Skip to main content

Palantir

Information Security Engineer - Endpoint

Washington, D.C.full-timemidAdded 1 month ago

About this role

Palantir seeks a seasoned Information Security Engineer to safeguard its global Windows and Active Directory infrastructure against sophisticated threats. You'll lead detection, prevention, and investigation efforts across enterprise systems while applying deep adversarial knowledge of Windows security vulnerabilities and attack techniques.

What you'll do

  • Own security of global Windows infrastructure and Active Directory environments
  • Develop and maintain detection rules for Windows-based attacks (DCSync, Kerberos exploits, persistence mechanisms)
  • Conduct 24/7 monitoring, threat detection, and incident investigation
  • Build and enhance threat hunting pipelines and security automation
  • Design hardening strategies and security controls for Windows systems
  • Collaborate with security team to respond to sophisticated adversaries

What they're looking for

  • Advanced Windows and Active Directory security knowledge
  • Threat detection and hunting experience
  • Windows kernel and privilege escalation understanding
  • Kerberos protocol expertise
  • Security tool development and automation
  • Incident investigation and response
  • Adversarial threat modeling
  • Log analysis and SIEM platforms
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Palantir

Palantir builds data platforms and software solutions that help government and enterprise customers tackle complex operational challenges, with a focus on responsible AI governance and privacy. The company is hiring software engineers and interns for forward-deployed customer roles, infrastructure and platform teams, and specialized privacy and civil liberties engineering positions.

View all jobs at Palantir

Likely interview questions

  • Walk us through a time you discovered or detected a novel Windows or Active Directory attack technique. How did you analyze it, and what detection or mitigation did you implement?
  • Describe your experience with DCSync attacks or Kerberos ticket anomalies. How would you design a detection pipeline to catch these in a large enterprise environment?