> Markdown version of [/jobs/ext/2702731-it-security-engineer](https://www.wearedevelopers.com/jobs/ext/2702731-it-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Engineer - **Company:** TWENTY TECHNOLOGIES INC. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Proxy Servers, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Leak Prevention, Dynamic Host Configuration Protocol, Digital Assets, Domain Name System (DNS), Multi-Factor Authentication, Cryptographic Protocols, Identity and Access Management, Intrusion Detection Systems, Virtual Private Networks (VPN), Network Security, Network Segmentation, Network Protocols, Open Web Application Security, PCI Data Security Standards, Ansible, Secure Coding, Security Information and Event Management, TCP/IP, Software Vulnerability Management, Snort (Software), Firewalls (Computer Science), Containerization, Kubernetes, Information Technology, Patch Management, CIS Benchmarks, Terraform, Splunk, Docker, Security Orchestration, Automation & Response, Elk Stack, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/it-security-engineer-twenty-8705524 ## About the Role * Bachelor's degree in Computer Science, Information Security, or related field (or equivalent professional experience). * 5+ years of professional IT security experience, with demonstrated expertise in at least two of the following domains: network security, systems security, or cybersecurity. * Strong knowledge of TCP/IP, DNS, DHCP, and network protocols; experience with firewalls, proxies, and network segmentation. * Hands-on experience with security tools such as Splunk, ELK Stack, Snort, Suricata, or similar SIEM and IDS/IPS platforms. * Proficiency in systems security, including endpoint protection and vulnerability management. * Experience with cloud security (AWS, Azure, or GCP) and containerized environments (Docker, Kubernetes). * Understanding of common attack vectors and security frameworks (NIST, CIS Controls, OWASP Top 10). * Excellent problem-solving skills with the ability to work independently and as part of a team. * Strong communication skills to explain complex security concepts to non-technical stakeholders. Nice-to-haves * Security certifications such as CISSP, CISM, CEH, CCNA Security, Security+, or similar. * Experience with security automation and Infrastructure as Code (Terraform, Ansible). * Knowledge of application security testing (SAST/DAST) and secure development practices. * Experience with incident response and forensics investigations. * Familiarity with compliance frameworks and audit processes. ## Description We are seeking IT Security Engineer to join our growing technology engineering team. This is a critical role that will establish and maintain our security infrastructure, protect our digital assets, and ensure compliance with industry standards. You will be responsible for implementing comprehensive security solutions across our network, systems, and applications, while working closely with our development and operations teams to embed security into our organizational culture., * Design, implement, and maintain enterprise network security architecture, including firewalls, intrusion detection systems, VPNs, and DMZs. * Develop and enforce security policies, standards and procedures across the organization. * Conduct security assessments, vulnerability scans and penetration testing to identify and remediate security gaps. * Monitor systems and networks 24/7 using security information and event management (SIEM) tools; investigate and respond to security incidents. * Manage access controls, identity and access management (IAM), and multi-factor authentication (MFA) solutions. * Establish and manage data loss prevention (DLP) and encryption protocols for sensitive data at rest and in transit. * Perform security hardening of servers, workstations, and endpoints; manage patch management and system updates. * Provide security awareness training and education to employees to foster a security-conscious culture. * Conduct root cause analysis on security incidents and prepare incident response reports and recommendations. * Ensure compliance with relevant regulations (CMMC, SOC 2, GDPR, PCI-DSS, or industry-specific standards as applicable). ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)