability scans and penetration testing.
  • Monitor systems and networks 24/7 using SIEM tools; investigate and respond to security incidents.
  • Manage access controls, IAM, and MFA solutions.
  • Establish and manage data loss prevention and encryption protocols.
  • Perform security hardening and patch management.
  • Provide security awareness training to employees.
  • Conduct root cause analysis on security incidents and prepare reports.

Skills

Network security
Systems security
Cybersecurity
Cloud security
Container security
IAM/MFA
Vulnerability management
SIEM usage

Education

Bachelor's degree in Computer Science or Information Security

Tools

Splunk
ELK Stack
Snort
Suricata
Docker
Kubernetes

Job description

About the Company

America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned—correctly—that those attacks rarely produce consequences.

Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace—a future where they cannot contest us, deterrence is assured, and the free world remains secure.

Founded in 2024, Twenty Technologies (www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $138M from Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In‑Q‑T el.

Role Summary

We are seeking IT Security Engineer to join our growing technology engineering team. This is a critical role that will establish and maintain our security infrastructure, protect our digital assets, and ensure compliance with industry standards. You will be responsible for implementing comprehensive security solutions across our network, systems, and applications, while working closely with our development and operations teams to embed security into our organizational culture.

Responsibilities
  • Design, implement, and maintain enterprise network security architecture, including firewalls, intrusion detection systems, VPNs, and DMZs.
  • Develop and enforce security policies, standards and procedures across the organization.
  • Conduct security assessments, vulnerability scans and penetration testing to identify and remediate security gaps.
  • Monitor systems and networks 24/7 using security information and event management (SIEM) tools; investigate and respond to security incidents.
  • Manage access controls, identity and access management (IAM), and multi‑factor authentication (MFA) solutions.
  • Establish and manage data loss prevention (DLP) and encryption protocols for sensitive data at rest and in transit.
  • Perform security hardening of servers, workstations, and endpoints; manage patch management and system updates.
  • Provide security awareness training and education to employees to foster a security‑conscious culture.
  • Conduct root cause analysis on security incidents and prepare incident response reports and recommendations.
  • Ensure compliance with relevant regulations (CMMC, SOC 2, GDPR, PCI‑DSS, or industry‑specific standards as applicable).
Requirements
  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
  • 5+ years of professional IT security experience, with demonstrated expertise in at least two of the following domains: network security, systems security, or cybersecurity.
  • Strong knowledge of TCP/IP, DNS, DHCP, and network protocols; experience with firewalls, proxies, and network segmentation.
  • Hands‑on experience with security tools such as Splunk, ELK Stack, Snort, Suricata, or similar SIEM and IDS/IPS platforms.
  • Proficiency in systems security, including endpoint protection and vulnerability management.
  • Experience with cloud security (AWS, Azure, or GCP) and containerized environments (Docker, Kubernetes).
  • Understanding of common attack vectors and security frameworks (NIST, CIS Controls, OWASP Top 10).
  • Excellent problem‑solving skills with the ability to work independently and as part of a team.
  • Strong communication skills to explain complex security concepts to non‑technical stakeholders.
Nice-to-haves
  • Security certifications such as CISSP, CISM, CEH, CCNA Security, Security+, or similar.
  • Experience with security automation and Infrastructure as Code (Terraform, Ansible).
  • Knowledge of application security testing (SAST/DAST) and secure development practices.
  • Experience with incident response and forensics investigations.
  • Familiarity with compliance frameworks and audit processes.
Benefits

What's on the table:

  • Health. Medical, dental, and vision plan options. Life / AD&D, disability coverage options.
  • Family. Paid parental leave for eligible full‑time employees. 12 weeks for birthing parents, 4 for non‑birthing parents, 6 weeks for adoptive, foster, or intended parents through surrogacy.
  • Vacation. Paid holidays and flexible PTO. Take what you need.
  • Retirement. 401(k) with pre‑tax and Roth options. HSA/FSA options, dependent care FSA.

Benefits vary by location, role, and eligibility. Full plan details provided during the interview and offer process.

If this role sounds like you, apply and share with us your interest

Due to U.S. government contract and security requirements, this role is limited to U.S. citizens. Some positions may also require eligibility to obtain and maintain a U.S. Government security clearance. Any active clearance requirement will be listed in the role description.

Twenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status, consistent with applicable law.

If you need a reasonable accommodation during the hiring process, let us know and we will work with you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer
IT Security Engineer

Twenty Technologies • Arlington (TX)

On-site
USD 120,000 - 170,000
Health benefits
Parental leave
Vacation
+1
Senior / Staff DevSecOps Engineer
Senior / Staff DevSecOps Engineer

Twenty Technologies • Arlington (TX)

On-site
DevOps Engineer
DevOps Engineer

Twenty Technologies • Arlington (TX)

On-site
Lead Offensive Cyber Research & Strategy Architect
Lead Offensive Cyber Research & Strategy Architect

Twenty Technologies • Washington

On-site
Principal Offensive Cyber Research Engineer
Principal Offensive Cyber Research Engineer

Twenty Technologies • Washington

On-site
Senior DevSecOps Engineer - Secure-by-Design Cloud & CI/CD
Senior DevSecOps Engineer - Secure-by-Design Cloud & CI/CD

Twenty Technologies • Arlington (TX)

On-site
Cloud Infra & Reliability DevOps Engineer
Cloud Infra & Reliability DevOps Engineer

Twenty Technologies • New York (NY)

On-site
Dir, Software Engineering
Dir, Software Engineering

Twenty • Washington

On-site
USD 180,000 - 260,000
Health insurance
Parental leave
Holiday time
+1
DevOps Engineer
DevOps Engineer

Twenty Technologies • New York (NY)

On-site
Senior Forward-Deployed Cyber Ops & Intelligence Lead
Senior Forward-Deployed Cyber Ops & Intelligence Lead

Twenty Technologies • San Antonio (TX)

On-site