Twenty is a cyber warfare startup that builds AI-enabled, end-to-end offensive cyber systems for the U.S. military and the Intelligence Community.
ABOUT THE COMPANY America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned—correctly—that those attacks rarely produce consequences. Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace—a future where they cannot contest us, deterrence is assured, and the free world remains secure. Founded in 2024, Twenty Technologies (www.twenty.io http://www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel. ROLE SUMMARY You'll be based in Twenty's New York City office, building and operating the data integrations that feed Twenty's mission-critical platform. Twenty builds software for cyber operations, and the applications this role feeds are used by operators and analysts working against hard national security problems. This is a hands-on engineering role with real production ownership: you'll build the pipelines that retrieve, process, and integrate new data sources into our applications, monitor the health of the data flowing through the systems you can reach, and debug production issues when they surface. Where your work runs in environments you can't access, you'll partner with Twenty's forward deployed engineers, who operate on-site at customer facilities, to get it deployed and keep it healthy. You'll join the data platform team, reporting to its engineering manager. The data integration tooling you'll build on is young and under active development. You'll be among its first production users, and what you learn in operation will directly shape how it evolves. If you're an experienced data engineer who wants your work in the hands of operators the same week you build it, and you'd rather own a production system end to end than ship features into a backlog, this role is for you. WHO YOU ARE - You independently identify the right solution to ambiguous, open-ended problems. New data sources arrive undocumented and messy; you investigate, form a design, and deliver without waiting for a spec. - You respond with urgency to operational issues and own resolution within your sphere. You're unafraid to call an incident when the signal warrants it. - You proactively create and update runbooks and documentation for the components you own. Some of the environments your code runs in are ones you'll never touch, and what you write down is what the engineers there have to work with. - You make informed decisions by consulting the right stakeholders and balancing detail with the big picture, and you execute against the spirit of the requirement, not just the letter. - You actively seek out and eliminate sources of toil. Repetitive manual work is a design problem, and you treat it like one. - You understand the customer and the mission well enough to know which work has the greatest impact, and you redirect your focus when what you're doing isn't moving the needle. - You tailor your communication to your audience, whether that's a forward deployed engineer at a customer site, a product engineer in Arlington, or a teammate across the desk, and you proactively share information so the right people stay informed and aligned. - You're comfortable building for restricted environments where deployment is gated, feedback loops are longer than you'd like, and disciplined engineering practice is the price of admission. WHAT YOU'LL DO DATA SOURCE INTEGRATION & PIPELINE DEVELOPMENT - Design and build data pipelines that retrieve, parse, transform, and load new data sources into Twenty's applications, primarily as AWS Glue jobs written in PySpark. - Investigate unfamiliar source systems and data formats, working with Twenty's engineers to understand semantics, access patterns, and constraints before writing code. - Design schemas and data models that fit the platform's performance characteristics and the shape of the data, including analytical models in ClickHouse. - Write code that is testable, debuggable, and maintainable by engineers operating it in environments you can't access. Tests carry unusual weight here: they're how the field trusts a change you'll never see run. - Write integration code that meets the security standards of classified environments: no hardcoded secrets, disciplined credential handling, and audit-ready practices throughout, so your work moves through customer approval processes without friction. DEPLOYMENT & FIELD SUPPORT - Deploy, operate, and iterate on integrations against the systems reachable from the office, end to end. - Package pipelines and integrations destined for restricted environments so forward deployed engineers and customer deployment teams can install, verify, and operate them without you in the room. - Support field deployments remotely: reproduce issues, cut fixes, and move them through the pipeline quickly when an on-site engineer is blocked. - Operate and improve pipelines built elsewhere on the team, and feed operational learnings back into their design. PRODUCTION HEALTH & MONITORING - Monitor the health of data pipelines and platform services using the LGTM stack (Grafana, Loki, Tempo, Mimir). - Track data quality, throughput, and freshness; identify anomalies and degradations before they become incidents. - Build and improve the dashboards and alerts that make pipeline health visible to the team and to the forward deployed engineers who depend on it. INCIDENT RESPONSE & DEBUGGING - Diagnose and resolve production issues in the data path: failed ingests, malformed source data, pipeline stalls, performance degradation. - Own resolution of incidents within your sphere of res