Twenty

Senior / Staff DevSecOps Engineer

Twenty
Apply
16 hours ago
Arlington, VA, USASenior / Staff+

Base Salary

$159k - $263k/yr

Responsibilities

  • Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
  • Design and enforce least-privilege identity and access management across AWS and internal systems.
  • Own secrets and credentials management, including policies, tooling, rotation, and developer workflows.
  • Lead security incident response through detection, containment, root cause analysis, and durable remediation.
  • Manage AWS Organizations, account boundaries, service control policies, and security guardrails.
  • Harden CI/CD pipelines by embedding security scanning and policy enforcement into software delivery.
  • Drive compliance programs, including evidence collection, controls, and remediation work.
  • Build secure-by-default repository, pipeline, and infrastructure templates.
  • Automate certificate issuance, secrets access, policy-as-code, and developer-facing security tooling.
  • Create practical security guidance and shape the DevSecOps function as it scales, including contributing to hiring and team-building.

Requirements

  • 8+ years of experience in DevSecOps, platform security, or a closely related security engineering role.
  • Deep hands-on AWS experience with IAM, SCPs, Organizations, GuardDuty, Security Hub, CloudTrail, and related security services.
  • Strong Terraform experience for enforcing security controls, plus policy-as-code or continuous compliance tooling such as OPA, Checkov, tfsec, or AWS Config Rules.
  • End-to-end production experience owning secrets management.
  • Experience designing and hardening CI/CD pipelines, including GitHub Actions.
  • Hands-on container security experience, including image scanning and runtime controls.
  • Experience leading or substantially contributing to a compliance program; CMMC Level 2 or NIST SP 800-171 experience is strongly preferred.
  • Experience running incident response, participating in on-call operations, leading post-mortems, and shipping remediation.
  • Strong communication skills and the ability to drive security adoption through enablement.
  • Experience growing a DevSecOps or security engineering function, familiarity with observability tooling and the LGTM stack, Ansible or similar configuration management experience, and developer-facing security platform experience are preferred.
  • U.S. citizenship is required, and the candidate must be eligible to obtain and maintain a U.S. Government security clearance.

Benefits

  • Medical, dental, and vision plan options, plus life/AD&D and disability coverage options.
  • Paid parental leave for eligible full-time employees, including 12 weeks for birthing parents, 4 weeks for non-birthing parents, and 6 weeks for adoptive, foster, or intended parents through surrogacy.
  • Paid holidays and flexible PTO.
  • 401(k) with pre-tax and Roth options, HSA/FSA options, and dependent care FSA.
  • Full-time, onsite role in Arlington, Virginia; benefits vary by location, role, and eligibility.

Tech Stack

Categories

Twenty

About Twenty

51-200 employees
Contact me