Palantir

Information Security Engineer - Endpoint

Palantir
Apply
5 months ago

Base Salary

$145k - $200k/yr

Responsibilities

  • Own the security posture of Palantir’s Windows and Active Directory estate through hardening, configuration standards, and ongoing validation
  • Audit and remediate Active Directory misconfigurations, legacy protocol exposure, excessive privileges, Kerberos delegation abuse, and tier model violations
  • Evaluate, deploy, and configure EDR, PAM, identity threat detection, and endpoint hardening tools
  • Build and maintain Windows security automation for patching, configuration drift monitoring, access reviews, and credential hygiene
  • Partner with Identity and Infrastructure teams on tiered administration, Protected Users, LAPS, Credential Guard, and authentication policy silos
  • Convert assessment and red-team findings into configuration changes, architectural improvements, and policy updates

Requirements

  • At least 5 years of hands-on security experience, primarily focused on Windows environments and Active Directory
  • Deep working knowledge of Active Directory architecture, including replication, trust relationships, delegation, and LDAP schema
  • Hands-on experience investigating and detecting Active Directory attacks across the full kill chain
  • Experience with Active Directory hardening, tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos
  • Thorough understanding of Windows security architecture, kernel structures, driver behavior, and undocumented APIs
  • Proficiency with WinDbg, Process Monitor, Process Hacker, Volatility, and x64dbg
  • Experience with ETW-based telemetry pipelines and Windows event detection
  • Proven ability to write high-fidelity detection logic and lead complex incident response investigations
  • Strong Windows disk, memory, and network forensics fundamentals
  • Proficiency in Python or PowerShell for detection development, automation, and forensic tooling
  • Active TS/SCI security clearance or eligibility and willingness to obtain one
  • Portfolio of real work, such as written detections, published research, built tools, or led incidents
  • Experience with Entra ID, hybrid identity architectures, cloud-based attack paths, adversary simulation, red teaming, or offensive security research is valued
  • Public contributions such as conference talks, blog posts, or open-source tooling are valued

Benefits

  • Medical, dental, vision, voluntary life, basic life, AD&D, and disability insurance options
  • Commuter benefits
  • Take-what-you-need paid time off, plus two weeks of paid time off at year end subject to team and business needs
  • 10 paid holidays
  • Supportive leave of absence program, including military and medical leave
  • Paid parental leave and subsidized backup care
  • Fertility and family-building benefits
  • New-child expense stipend
  • 401(k) plan
  • Primarily in-office work is encouraged; many teams offer hybrid work one or two days per week, with exceptional remote arrangements for select roles

Tech Stack

PowerShellPythonWindows

Categories

Palantir

About Palantir

1,001-5,000 employees

AI-powered automation for every decision. At Palantir, our software powers AI-driven decisions in critical government and commercial enterprises in the West, from the factory floors to the front lines. Our platforms feature advanced tools for data protection, governance, responsible use of AI, and civilian protection capabilities for defense applications. Dominate your most complex problems with Palantir.

Contact me