Twenty

Senior/Staff DevSecOps Engineer

Twenty
Apply
16 hours ago
New York, NY, USASenior / Staff+

Base Salary

$159k - $263k/yr

Responsibilities

  • Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
  • Design and enforce least-privilege identity and access management across AWS and internal systems.
  • Own secrets and credentials management, including policies, tooling, rotation, and developer workflows.
  • Lead security incident response, including detection, containment, root cause analysis, post-mortems, and durable remediation.
  • Manage AWS Organizations, account boundaries, service control policies, and security guardrails.
  • Harden CI/CD pipelines by embedding security scanning and policy enforcement into software delivery.
  • Drive compliance programs by owning evidence, controls, and remediation work.
  • Build secure-by-default repository, pipeline, and infrastructure templates.
  • Automate certificate issuance, secrets access, policy-as-code, and developer-facing security tooling.
  • Provide practical security guidance and shape the DSO function as it scales, including contributing to hiring and team building.

Requirements

  • 8+ years of experience in DevSecOps, platform security, or a closely related security engineering role.
  • Deep hands-on AWS experience, including IAM, SCPs, Organizations, GuardDuty, Security Hub, and CloudTrail.
  • Strong Terraform and infrastructure-as-code experience, including security controls and policy-as-code or continuous compliance tooling such as OPA, Checkov, tfsec, or AWS Config Rules.
  • End-to-end production experience owning secrets management.
  • Experience designing and hardening CI/CD pipelines, including GitHub Actions.
  • Hands-on container security experience, including image scanning and runtime controls.
  • Experience leading or meaningfully contributing to a compliance program; CMMC Level 2 or NIST SP 800-171 experience is strongly preferred.
  • Experience running incident response, participating in on-call operations, leading post-mortems, and shipping remediation.
  • Strong communication, judgment, ownership, and ability to drive security adoption through enablement.
  • Experience growing a DSO or security engineering function, configuration management experience with Ansible or similar, familiarity with observability tooling, and experience building developer-facing security platforms are preferred.
  • U.S. citizenship and eligibility to obtain and maintain a U.S. Government security clearance are required.

Benefits

  • Onsite, full-time role in a controlled work environment.
  • Medical, dental, vision, life, AD&D, and disability plan options.
  • Paid parental leave, including 12 weeks for birthing parents, 4 weeks for non-birthing parents, and 6 weeks for adoptive, foster, or intended parents through surrogacy.
  • Paid holidays and flexible PTO.
  • 401(k) pre-tax and Roth options, HSA/FSA options, and dependent care FSA.

Tech Stack

AnsibleAWSDockerGitHub ActionsGoGrafanaNode.jsPythonReactSAP Cloud PlatformTerraformTypeScript

Categories

Twenty

About Twenty

51-200 employees
Contact me