IT Security Engineer
Twenty — Open Source CRM
About the role
ABOUT THE COMPANY
America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned—correctly—that those attacks rarely produce consequences.
Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace—a future where they cannot contest us, deterrence is assured, and the free world remains secure.
Founded in 2024, Twenty Technologies (www.twenty.io http://www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.
ROLE SUMMARY
We are seeking IT Security Engineer to join our growing technology engineering team. This is a critical role that will establish and maintain our security infrastructure, protect our digital assets, and ensure compliance with industry standards. You will be responsible for implementing comprehensive security solutions across our network, systems, and applications, while working closely with our development and operations teams to embed security into our organizational culture.
RESPONSIBILITIES
- Design, implement, and maintain enterprise network security architecture, including firewalls, intrusion detection systems, VPNs, and DMZs.
- Develop and enforce security policies, standards and procedures across the organization.
- Conduct security assessments, vulnerability scans and penetration testing to identify and remediate security gaps.
- Monitor systems and networks 24/7 using security information and event management (SIEM) tools; investigate and respond to security incidents.
- Manage access controls, identity and access management (IAM), and multi-factor authentication (MFA) solutions.
- Establish and manage data loss prevention (DLP) and encryption protocols for sensitive data at rest and in transit.
- Perform security hardening of servers, workstations, and endpoints; manage patch management and system updates.
- Provide security awareness training and education to employees to foster a security-conscious culture.
- Conduct root cause analysis on security incidents and prepare incident response reports and recommendations.
- Ensure compliance with relevant regulations (CMMC, SOC 2, GDPR, PCI-DSS, or industry-specific standards as applicable).
REQUIREMENTS
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- 5+ years of professional IT security experience, with demonstrated expertise in at least two of the following domains: network security, systems security, or cybersecurity.
- Strong knowledge of TCP/IP, DNS, DHCP, and network protocols; experience with firewalls, proxies, and network segmentation.
- Hands-on experience with security tools such as Splunk, ELK Stack, Snort, Suricata, or similar SIEM and IDS/IPS platforms.
- Proficiency in systems security, including endpoint protection and vulnerability management.
- Experience with cloud security (AWS, Azure, or GCP) and containerized environments (Docker, Kubernetes).
- Understanding of common attack vectors and security frameworks (NIST, CIS Controls, OWASP Top 10).
- Excellent problem-solving skills with the ability to work independently and as part of a team.
- Strong communication skills to explain complex security concepts to non-technical stakeholders.
NICE-TO-HAVES
- Security certifications such as CISSP, CISM, CEH, CCNA Security, Security+, or similar.
- Experience with security automation and Infrastructure as Code (Terraform, Ansible).
- Knowledge of application security testing (SAST/DAST) and secure development practices.
- Experience with incident response and forensics investigations.
- Familiarity with compliance frameworks and audit processes.
Benefits
What's on the table:
- Health. Medical, dental, and vision plan options. Life / AD&D, disability coverage options.
- Family. Paid parental leave for eligible full-time employees. 12 weeks for birthing parents, 4 for non-birthing parents, 6 weeks for adoptive, foster, or intended parents through surrogacy.
- Vacation. Paid holidays and flexible PTO. Take what you need.
- Retirement. 401(k) with pre-tax and Roth options. HSA/FSA options, dependent care FSA.
Benefits vary by location, role, and eligibility. Full plan details provided during the interview and offer process.
If this role sounds like you, apply and share with us your interest
Due to U.S. government contract and security requirements, this role is limited to U.S. citizens. Some positions may also require eligibility to obtain and maintain a U.S. Government security clearance. Any active clearance requirement will be listed in the role description.
Twenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status, consistent with applicable law.
If you need a reasonable accommodation during the hiring process, let us know and we will work with you.
What the index says about this role
- First seen by JobLarper — Aug 2, 2026, 5 days ago. Older postings collect hundreds of applicants — a tailored résumé matters more the longer a role has been live.
- What Security Engineer roles ask for — across 643 indexed openings: Cloud (45%), Python (41%), REST/APIs (40%), Go (31%), AI/LLM (29%). This posting names Cloud, REST/APIs.
- Twenty is hiring actively — 22 open roles indexed.
Derived from the 27,000 roles JobLarper indexes daily from official company boards — not from the job description above.
More open roles at Twenty
- Senior/Staff Forward Deployed Software Engineer - TS/SCI ClearedNational Capital Region | On Site · Senior+ · $192K – $455K • Multiple Ranges
- Dir, Software EngineeringWashington DC · Mid · $224K – $470K • Multiple Ranges
- Engineering Manager, Platform TeamWashington DC · Manager · $197K – $354K • Multiple Ranges
- DevOps EngineerArlington, VA · Mid · $130K – $184K • Multiple Ranges
- DevOps EngineerNew York, NY · Mid · $130K – $184K • Multiple Ranges
- Staff Data EngineerNew York, NY · Senior+ · $192K – $455K • Multiple Ranges
- Forward Deployed Site Reliability Engineer (TS/SCI Required)Arlington, VA · Mid · $192K – $455K • Multiple Ranges
- Forward Deployed Site Reliability EngineerFort Meade, MD · National Capital Region | On Site · Mid · $192K – $455K • Multiple Ranges
Similar Security Engineer roles at other companies
- Senior Product Security EngineerFunction Health · US - Remote · Canada - Remote · Remote
- Senior Security Engineer, Incident ResponseAirbnb · United States
- Staff Product Security EngineerChainguard · United States - Remote · Remote
- Security EngineerCognition · San Francisco
- Staff Security Engineer - IAMAledade · Austin, TX · Remote
- Endpoint Security EngineerSapphire Digital, Part of Zelis · India Hyderabad
- Senior Database Security EngineerAmerican Express · Phoenix, AZ, United States
- Data Security EngineerFiserv · Columbus, Ohio, United States of America
Browse all security engineer jobs in united states — 373 open roles across 191 companies.