Skip to main content

Palantir

Information Security Engineer - Endpoint

New York, NYfull-timemidAdded 1 month ago

About this role

Palantir seeks an experienced Information Security Engineer to defend its global Windows and Active Directory infrastructure against sophisticated threats. This role involves designing and operating detection systems, threat hunting, and infrastructure hardening across a 24/7 security operation.

What you'll do

  • Own security posture of Palantir's enterprise Windows infrastructure globally
  • Develop and maintain detection rules and hunting pipelines for Windows and Active Directory attacks
  • Conduct 24/7 prevention, detection, and investigation of security events
  • Design and implement Windows hardening strategies and security controls
  • Perform threat hunting and adversarial analysis of Windows attack techniques
  • Collaborate with security team on incident response and threat intelligence

What they're looking for

  • Deep expertise in Windows and Active Directory security
  • Proficiency writing detection rules and SIEM queries
  • Knowledge of Windows kernel and privilege escalation techniques
  • Understanding of Kerberos authentication and anomaly detection
  • Experience with threat hunting and adversarial analysis
  • Incident response and forensics capabilities
  • Infrastructure security and hardening practices
  • Security tool development and integration
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Palantir

Palantir builds data platforms and software solutions that help government and enterprise customers tackle complex operational challenges, with a focus on responsible AI governance and privacy. The company is hiring software engineers and interns for forward-deployed customer roles, infrastructure and platform teams, and specialized privacy and civil liberties engineering positions.

View all jobs at Palantir

Likely interview questions

  • Walk us through a time you discovered or detected a novel attack technique against Windows or Active Directory. How did you validate it and what detection did you build?
  • Describe your experience hunting for lateral movement in Active Directory. What artifacts and anomalies do you prioritize, and how would you detect a sophisticated attacker using legitimate credentials?