Palantir

Offensive Security Engineer

Palantir
Apply
2 hours ago
Washington, DC, USAMid Level

Base Salary

$145k - $200k/yr

Responsibilities

  • Conduct hybrid web application penetration tests combining source code review with runtime exploitation.
  • Perform external network penetration tests against internet-facing infrastructure and internal network and Active Directory assessments.
  • Assess cloud and containerized infrastructure, including identity, network, workload, and orchestration configurations.
  • Chain findings into realistic attack paths involving privilege escalation, lateral movement, and cloud control-plane access.
  • Collaborate with detection engineering to validate telemetry and detection coverage against real-world attack techniques.
  • Scope and manage third-party penetration testing engagements, review results, and convert findings into prioritized remediation.
  • Partner with engineering teams to reproduce, prioritize, and verify security fixes.
  • Design and build offensive security tooling and automation tailored to Palantir’s technology stack.
  • Design and validate agentic, LLM-driven offensive security tooling on live assessments.
  • Write clear technical and non-technical findings, readouts, business-risk explanations, and prioritized remediation guidance.

Requirements

  • At least 4 years of professional experience in offensive security, penetration testing, red teaming, or a closely related field.
  • Proficiency in at least one scripting or programming language, such as Python or Go, sufficient to build and adapt testing tooling.
  • Demonstrated experience assessing cloud environments including AWS, Azure, or GCP and containerized environments including Docker or Kubernetes.
  • Demonstrated strength in web application penetration testing across source code review and runtime testing.
  • Demonstrated strength in external and internal network penetration testing, including attack-surface enumeration, exploitation, foothold establishment, and lateral access expansion.
  • Working knowledge of CI/CD pipelines, infrastructure-as-code, cloud security, container security, and orchestration security.
  • Understanding of identity and cloud attack paths, including Kerberos abuse, Active Directory delegation misconfigurations, ADCS/SCCM exploitation, IMDS abuse, IAM privilege escalation, and SSRF-driven cloud pivots.
  • Clear written and verbal communication and the ability to explain vulnerabilities, impacts, and fixes to engineers and other stakeholders.
  • Offensive security certifications such as OSCP or OSWE, CTF competition experience, or bug bounty experience are preferred but not required.
  • Eligibility and willingness to obtain a U.S. security clearance is preferred.

Benefits

  • Medical, dental, vision, and voluntary life insurance options
  • Employer-provided basic life, AD&D, and disability insurance
  • Commuter benefits and relocation assistance
  • Take-what-you-need paid time off, plus two weeks of paid year-end time off subject to business needs
  • 10 paid holidays
  • Supportive leave of absence program, including military and medical leave
  • Paid parental leave and subsidized backup care
  • Fertility and family-building benefits
  • New-child expense stipend
  • 401(k) plan
  • Employees are encouraged to work from company offices; many teams offer hybrid work one or two days per week, with limited exceptional remote options
Palantir

About Palantir

1,001-5,000 employees

AI-powered automation for every decision. At Palantir, our software powers AI-driven decisions in critical government and commercial enterprises in the West, from the factory floors to the front lines. Our platforms feature advanced tools for data protection, governance, responsible use of AI, and civilian protection capabilities for defense applications. Dominate your most complex problems with Palantir.