As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.
Core Responsibilities
- Own the security posture of Palantir's Windows and Active Directory estate — hardening, configuration standards, and ongoing validation that those standards hold.
- Reduce attack surface across AD: audit and remediate misconfigurations, legacy protocol exposure, excessive privilege, Kerberos delegation abuse, and tier model violations.
- Evaluate, deploy, and own the configuration of defensive tooling across the Windows environment: EDR, PAM, identity threat detection, and endpoint hardening controls.
- Build and maintain automation for security operations across Windows infrastructure — patching pipelines, configuration drift monitoring, access reviews, and credential hygiene.
- Partner with Identity and Infrastructure teams to drive architectural improvements: tiered administration, Protected Users, LAPS, Credential Guard, and authentication policy silos.
- Translate findings from assessments and red team exercises into durable fixes — configuration changes, architectural improvements, and policy updates that reduce recurrence.
What We're Looking For
- Deep, working knowledge of AD architecture: sites and services, replication, trust relationships, delegation models, and the LDAP schema.
- Hands-on experience investigating and detecting AD attacks across the full kill chain — from initial enumeration through domain dominance.
- Familiarity with attack tooling (BloodHound, Impacket, Rubeus, Mimikatz, CrackMapExec) and, critically, what they leave behind.
- Experience hardening AD environments: tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos.
- Thorough understanding of Windows security architecture: access tokens, privilege model, integrity levels, LSASS and credential storage, SAM, and the Security Reference Monitor.
- Ability to read and interpret Windows kernel structures, driver behavior, and undocumented APIs when necessary.
- Proficiency with low-level analysis tools: WinDbg, Process Monitor, Process Hacker, Volatility, and x64dbg.
- Experience with ETW-based telemetry pipelines and building detections on top of raw Windows event data.
- Proven track record writing high-fidelity detection logic, not just tuning vendor signatures.
- Experience leading complex incident response investigations, including those involving nation-state or sophisticated criminal actors.
- Strong forensic fundamentals across disk, memory, and network artifacts on Windows systems.
What We Value
- Experience with Entra ID (Azure AD), hybrid identity architectures, and cloud-based attack paths that pivot through on-prem AD.
- Prior work in adversary simulation, red teaming, or offensive security research — especially against AD targets.
- Public contributions: conference talks (BlueHat, BSides, SANS, etc.), blog posts, or open-source tooling.
What We Require
- 5+ years of hands-on security experience, with the majority focused on Windows environments and Active Directory.
- Proficiency in Python or PowerShell for detection development, automation, and forensic tooling.
- Active TS/SCI security clearance, or eligibility and willingness to obtain one.
- A portfolio of real work: detections you've written, research you've published, tools you've built, or incidents you've led.
Salary
If you would like to understand more about how your personal data will be processed by Palantir, please see our Privacy Policy.
Skills Required
- 5+ years of hands-on security experience
- Deep working knowledge of Active Directory
- Experience with Windows security architecture
- Proficiency in Python or PowerShell
- Active TS/SCI security clearance or eligibility
Palantir Technologies Compensation & Benefits Highlights
-
Fair & Transparent Compensation — Pay is considered competitive for core engineering and other key technical roles, with total compensation that compares favorably in major markets. Offers for these functions are often viewed as market-aligned and materially attractive.
-
Healthcare Strength — Health coverage is described as comprehensive and high quality, contributing meaningfully to overall compensation satisfaction. Coverage breadth and employer support for medical needs are consistently emphasized in benefits descriptions.
-
Equity Value & Accessibility — Equity forms a significant part of the package, providing meaningful upside through RSUs and related awards over multi-year schedules. When aligned with tenure and company performance, realized value can feel compelling.
Palantir Technologies Insights
What We Do
At Palantir, we're helping the world's most important institutions use their data to solve their most urgent problems. Our software lets our customers integrate and analyze all of their data so they can answer questions that they couldn't before. From delivering disaster relief to building safer automobiles, we're honored to help make our partners better at their most important work. Together with our customers, we're building the future of national security, healthcare, energy, finance, manufacturing, and more. And we need bright minds from around the world to help us.
Palantir Technologies Offices
OnSite Workspace