Information Security Engineer - Endpoint

Palantir

Washington (District of Columbia)

On-site

USD 145,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
Voluntary life insurance
401k plan
PTO and holidays
Paid parental leave
Commuter benefits

Job summary

Palantir is seeking an Information Security Engineer focused on Windows and Active Directory to own the security of Palantir's global Windows infrastructure. You will lead 24/7 prevention, detection, and investigation of security events across the environment.

The role demands deep AD expertise, Windows internals knowledge, and experience with threat hunting and red-teaming. You will drive automation, tooling, and architectural improvements to reduce risk.

Qualifications

  • 5+ years of hands‑on security experience, with the majority focused on Windows environments and Active Directory.
  • Experience investigating and detecting AD attacks across the full kill chain — enumeration through domain dominance.
  • Proficiency with threat hunting tooling and low-level Windows analysis.
  • Public contributions: talks, blogs, or open‑source tooling.

Responsibilities

  • Own the security posture of Palantir's Windows and Active Directory estate — hardening, configuration standards, and ongoing validation.
  • Reduce AD attack surface by auditing and remediating misconfigurations, legacy protocols, excessive privilege, and Kerberos delegation abuse.
  • Evaluate, deploy, and own the configuration of defensive tooling across Windows: EDR, PAM, identity threat detection, and endpoint hardening controls.
  • Build and maintain automation for security operations across Windows infrastructure — patching pipelines, drift monitoring, access reviews, credential hygiene.
  • Partner with Identity and Infrastructure teams to drive architectural improvements: tiered administration, Protected Users, LAPS, Credential Guard, and auth silos.
  • Translate findings from assessments and red team exercises into durable fixes — changes, architectural improvements, policy updates.

Skills

Windows security
Active Directory
Threat detection
Incident response
Adversary simulation
Forensics
Python/PowerShell
Public talks/research
Cloud/hybrid identity
Threat hunting

Tools

BloodHound
Impacket
Rubeus
Mimikatz
CrackMapExec
WinDbg
Process Monitor
Volatility
x64dbg

Job description

A World-Changing Company
Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.

The Role

We're looking for someone who has spent years thinking adversarially about Windows and Active Directory — not just operating them, but understanding every layer of how they can be abused, detected, and hardened. If you've written detections for DCSync, built hunting pipelines around Kerberos ticket anomalies, or reverse-engineered a novel persistence mechanism in a Windows kernel driver, this is the team you want to be on.

As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.

  • Own the security posture of Palantir's Windows and Active Directory estate — hardening, configuration standards, and ongoing validation that those standards hold.
  • Reduce attack surface across AD: audit and remediate misconfigurations, legacy protocol exposure, excessive privilege, Kerberos delegation abuse, and tier model violations.
  • Evaluate, deploy, and own the configuration of defensive tooling across the Windows environment: EDR, PAM, identity threat detection, and endpoint hardening controls.
  • Build and maintain automation for security operations across Windows infrastructure — patching pipelines, configuration drift monitoring, access reviews, and credential hygiene.
  • Partner with Identity and Infrastructure teams to drive architectural improvements: tiered administration, Protected Users, LAPS, Credential Guard, and authentication policy silos.
  • Translate findings from assessments and red team exercises into durable fixes — configuration changes, architectural improvements, and policy updates that reduce recurrence.
Active Directory
  • Deep, working knowledge of AD architecture: sites and services, replication, trust relationships, delegation models, and the LDAP schema.
  • Hands-on experience investigating and detecting AD attacks across the full kill chain — from initial enumeration through domain dominance.
  • Familiarity with attack tooling (BloodHound, Impacket, Rubeus, Mimikatz, CrackMapExec) and, critically, what they leave behind.
  • Experience hardening AD environments: tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos.
Windows Internals
  • Thorough understanding of Windows security architecture: access tokens, privilege model, integrity levels, LSASS and credential storage, SAM, and the Security Reference Monitor.
  • Ability to read and interpret Windows kernel structures, driver behavior, and undocumented APIs when necessary.
  • Proficiency with low-level analysis tools: WinDbg, Process Monitor, Process Hacker, Volatility, and x64dbg.
  • Experience with ETW-based telemetry pipelines and building detections on top of raw Windows event data.
Detection & Response
  • Proven track record writing high-fidelity detection logic, not just tuning vendor signatures.
  • Experience leading complex incident response investigations, including those involving nation-state or sophisticated criminal actors.
  • Strong forensic fundamentals across disk, memory, and network artifacts on Windows systems.
  • Experience with Entra ID (Azure AD), hybrid identity architectures, and cloud-based attack paths that pivot through on-prem AD.
  • Prior work in adversary simulation, red teaming, or offensive security research — especially against AD targets.
  • Public contributions: conference talks (BlueHat, BSides, SANS, etc.), blog posts, or open-source tooling.
  • 5+ years of hands‑on security experience, with the majority focused on Windows environments and Active Directory.
  • Proficiency in Python or PowerShell for detection development, automation, and forensic tooling.
  • Active TS/SCI security clearance, or eligibility and willingness to obtain one.
  • A portfolio of real work: detections you've written, research you've published, tools you've built, or incidents you've led.
Salary

The estimated salary range for this position is estimated to be $145,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individual’s relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.

Benefits
  • Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance
  • Employees are automatically covered by Palantir’s basic life, AD&D and disability insurance
  • Commuter benefits
  • Take what you need paid time off, not accrual based
  • 2 weeks paid time off built into the end of each year (subject to team and business needs)
  • 10 paid holidays throughout the calendar year
  • Supportive leave of absence program including time off for military service and medical events
  • Paid leave for new parents and subsidized back‑up care for all parents
  • Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation
  • Stipend to help with expenses that come with a new child
  • Employees can enroll in Palantir’s 401k plan

We are proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process please reach out and let us know how we can help.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Engineer - Infrastructure Security
Information Security Engineer - Infrastructure Security

Palantir Technologies • Washington

On-site
USD 145,000 - 200,000
Medical, dental, vision insurance
401k plan
Sign-on bonus
+5
Information Security Engineer - Infrastructure Security
Information Security Engineer - Infrastructure Security

Palantir Technologies • New York (NY)

On-site
USD 145,000 - 200,000
Medical, dental, and vision insurance
401k plan
Paid parental leave
+1
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

The Rundown AI, Inc. • United States

Hybrid
USD 145,000 - 200,000
Medical, dental, and vision insurance
401k plan
Paid leave for new parents
+1
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

The Rundown AI, Inc. • New York (NY)

On-site
USD 145,000 - 200,000
Medical, dental, and vision insurance
401k plan
Paid time off and holidays
Information Security Engineer
Information Security Engineer

Palantir • New York (NY)

On-site
USD 135,000 - 200,000
Medical, dental, vision insurance
Relocation assistance
Commuter benefits
+2
Information Security Engineer - Infrastructure Security
Information Security Engineer - Infrastructure Security

Palantir • New York (NY)

On-site
USD 145,000 - 200,000
Medical insurance
Life insurance
Disability insurance
+7
Defensive Security Analyst
Defensive Security Analyst

The Rundown AI, Inc. • Washington

Hybrid
USD 145,000 - 200,000
Medical, dental, and vision insurance
Paid time off
Commuter benefits
+1
Offensive Security Engineer
Offensive Security Engineer

Palantir • Washington

On-site
USD 145,000 - 200,000
Relocation assistance
2 weeks paid time off year-end
10 holidays per year
+1
Offensive Security Engineer
Offensive Security Engineer

Palantir Technologies • New York (NY)

Hybrid
USD 145,000 - 200,000
Medical, dental, and vision insurance
Commuter benefits
Relocation assistance
+4
Offensive Security Engineer
Offensive Security Engineer

Palantir • New York (NY)

Hybrid
USD 145,000 - 200,000