Skip to content

Open nowPosted 5 days ago

Senior/Staff DevSecOps Engineer

Twenty37 open roles

Pay
$159,000 – $263,000 a year
Where
New York, NY
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior/Staff DevSecOps EngineerTwenty · New York, NY
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Twenty's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Twenty postings stay open a median of 43 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 5 days ago

Twenty median: 43 days open

The posting

ABOUT THE COMPANY

America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned—correctly—that those attacks rarely produce consequences.

Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace—a future where they cannot contest us, deterrence is assured, and the free world remains secure.

Founded in 2024, Twenty Technologies (www.twenty.io http://www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.

Mission | On Site | Full Time | U.S. Citizenship Required / No Active Clearance Required

ROLE SUMMARY

You'll build and own the security infrastructure that keeps Twenty's engineering systems safe without slowing engineers down. This role spans runtime security, access control, secrets management, compliance, and CI/CD hardening — but it's equally about making security the path of least resistance. You'll embed with our engineering teams, design secure-by-default foundations, and build the tooling and automation that lets developers move fast without cutting corners. You'll report directly to the VP of Engineering and operate as a shared function across our product teams.

WHAT YOU'LL DO

- Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.

- Design and enforce identity and access management (IAM) across AWS and internal systems — least-privilege by default.

- Own secrets and credentials management: policies, tooling, rotation, and developer workflows that make doing the right thing easy.

- Lead security incident response: detection, containment, root cause analysis, and durable remediation.

- Manage AWS Organization structure, account boundaries, SCPs, and guardrails.

- Harden and maintain CI/CD pipelines, embedding security scanning and policy enforcement into the software delivery lifecycle.

- Drive compliance efforts — own the evidence, controls, and remediation work to meet and maintain relevant frameworks.

- Build and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.

- Reduce friction through automation: certificate issuance, secrets access, policy-as-code, and developer-facing tooling.

- Produce lightweight, practical security guidance that engineers actually use.

- Shape the direction of the DSO function as it scales, and contribute to hiring and team-building as we grow.

WHO YOU ARE

- You believe security should be a force multiplier for engineering, not a gatekeeper.

- You take ownership end-to-end: from identifying a risk to designing the control to shipping the fix.

- You bring high judgment to tradeoffs — you know when to enforce hard controls and when friction kills adoption.

- You communicate clearly with both engineers and non-technical stakeholders, and you translate risk into plain language.

- You prefer automation over policy: if an engineer has to do something manually to stay secure, you see that as a bug.

- You hold a high bar for reliability and auditability in the systems you build.

- You're self-directed and thrive in an environment where the function is new and you're defining it.

MUST HAVE

- 8+ years in DevSecOps, platform security, or a closely related security engineering role.

- Deep hands-on experience with AWS — IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail, etc.).

- Strong IaC experience with Terraform; you've used it to enforce security controls, not just provision infrastructure — and you've layered in policy-as-code tooling (e.g., OPA, Checkov, tfsec) or continuous compliance checks (e.g., AWS Config Rules) to catch drift and misconfigurations.

- Experience owning secrets management end-to-end in a production engineering environment.

- Proven track record designing and hardening CI/CD pipelines (we use GitHub Actions).

- Hands-on experience with container security, including image scanning and runtime controls.

- Experience leading or meaningfully contributing to a compliance program; CMMC Level 2 (or NIST SP 800-171) experience strongly preferred.

- You've run incident response — you've been on call, you've led the post-mortem, and you've shipped the fix.

- Strong communication skills and the ability to drive security adoption through enablement, not mandates.

NICE TO HAVE

- Experience growing a DSO or security engineering function — expanding scope, tooling, and team.

- Familiarity with observability tooling and using it for security signal (we use the LGTM stack).

- Background in configuration management tooling (Ansible or similar).

- Experience with developer-facing security platforms or internal tooling that improved engineering workflows.

- Interest in growing into a lead or manager role as the team scales.

TECH ENVIRONMENT (YOU MIGHT WORK WITH)

- Cloud: AWS (primary), Terraform for IaC, Ansible for configuration management

- Containers: Docker, Docker Compose

- CI/CD: GitHub Actions

- Vulnerability scanning: Trivy

- Observability: Grafana, Loki, Tempo, Mimir (LGTM stack)

- Alerting / on-call: PagerDuty

- Languages in use across engineering: Go, TypeScript/Node, React, Python

SECURITY / WORK ENVIRONMENT

This role requires eligibility to obtain and maintain a U.S. Government security clearance. This role may involve work in a controlled environment.

Benefits What's on the table:

- Health. Medical, dental, and vision plan options. Life / AD&D, disability coverage options.

- Family. Paid parental leave for eligible full-time employees. 12 weeks for birthing parents, 4 for non-birthing parents, 6 weeks for adoptive, foster, or intended parents through surrogacy.

- Vacation. Paid holidays and flexible PTO. Take what you need.

- Retirement. 401(k) with pre-tax and Roth options. HSA/FSA options, dependent care FSA.

Benefits vary by location, role, and eligibility. Full plan details provided during the interview and offer process.

If this role sounds like you, apply and share with us your interest

Due to U.S. government contract and security requirements, this role is limited to U.S. citizens. Some positions may also require eligibility to obtain and maintain a U.S. Government security clearance. Any active clearance requirement will be listed in the role description.

Twenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status, consistent with applicable law.

If you need a reasonable accommodation during the hiring process, let us know and we will work with you.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Twenty's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Twenty's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Twenty's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.