
Palantir Technologies
Posted 2 months ago
Information Security Engineer - Endpoint
New York, NYOn-siteFull-time
AI Summary
Information Security Engineer focused on Windows and Active Directory; responsible for hardening, monitoring, and defending Palantir’s Windows/AD estate, building detections, tooling, and incident response.
About this role
A World-Changing Company
Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.
The Role
We're looking for someone who has spent years thinking adversarially about Windows and Active Directory — not just operating them, but understanding every layer of how they can be abused, detected, and hardened. If you've written detections for DCSync, built hunting pipelines around Kerberos ticket anomalies, or reverse-engineered a novel persistence mechanism in a Windows kernel driver, this is the team you want to be on.
As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.
As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.
Core Responsibilities
What We're Looking For
Active Directory
Windows Internals
Detection & Response
What We Value
What We Require
Skills
Active DirectoryAD ArchitectureBloodHoundCrackMapExecCredential GuardCredential StorageDCSyncEDRETWIdentity Threat DetectionImpacketKerberosLAPSLSASSMimikatzPAMPowerShellProcess HackerProcess MonitorProtected UsersPythonRubeusSAMSecurity Operations AutomationSecurity Reference MonitorVolatilityWinDbgWindows KernelWindows SecurityX64dbg