Twenty is a cyber warfare startup that builds AI-enabled, end-to-end offensive cyber systems for the U.S. military and the Intelligence Community.
ABOUT THE COMPANY America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned—correctly—that those attacks rarely produce consequences. Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace—a future where they cannot contest us, deterrence is assured, and the free world remains secure. Founded in 2024, Twenty Technologies (www.twenty.io http://www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel. Twenty is seeking an exceptionally skilled Offensive Cyber Research Engineer for an in-office position in its Arlington, VA office to lead the development of sophisticated offensive cyber capabilities that defend democracies worldwide. We're looking for someone with 6-8 years of deep technical expertise in offensive cyber operations, software development, and research, combined with proven leadership experience mentoring engineers and driving strategic technical initiatives. In this role, you'll architect and lead the development of advanced attack path frameworks, establish engineering best practices for offensive tooling, mentor junior researchers, and serve as a technical authority on adversarial techniques and red team operations. You'll leverage your extensive operational background—ideally from government/military Digital Network Exploitation Analysis (DNEA), Exploitation Analyst (EA) operations, advanced penetration testing, or threat intelligence analysis—to shape the technical direction of our offensive cyber capabilities and build the next generation of cyber technologies for the United States and its allies. ROLE DETAILS TECHNICAL LEADERSHIP & ARCHITECTURE - Lead the architecture and design of sophisticated attack path frameworks that emulate advanced persistent threat (APT) behaviors and nation-state TTPs - Establish technical standards and best practices for offensive cyber tool development across the organization - Evaluate and recommend engineering courses of action for new offensive capabilities and system enhancements - Drive technical decision-making for complex offensive cyber integrations and performance optimizations - Architect scalable, modular frameworks for attack technique automation and adversary emulation RESEARCH & INNOVATION - Conduct advanced research into emerging adversary techniques, zero-day exploitation strategies, and novel attack vectors - Develop proof-of-concept tools and techniques that push the boundaries of offensive cyber capabilities - Stay current with threat actor innovations and translate emerging TTPs into defensive and offensive capabilities - Publish internal research findings and contribute to the broader cyber security research community - Identify capability gaps and lead initiatives to develop new offensive tools and methodologies TEAM LEADERSHIP & MENTORSHIP - Mentor and provide technical guidance to offensive cyber engineers and researchers, conducting thorough code reviews and knowledge transfer - Lead technical discussions and facilitate strategic planning sessions for offensive capability development - Organize research efforts and coordinate cross-functional collaboration with data engineering, backend, and intelligence analysis teams - Establish and maintain engineering best practices, secure coding standards, and operational security procedures - Guide junior engineers in understanding complex adversary behaviors and translating them into technical implementations ATTACK PATH DEVELOPMENT & IMPLEMENTATION - Design and implement advanced attack paths that emulate sophisticated adversary campaigns across multiple domains - Create reusable, production-grade components for complex attack techniques including credential harvesting, lateral movement, and defense evasion - Develop custom tooling and automation frameworks that operate at machine speed for large-scale adversary emulation DATA ENGINEERING & INTELLIGENCE INTEGRATION - Lead the design of ETL pipelines for processing threat intelligence, security logs, and operational data at scale - Architect standardized schemas for cyber operations datasets that support graph-based analysis and AI/ML workflows - Implement advanced data enrichment pipelines that integrate diverse threat intelligence sources - Design efficient storage and retrieval systems for large-scale security-relevant data OPERATIONAL COLLABORATION - Work closely with government customers and operational teams to understand mission requirements and capability gaps - Translate operational feedback into technical requirements and development priorities - Lead technical demonstrations showcasing offensive cyber capabilities to stakeholders - Provide subject matter expertise for customer engagements and strategic planning sessions QUALIFICATIONS TECHNICAL SKILLS & EXPERIENCE - 6-8 years of threat research, offensive cyber operations, and software development experience - Expert-level operational cyber security experience in one or more of the following domains: - Digital Network Exploitation Analysis (DNEA) within U.S. Government military or intelligence organizations - Exploitation Analyst (EA) operations conducting advanced network exploitation and intelligence analysis - Advanced Penetration Testing/Red Teaming leading sophisticated offensive security assessments - Senior-level Threat Hunting and threat intelligence analysis in high-stakes environments - Demonstrated technical leadership experience mentoring offensive cyber engineers and leading research initiatives - Deep expertise i