Staff Data Engineer - TS/SCI Cleared
About this role
About the Company
America is under sustained cyber attack. Our adversaries infiltrate our networks, steal our IP, and degrade the digital infrastructure that modern life runs on. They’ve learned—correctly—that those attacks rarely produce consequences.
Twenty was founded to change that, by making our adversaries think twice before they attack us. Our vision is American and allied primacy in cyberspace—a future where they cannot contest us, deterrence is assured, and the free world remains secure.
Founded in 2024, Twenty Technologies (www.twenty.io) industrializes offensive cyber operations for the U.S. and its allies. Headquartered in Arlington, Virginia, Twenty has raised $168M from Khosla Ventures, Accel, Caffeinated Capital, Friends & Family Capital, Point72 Ventures, General Catalyst, and In-Q-Tel.
Role Summary
You'll be on the ground at a government customer site in Northern Virginia, building and operating the data integrations that feed Twenty's mission-critical platform in a restricted, air-gapped environment. Twenty builds software for cyber operations, and the applications this role feeds are used by operators and analysts working against hard national security problems. This is a hands-on engineering role with real production ownership: you'll write software extensions that retrieve, process, and integrate new data sources into our applications, work with the customer's deployment team to get those extensions running on the high side, monitor the health of the data flowing through the system, and debug production issues where they happen. You'll report directly to the VP of Engineering. You'll be part of a small forward deployed team, working closely with other on-site engineers, the Arlington-based product engineering and DevSecOps teams, and the customer's own technical staff. The data integration tooling you'll build on is young and under active development. You'll be among its first production users, and what you learn in the field will directly shape how it evolves.
The office-based team can't see this system. You are the engineering presence where the software actually runs. That means the interesting problems land on you first, and the judgment calls about what's wrong, what's urgent, and what Arlington needs to know are yours to make.
If you're an experienced data engineer who wants your work in the hands of operators the same week you build it, and you'd rather own a production system end to end than ship features into a backlog, this role is for you.
Who You Are
You independently identify the right solution to ambiguous, open-ended problems. New data sources arrive undocumented and messy; you investigate, form a design, and deliver without waiting for a spec.
You respond with urgency to operational issues and own resolution within your sphere. You're unafraid to call an incident when the signal warrants it.
You proactively create and update runbooks and documentation for the components you own. In an environment the rest of the team can't access, what you write down is what they know.
You make informed decisions by consulting the right stakeholders and balancing detail with the big picture, and you execute against the spirit of the requirement, not just the letter.
You actively seek out and eliminate sources of toil. Repetitive manual work in a constrained environment is a design problem, and you treat it like one.
You understand the customer and the mission well enough to know which work has the greatest impact, and you redirect your focus when what you're doing isn't moving the needle.
You tailor your communication to your audience, whether that's a product engineer in Arlington, a DevSecOps teammate, or a non-technical customer stakeholder, and you proactively share information so the right people stay informed and aligned.
You're comfortable operating in secure environments where tooling is limited, internet access is not a given, and the stakes are real.
What You'll Do
Data Source Integration & Extension Development
Design and build software extensions that retrieve, parse, transform, and load new data sources into Twenty's applications.
Investigate unfamiliar source systems and data formats, working with customer stakeholders to understand semantics, access patterns, and constraints before writing code.
Design schemas and data models that fit the platform's performance characteristics and the shape of the data.
Write code that is testable, debuggable, and maintainable by engineers who can't access the environment it runs in. Tests carry unusual weight here: they're how Arlington trusts a change they'll never see run.
Write integration code that meets the security standards of classified environments: no hardcoded secrets, disciplined credential handling, and audit-ready practices throughout, so your work moves through the customer's approval process without friction.
Deployment & High-Side Operations
Work with the customer's deployment team to get extensions approved, deployed, and running in the high-side environment.
Work across low-side and high-side environments as customer policy allows, shepherding code through the customer's approval and deployment process into production.
Execute deployments and updates of data integration components in coordination with the customer deployment team and Arlington engineering.
Operate and maintain extensions built by the Arlington team, and feed operational learnings back into their design.
Apply validated changes within the enclave under the guidance of the Arlington engineering and DSO teams.
Production Health & Monitoring
Monitor the health of data pipelines and platform services on-site using the LGTM stack (Grafana, Loki, Tempo, Mimir).
Track data quality, throughput, and freshness; identify anomalies and degradations before they become incidents. In an air-gapped environment, efficiency compounds.
Build and improve the dashboards and alerts that make pipeline health visible, both on-site and to the Arlington team.
Incident Response & Debugging
Diagnose and resolve production issues in the data path: failed ingests, malformed source data, pipeline stalls, performance degradation.
Own resolution of incidents within your sphere of responsibility, escalating to Arlington with a clear picture of what you found, not just what triggered the alert.
Drive root cause analysis and post-incident reviews in partnership with the Arlington engineering team, and turn findings into runbooks, fixes, or upstream design changes.
Participate in on-call rotation using PagerDuty, with clear escalation paths to the engineering team. The environment is air-gapped, so off-hours incident response may require returning to the customer facility rather than remoting in.
Customer & Team Liaison
Serve as a consistent engineering presence for the government customer: professional, reliable, and clear under pressure.
Relay operational observations, data source opportunities, and customer feedback to the Arlington team accurately and promptly.
Work alongside other forward deployed engineers, sharing context and coverage across the on-site team.
Surface patterns from the field that should become platform capabilities, and advocate for them with the product engineering team.
Must Have
5+ years of experience in data engineering, or software engineering with a substantial data infrastructure focus.
Strong programming ability in Python or Go, with code quality good enough that remote teammates can review, extend, and trust it.
Hands-on experience building ETL/ELT pipelines (example technologies: Airflow, NiFi, AWS Glue, or equivalent custom pipeline development).
Strong SQL and schema design skills, including the ability to analyze access patterns and make sound partitioning and indexing decisions.
Experience debugging production data systems: reading logs, tracing failures across components, and root-causing issues under time pressure.
Experience in a forward deployed, field engineering, or embedded customer-facing engineering role, with demonstrated ability to work independently, including sound judgment about when to decide and when to escalate.
Ability to work on-site full-time at a government facility in Northern Virginia, with travel to Arlington, VA (typically 4 days per month).
Nice To Have
Experience with data lake and large-scale query technologies (example technologies: Apache Iceberg, Delta Lake, Trino, Presto, Spark, Athena).
Experience with streaming and message queue technologies (example technologies: Kafka, NATS, Kinesis, RabbitMQ).
Hands-on experience with observability tooling (Grafana, Datadog, Splunk, or similar).
Experience deploying and operating software in air-gapped, classified, or otherwise restricted environments.
Background in a military, intelligence, or defense contracting environment.
Familiarity with containerized environments (Docker, Docker Compose) and CI/CD concepts.
Tech Environment (You Might Work With)
Cloud: AWS (EC2, ECS, RDS, CloudWatch) in closed enclave environments
Containers: Docker, Docker Compose
Observability: Grafana, Loki, Tempo, Mimir (LGTM stack)
Alerting / on-call: PagerDuty
Messaging: NATS
Databases: PostgreSQL
Data integration: Twenty's purpose-built data platform and integration layer (in active development)
Languages in use across engineering: Go, TypeScript, Python
Security / Work Environment
This role requires an active TS/SCI security clearance with full-scope polygraph. Work is performed on-site at a government facility in Northern Virginia, with travel to Twenty's Arlington, VA office typically 4 days per month. Access to systems is restricted and tooling constraints apply.
Benefits
What's on the table:
Health. Medical, dental, and vision plan options. Life / AD&D, disability coverage options.
Family. Paid parental leave for eligible full-time employees. 12 weeks for birthing parents, 4 for non-birthing parents, 6 weeks for adoptive, foster, or intended parents through surrogacy.
Vacation. Paid holidays and flexible PTO. Take what you need.
Retirement. 401(k) with pre-tax and Roth options. HSA/FSA options, dependent care FSA.
Benefits vary by location, role, and eligibility. Full plan details provided during the interview and offer process.
If this role sounds like you, apply and share with us your interest
Due to U.S. government contract and security requirements, this role is limited to U.S. citizens. Some positions may also require eligibility to obtain and maintain a U.S. Government security clearance. Any active clearance requirement will be listed in the role description.
Twenty is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other protected status, consistent with applicable law.
If you need a reasonable accommodation during the hiring process, let us know and we will work with you.
