Startups

Senior / Staff DevSecOps Engineer

Twenty · Arlington, VA · On-site

← All jobs
About Twenty

The #1 Open Source CRM for modern teams. Modular, scalable, and built to fit your business. Backed by Y Combinator.

About the role

Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking. Design and enforce identity and access management (IAM) across AWS and internal systems — least-privilege by default.

What they're looking for

  • You believe security should be a force multiplier for engineering, not a gatekeeper
  • You take ownership end-to-end: from identifying a risk to designing the control to shipping the fix
  • You bring high judgment to tradeoffs — you know when to enforce hard controls and when friction kills adoption
  • You communicate clearly with both engineers and non-technical stakeholders, and you translate risk into plain language
  • You prefer automation over policy: if an engineer has to do something manually to stay secure, you see that as a bug
  • You hold a high bar for reliability and auditability in the systems you build
More about this role

America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned—correctly—that those attacks rarely produce consequences.

Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace—a future where they cannot contest us, deterrence is assured, and the free world remains secure.

Founded in 2024, Twenty Technologies ( www.twenty.io ) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.

Mission | On Site | Full Time | U.S. Citizenship Required / No Active Clearance Required

You'll build and own the security infrastructure that keeps Twenty's engineering systems safe without slowing engineers down. This role spans runtime security, access control, secrets management, compliance, and CI/CD hardening — but it's equally about making security the path of least resistance. You'll embed...

Read the full posting on Twenty's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.