Information Security Engineer - Infrastructure Security

Palantir Technologies

Washington (District of Columbia)

On-site

USD 145,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
401k plan
Sign-on bonus
Restricted Stock units
Paid time off
Holidays
Parental leave support
Commuter benefits

Job summary

Palantir Technologies is seeking an Information Security Engineer focused on Windows and Active Directory. You will own security across Palantir's global Windows infrastructure, maintain 24/7 prevention, detection, and investigation, and drive architectural improvements with Identity and Infrastructure teams.

The role requires 5+ years in security with Windows/AD focus, proficiency in Python or PowerShell, and TS/SCI eligibility. Salary ranges with stock options and sign-on bonuses may apply.

Qualifications

  • Deep knowledge of AD architecture and security controls.
  • Experience investigating AD attacks across the kill chain.
  • Familiarity with attack tooling and what it leaves behind.
  • Experience hardening AD environments and enforcement of security policy.

Responsibilities

  • Own the security posture of Palantir's Windows and AD estate; enforce hardening and standards.
  • Reduce attack surface across AD; audit and remediate misconfigurations and exposure.
  • Deploy and tune defensive tooling across Windows: EDR, PAM, threat detection, and endpoint hardening.
  • Build automation for security operations: patching, drift monitoring, access reviews, credential hygiene.
  • Partner with Identity and Infrastructure teams to drive architectural improvements and policy updates.
  • Translate assessments into durable fixes and preventive controls.

Skills

Active Directory
AD architecture
Threat hunting
Detection logic
Incident response
Windows internals

Tools

WinDbg
Process Monitor
Volatility
x64dbg
BloodHound
Impacket
Mimikatz

Job description

We're looking for someone who has spent years thinking adversarially about Windows and Active Directory - not just operating them, but understanding every layer of how they can be abused, detected, and hardened. If you've written detections for DCSync, built hunting pipelines around Kerberos ticket anomalies, or reverse‑engineered a novel persistence mechanism in a Windows kernel driver, this is the team you want to be on.

As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.

Core Responsibilities
  • Own the security posture of Palantir's Windows and Active Directory estate - hardening, configuration standards, and ongoing validation that those standards hold.
  • Reduce attack surface across AD: audit and remediate misconfigurations, legacy protocol exposure, excessive privilege, Kerberos delegation abuse, and tier model violations.
  • Evaluate, deploy, and own the configuration of defensive tooling across the Windows environment: EDR, PAM, identity threat detection, and endpoint hardening controls.
  • Build and maintain automation for security operations across Windows infrastructure - patching pipelines, configuration drift monitoring, access reviews, and credential hygiene.
  • Partner with Identity and Infrastructure teams to drive architectural improvements: tiered administration, Protected Users, LAPS, Credential Guard, and authentication policy silos.
  • Translate findings from assessments and red team exercises into durable fixes - configuration changes, architectural improvements, and policy updates that reduce recurrence.
What We're Looking For
Active Directory
  • Deep, working knowledge of AD architecture: sites and services, replication, trust relationships, delegation models, and the LDAP schema.
  • Hands‑on experience investigating and detecting AD attacks across the full kill chain - from initial enumeration through domain dominance.
  • Familiarity with attack tooling (BloodHound, Impacket, Rubeus, Mimikatz, CrackMapExec) and, critically, what they leave behind.
  • Experience hardening AD environments: tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos.
Windows Internals
  • Thorough understanding of Windows security architecture: access tokens, privilege model, integrity levels, LSASS and credential storage, SAM, and the Security Reference Monitor.
  • Ability to read and interpret Windows kernel structures, driver behavior, and undocumented APIs when necessary.
  • Proficiency with low‑level analysis tools: WinDbg, Process Monitor, Process Hacker, Volatility, and x64dbg.
  • Experience with ETW‑based telemetry pipelines and building detections on top of raw Windows event data.
Detection & Response
  • Proven track record writing high‑fidelity detection logic, not just tuning vendor signatures.
  • Experience leading complex incident response investigations, including those involving nation‑state or sophisticated criminal actors.
  • Strong forensic fundamentals across disk, memory, and network artifacts on Windows systems.
What We Value
  • Experience with Entra ID (Azure AD), hybrid identity architectures, and cloud‑based attack paths that pivot through on‑prem AD.
  • Prior work in adversary simulation, red teaming, or offensive security research - especially against AD targets.
  • Public contributions: conference talks (BlueHat, BSides, SANS, etc.), blog posts, or open‑source tooling.
What We Require
  • 5+ years of hands‑on security experience, with the majority focused on Windows environments and Active Directory.
  • Proficiency in Python or PowerShell for detection development, automation, and forensic tooling.
  • Active TS/SCI security clearance, or eligibility and willingness to obtain one.
  • A portfolio of real work: detections you've written, research you've published, tools you've built, or incidents you've led.

Salary: The estimated salary range for this position is $145,000 - $200,000/year. Total compensation may also include Restricted Stock units, sign‑on bonus, and other potential future incentives. Compensation is determined by relevant qualifications, experience, and skills.

Benefits
  • Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance.
  • Employees are automatically covered by Palantir's basic life, AD&D and disability insurance.
  • Commuter benefits.
  • Paid time off: take what you need, not accrual based.
  • 2 weeks paid time off built into the end of each year (subject to team and business needs).
  • 10 paid holidays throughout the calendar year.
  • Supportive leave of absence program including time off for military service and medical events.
  • Paid leave for new parents and subsidized back‑up care for all parents.
  • Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation.
  • Stipend to help with expenses that come with a new child.
  • Employees can enroll in Palantir's 401k plan.

We are proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Engineer - Endpoint
Information Security Engineer - Endpoint

Palantir • Washington

On-site
USD 145,000 - 200,000
Medical, dental, vision insurance
Voluntary life insurance
401k plan
+3
Information Security Engineer - Infrastructure Security
Information Security Engineer - Infrastructure Security

Palantir Technologies • New York (NY)

On-site
USD 145,000 - 200,000
Medical, dental, and vision insurance
401k plan
Paid parental leave
+1
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

The Rundown AI, Inc. • United States

Hybrid
USD 145,000 - 200,000
Medical, dental, and vision insurance
401k plan
Paid leave for new parents
+1
Senior Windows & Active Directory Security Engineer
Senior Windows & Active Directory Security Engineer

Palantir Technologies • Washington

On-site
USD 145,000 - 200,000
Medical, dental, vision insurance
401k plan
Sign-on bonus
+5
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

The Rundown AI, Inc. • New York (NY)

On-site
USD 145,000 - 200,000
Medical, dental, and vision insurance
401k plan
Paid time off and holidays
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

The Rundown AI, Inc. • Seattle (WA)

On-site
USD 145,000 - 200,000
Medical, dental, and vision insurance
Commuter benefits
401k plan
+1
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

Palantir • Washington

On-site
USD 145,000 - 200,000
Medical, dental, and vision insurance
Paid time off
401k plan
+2
Information Security Engineer - Infrastructure Security
Information Security Engineer - Infrastructure Security

Palantir • New York (NY)

On-site
USD 145,000 - 200,000
Medical insurance
Life insurance
Disability insurance
+7
Information Security Engineer
Information Security Engineer

Palantir • New York (NY)

On-site
USD 135,000 - 200,000
Medical, dental, vision insurance
Relocation assistance
Commuter benefits
+2
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

Palantir Technologies • Seattle (WA)

Hybrid
USD 145,000 - 200,000
Medical, dental, and vision insurance
401(k) enrollment
Paid time off
+2