Twenty

Offensive Cyber Research Engineer

Twenty
Apply
11 months ago
Arlington, VA, USASenior

Base Salary

$159k - $263k/yr

Responsibilities

  • Lead architecture and development of attack-path frameworks that emulate advanced persistent threat behaviors and nation-state tactics, techniques, and procedures.
  • Research emerging adversary techniques, zero-day exploitation strategies, novel attack vectors, and offensive cyber methodologies.
  • Develop production-grade tools, payloads, modules, automation frameworks, and reusable components for credential harvesting, lateral movement, defense evasion, and adversary emulation.
  • Establish engineering standards, secure coding practices, operational security procedures, and technical best practices for offensive tooling.
  • Mentor offensive cyber engineers and researchers, conduct code reviews, lead technical discussions, and guide junior engineers.
  • Lead ETL, data-enrichment, schema, graph-analysis, storage, and retrieval systems for threat intelligence, security logs, and operational data.
  • Collaborate with government customers, operational teams, data engineering, backend, and intelligence analysis teams to translate mission needs into technical priorities.
  • Provide technical demonstrations and subject-matter expertise for customer engagements and strategic planning.

Requirements

  • 6–8 years of threat research, offensive cyber operations, and software development experience.
  • Expert operational cybersecurity experience in DNEA, EA operations, advanced penetration testing/red teaming, or senior-level threat hunting and threat intelligence analysis.
  • Demonstrated technical leadership, mentoring, research leadership, code review, and technical decision-making experience.
  • Deep expertise with MITRE ATT&CK and advanced adversary TTP development across multiple tactics.
  • Expert experience with Cobalt Strike, Metasploit, custom command-and-control frameworks, custom payloads, modules, and evasion techniques.
  • Advanced proficiency in persistence mechanisms, defense evasion, counter-forensics, anti-analysis, payload development, post-exploitation, command-and-control infrastructure, and multi-stage attack chains.
  • Expert Docker and Kubernetes experience for secure, scalable offensive-tool deployment.
  • Advanced Python and Golang programming and software architecture experience.
  • Expert experience with graph queries and graph-based analytical tools using Neo4j or similar graph databases.
  • Comprehensive knowledge of network security, application security, secure coding, cryptography, and security architecture.
  • Bachelor's degree in computer science, software engineering, cybersecurity, or a related field, or equivalent practical experience; a master's degree is preferred.
  • Must be eligible to obtain a U.S. Government security clearance and must be a U.S. citizen.
  • Preferred qualifications include government cyber leadership, novel offensive-tool development, OSCP/OSCE/OSEE/GXPN or comparable certifications, AI/ML integration, malware analysis, reverse engineering, exploit development, vulnerability research, intelligence correlation, publications, open-source contributions, cloud security, wireless security, IoT protocols, forensics, incident response, and government acquisition experience.

Benefits

  • Medical, dental, vision, life/AD&D, and disability plan options.
  • Paid parental leave, including 12 weeks for birthing parents, 4 weeks for non-birthing parents, and 6 weeks for adoptive, foster, or intended parents through surrogacy.
  • Paid holidays and flexible paid time off.
  • 401(k) with pre-tax and Roth options, HSA/FSA options, and dependent care FSA.
  • In-office, full-time position in Arlington, Virginia; benefits vary by location, role, and eligibility.
Twenty

About Twenty

51-200 employees
Contact me