1 year ago
New York, NY, USAMid Level
Base Salary
$145k - $200k/yr
Responsibilities
- Conduct hybrid web application penetration tests combining source-code review with runtime exploitation
- Perform external network penetration tests against internet-facing infrastructure and identify exposed services, misconfigurations, and initial foothold paths
- Perform internal network and Active Directory assessments focused on privilege escalation, lateral movement, and misconfigurations
- Assess cloud and containerized infrastructure, including identity, network, and workload configurations
- Collaborate with detection engineering to validate telemetry and detection coverage against real-world attack techniques
- Scope, manage, and critically review third-party penetration testing engagements and convert findings into prioritized remediation
- Partner with engineering to reproduce, prioritize, and verify vulnerability fixes
- Design and build offensive security tooling and automation tailored to Palantir’s technology stack
- Write actionable technical and non-technical findings reports and readouts that translate vulnerabilities into business risk and prioritized actions
Requirements
- At least four years of professional experience in offensive security, penetration testing, red teaming, or a closely related field
- Proficiency in at least one scripting or programming language, such as Python or Go, to build and adapt testing tooling
- Experience assessing cloud environments using AWS, Azure, or GCP and containerized environments using Docker or Kubernetes
- Demonstrated strength in web application penetration testing, including source-code review and runtime testing
- Demonstrated strength in external and internal network penetration testing, including attack-surface enumeration, exploitation, foothold establishment, and access expansion
- Working knowledge of cloud, container, and orchestration security principles and common attack paths involving identity and cloud environments
- Working knowledge of Kerberos abuse, Active Directory delegation misconfigurations, ADCS/SCCM exploitation, IMDS abuse, IAM privilege escalation, and SSRF-driven cloud pivots
- Ability to communicate vulnerabilities, business impact, and remediation clearly to technical and non-technical stakeholders
- Eligibility and willingness to obtain a U.S. security clearance is preferred
- OSCP or OSWE certification, CTF participation, or bug bounty experience is a plus but not required
Benefits
- Medical, dental, vision, voluntary life, basic life, AD&D, and disability insurance
- Commuter benefits and relocation assistance
- Flexible paid time off, two weeks of year-end paid time off subject to team and business needs, and 10 paid holidays
- Supportive leave of absence program, paid parental leave, subsidized backup care, and fertility and family-building benefits
- New-child stipend and access to a 401(k) plan
- Primarily in-person work, with many teams offering hybrid options of one or two work-from-home days per week; limited remote work may be available exceptionally
Categories
About Palantir
AI-powered automation for every decision. At Palantir, our software powers AI-driven decisions in critical government and commercial enterprises in the West, from the factory floors to the front lines. Our platforms feature advanced tools for data protection, governance, responsible use of AI, and civilian protection capabilities for defense applications. Dominate your most complex problems with Palantir.