Senior / Staff DevSecOps Engineer

Twenty

Arlington (VA)

Sur place

USD 120 000 - 160 000

Plein temps

14 jours+
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV et une lettre de motivation personnalisés en environ une minute.

Passez les filtres ATS

Résumé du poste

A leading cybersecurity firm in Arlington, VA, is looking for a DevSecOps engineer to build and manage essential security infrastructure. The role involves addressing cloud and container security, incident response, and fostering security practices within engineering teams. Ideal candidates should have over 8 years of experience in security engineering, particularly with AWS and CI/CD pipeline security. This position promotes both collaboration and automation to enhance security practices while ensuring agility in development cycles.

Qualifications

  • 8+ years in DevSecOps, platform security, or a closely related security engineering role.
  • Deep hands-on experience with AWS and security services.
  • Strong IaC experience with Terraform, using it for security controls.

Responsabilités

  • Own runtime security and vulnerability management across cloud and container environments.
  • Design and enforce identity and access management (IAM) across AWS.
  • Lead security incident response, including detection and remediation.

Connaissances

DevSecOps experience
AWS knowledge
IaC with Terraform
Container security
Incident response experience
Communication skills

Outils

Terraform
Docker
GitHub Actions
Trivy
Grafana

Description du poste

About the Company

At Twenty, we're taking on one of the most critical challenges of our time: defending democracies in the digital age. We develop revolutionary technologies that operate at the intersection of the cyber and electromagnetic domains, where the speed of operations exceeds human sensing and complexity transcends conventional boundaries. Our team doesn't just solve problems – we deliver game-changing outcomes that directly impact national security. We're pragmatic optimists who understand that while our mission of protecting America and its allies is challenging, success is possible.

Role Summary

You'll build and own the security infrastructure that keeps Twenty's engineering systems safe without slowing engineers down. This role spans runtime security, access control, secrets management, compliance, and CI/CD hardening — but it's equally about making security the path of least resistance. You'll embed with our engineering teams, design secure-by-default foundations, and build the tooling and automation that lets developers move fast without cutting corners. You'll report directly to the VP of Engineering and operate as a shared function across our product teams.

Who You Are
  • You believe security should be a force multiplier for engineering, not a gatekeeper.
  • You take ownership end-to-end: from identifying a risk to designing the control to shipping the fix.
  • You bring high judgment to tradeoffs — you know when to enforce hard controls and when friction kills adoption.
  • You communicate clearly with both engineers and non-technical stakeholders, and you translate risk into plain language.
  • You prefer automation over policy: if an engineer has to do something manually to stay secure, you see that as a bug.
  • You hold a high bar for reliability and auditability in the systems you build.
  • You're self-directed and thrive in an environment where the function is new and you're defining it.
What You'll Do
  • Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
  • Design and enforce identity and access management (IAM) across AWS and internal systems — least-privilege by default.
  • Own secrets and credentials management: policies, tooling, rotation, and developer workflows that make doing the right thing easy.
  • Lead security incident response: detection, containment, root cause analysis, and durable remediation.
  • Manage AWS Organization structure, account boundaries, SCPs, and guardrails.
  • Harden and maintain CI/CD pipelines, embedding security scanning and policy enforcement into the software delivery lifecycle.
  • Drive compliance efforts — own the evidence, controls, and remediation work to meet and maintain relevant frameworks.
  • Build and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.
  • Reduce friction through automation: certificate issuance, secrets access, policy-as-code, and developer-facing tooling.
  • Produce lightweight, practical security guidance that engineers actually use.
  • Shape the direction of the DSO function as it scales, and contribute to hiring and team-building as we grow.
Must Have
  • 8+ years in DevSecOps, platform security, or a closely related security engineering role.
  • Deep hands-on experience with AWS — IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail, etc.).
  • Strong IaC experience with Terraform; you've used it to enforce security controls, not just provision infrastructure — and you've layered in policy-as-code tooling (e.g., OPA, Checkov, tfsec) or continuous compliance checks (e.g., AWS Config Rules) to catch drift and misconfigurations.
  • Experience owning secrets management end-to-end in a production engineering environment.
  • Proven track record designing and hardening CI/CD pipelines (we use GitHub Actions).
  • Hands‑on experience with container security, including image scanning and runtime controls.
  • Experience leading or meaningfully contributing to a compliance program; CMMC Level 2 (or NIST SP 800‑171) experience strongly preferred.
  • You've run incident response — you've been on call, you've led the post‑mortem, and you've shipped the fix.
  • Strong communication skills and the ability to drive security adoption through enablement, not mandates.
Nice To Have
  • Experience growing a DSO or security engineering function — expanding scope, tooling, and team.
  • Familiarity with observability tooling and using it for security signal (we use the LGTM stack).
  • Background in configuration management tooling (Ansible or similar).
  • Experience with developer‑facing security platforms or internal tooling that improved engineering workflows.
  • Interest in growing into a lead or manager role as the team scales.
Tech Environment (You Might Work With)
  • Cloud: AWS (primary), Terraform for IaC, Ansible for configuration management
  • Containers: Docker, Docker Compose
  • CI/CD: GitHub Actions
  • Vulnerability scanning: Trivy
  • Observability: Grafana, Loki, Tempo, Mimir (LGTM stack)
  • Alerting / on‑call: PagerDuty
  • Languages in use across engineering: Go, TypeScript/Node, React, Python
Security / Work Environment

This role requires eligibility to obtain and maintain a U.S. Government security clearance. This role may involve work in a controlled environment.

Some positions may require eligibility to obtain a U.S. Government security clearance. Any clearance requirement will be listed in the role description.

Twenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status.

If you need a reasonable accommodation during the hiring process, let us know and we will work with you.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior/Staff DevSecOps Engineer
Senior/Staff DevSecOps Engineer

twenty • New York (NY)

Sur place
USD 180 000 - 240 000
Health insurance
Family benefits (parential leave)
Paid vacation & holidays
+1
Senior/Staff DevSecOps Engineer
Senior/Staff DevSecOps Engineer

Twenty Technologies • New York (NY)

Sur place
USD 180 000 - 230 000
Health insurance
Paid parental leave
Paid holidays and flexible PTO
+1
Senior / Staff DevSecOps Engineer
Senior / Staff DevSecOps Engineer

Twenty Technologies • Arlington (TX)

Sur place
USD 140 000 - 180 000
Health, dental, and vision options
401(k) matching
Paid time off
+1
Senior DevSecOps Engineer - Secure-by-Design Cloud & CI/CD
Senior DevSecOps Engineer - Secure-by-Design Cloud & CI/CD

Twenty Technologies • Arlington (TX)

Sur place
USD 140 000 - 180 000
Senior Manager, Cloud Platform and Security
Senior Manager, Cloud Platform and Security

Twenty Technologies • Virginia

Sur place
USD 180 000 - 280 000
Health coverage
Paid parental leave
Paid holidays
+1
IT Security Engineer
IT Security Engineer

Twenty Technologies • Arlington (TX)

Sur place
USD 120 000 - 170 000
Health benefits
Parental leave
Vacation
+1
Senior/Staff DevOps Engineer
Senior/Staff DevOps Engineer

Twenty • Arlington (VA)

Sur place
USD 140 000 - 190 000
Health
Parental leave
Paid vacation
+1
Forward Deployed Site Reliability Engineer
Forward Deployed Site Reliability Engineer

Twenty Technologies • Fort Meade (FL)

Sur place
USD 150 000 - 190 000
Health insurance
401(k) plan
Paid time off
+1
Forward Deployed Site Reliability Engineer
Forward Deployed Site Reliability Engineer

Twenty • Fort Meade (MD)

Sur place
USD 100 000 - 130 000
IT Security Engineer
IT Security Engineer

Twenty • Arlington (VA)

Sur place
USD 120 000 - 180 000
Health plan
Parental leave
Vacation
+1