Palantir Technologies

Information Security Engineer - Endpoint

Palantir Technologies$145K — $200K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on security experience focused on Windows environments and Active Directory.
  • Deep knowledge of Active Directory architecture and attack methodologies.
  • Proficiency in Python or PowerShell for detection and automation tasks.
  • Active TS/SCI security clearance or eligibility to obtain one.
  • Demonstrated contributions to the field through published work or tools.

Responsibilities

  • Own the security of Palantir's Windows and Active Directory infrastructure, ensuring hardening and validation standards.
  • Reduce attack surfaces by auditing and fixing misconfigurations and privilege issues.
  • Deploy and manage security tools like EDR and PAM across Windows environments.
  • Automate security operations processes, including patching and access reviews.
  • Collaborate with Identity and Infrastructure teams to enhance security architecture.
  • Translate findings from security assessments into actionable fixes.

Benefits

  • Comprehensive medical, dental, and vision insurance for employees and dependents.
  • Paid time off that emphasizes flexibility and work-life balance, including an additional 2 weeks at year-end.
  • Paid leave for new parents and fertility benefits, fostering family support.
  • 401k plan available for employee enrollment.
  • Support for various leave of absence needs, including military service.
Full Job Description
The Role

We're looking for someone who has spent years thinking adversarially about Windows and Active Directory - not just operating them, but understanding every layer of how they can be abused, detected, and hardened. If you've written detections for DCSync, built hunting pipelines around Kerberos ticket anomalies, or reverse-engineered a novel persistence mechanism in a Windows kernel driver, this is the team you want to be on.

As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.

Core Responsibilities

  • Own the security posture of Palantir's Windows and Active Directory estate - hardening, configuration standards, and ongoing validation that those standards hold.
  • Reduce attack surface across AD: audit and remediate misconfigurations, legacy protocol exposure, excessive privilege, Kerberos delegation abuse, and tier model violations.
  • Evaluate, deploy, and own the configuration of defensive tooling across the Windows environment: EDR, PAM, identity threat detection, and endpoint hardening controls.
  • Build and maintain automation for security operations across Windows infrastructure - patching pipelines, configuration drift monitoring, access reviews, and credential hygiene.
  • Partner with Identity and Infrastructure teams to drive architectural improvements: tiered administration, Protected Users, LAPS, Credential Guard, and authentication policy silos.
  • Translate findings from assessments and red team exercises into durable fixes - configuration changes, architectural improvements, and policy updates that reduce recurrence.


What We're Looking For

Active Directory
  • Deep, working knowledge of AD architecture: sites and services, replication, trust relationships, delegation models, and the LDAP schema.
  • Hands-on experience investigating and detecting AD attacks across the full kill chain - from initial enumeration through domain dominance.
  • Familiarity with attack tooling (BloodHound, Impacket, Rubeus, Mimikatz, CrackMapExec) and, critically, what they leave behind.
  • Experience hardening AD environments: tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos.

Windows Internals
  • Thorough understanding of Windows security architecture: access tokens, privilege model, integrity levels, LSASS and credential storage, SAM, and the Security Reference Monitor.
  • Ability to read and interpret Windows kernel structures, driver behavior, and undocumented APIs when necessary.
  • Proficiency with low-level analysis tools: WinDbg, Process Monitor, Process Hacker, Volatility, and x64dbg.
  • Experience with ETW-based telemetry pipelines and building detections on top of raw Windows event data.

Detection & Response
  • Proven track record writing high-fidelity detection logic, not just tuning vendor signatures.
  • Experience leading complex incident response investigations, including those involving nation-state or sophisticated criminal actors.
  • Strong forensic fundamentals across disk, memory, and network artifacts on Windows systems.


What We Value

  • Experience with Entra ID (Azure AD), hybrid identity architectures, and cloud-based attack paths that pivot through on-prem AD.
  • Prior work in adversary simulation, red teaming, or offensive security research - especially against AD targets.
  • Public contributions: conference talks (BlueHat, BSides, SANS, etc.), blog posts, or open-source tooling.


What We Require

  • 5+ years of hands-on security experience, with the majority focused on Windows environments and Active Directory.
  • Proficiency in Python or PowerShell for detection development, automation, and forensic tooling.
  • Active TS/SCI security clearance, or eligibility and willingness to obtain one.
  • A portfolio of real work: detections you've written, research you've published, tools you've built, or incidents you've led.


Salary

The estimated salary range for this position is estimated to be $145,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individual's relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.

Our benefits aim to promote health and wellbeing across all areas of Palantirians' lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies.

Benefits
• Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance
• Employees are automatically covered by Palantir's basic life, AD&D and disability insurance
• Commuter benefits
• Take what you need paid time off, not accrual based
• 2 weeks paid time off built into the end of each year (subject to team and business needs)
• 10 paid holidays throughout the calendar year
• Supportive leave of absence program including time off for military service and medical events
• Paid leave for new parents and subsidized back-up care for all parents
• Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation
• Stipend to help with expenses that come with a new child
• Employees can enroll in Palantir's 401k plan

Life at Palantir

We want every Palantirian to achieve their best outcomes, that's why we celebrate individuals' strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians' lives is just one of the ways we're investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region.

In keeping consistent with Palantir's values and culture, we believe employees are "better together" and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for "Remote" work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office.

About Palantir Technologies

Palantir Technologies is a software and services company specializing in data analysis. The company was founded in 2003 by a group of PayPal alumni and Stanford computer scientists. Palantir's original clients were federal agencies of the United States Intelligence Community. It has since expanded its customer base to serve state and local governments, as well as private companies in the financial and healthcare industries. Palantir's software allows users to integrate, visualize, and analyze large amounts of data. The company has been the subject of controversy due to its work with government agencies, including the U.S. Immigration and Customs Enforcement (ICE).
Learn more about Palantir Technologies
Size
2,500 employees
Market Cap
$12.5 billion
Industry
Founded
2004
Revenue
$1 billion
NASDAQ

Similar Jobs

More Jobs at Palantir Technologies

More Information Technology Jobs

Find similar Information Security Engineer - Endpoint jobs: