×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Information Security Engineer - Infrastructure Security

Job in Washington, District of Columbia, 20022, USA
Listing for: Palantir Technologies
Full Time position
Listed on 2026-10-05
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 145000 - 200000 USD Yearly USD 145000.00 200000.00 YEAR
Job Description & How to Apply Below

We're looking for someone who has spent years thinking adversarially about Windows and Active Directory - not just operating them, but understanding every layer of how they can be abused, detected, and hardened. If you've written detections for DCSync, built hunting pipelines around Kerberos ticket anomalies, or reverse‑engineered a novel persistence mechanism in a Windows kernel driver, this is the team you want to be on.

As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.

Core Responsibilities
  • Own the security posture of Palantir's Windows and Active Directory estate - hardening, configuration standards, and ongoing validation that those standards hold.
  • Reduce attack surface across AD: audit and remediate misconfigurations, legacy protocol exposure, excessive privilege, Kerberos delegation abuse, and tier model violations.
  • Evaluate, deploy, and own the configuration of defensive tooling across the Windows environment: EDR, PAM, identity threat detection, and endpoint hardening controls.
  • Build and maintain automation for security operations across Windows infrastructure - patching pipelines, configuration drift monitoring, access reviews, and credential hygiene.
  • Partner with Identity and Infrastructure teams to drive architectural improvements: tiered administration, Protected Users, LAPS, Credential Guard, and authentication policy silos.
  • Translate findings from assessments and red team exercises into durable fixes - configuration changes, architectural improvements, and policy updates that reduce recurrence.
What We're Looking For Active Directory
  • Deep, working knowledge of AD architecture: sites and services, replication, trust relationships, delegation models, and the LDAP schema.
  • Hands‑on experience investigating and detecting AD attacks across the full kill chain - from initial enumeration through domain dominance.
  • Familiarity with attack tooling (Blood Hound, Impacket, Rubeus, Mimikatz, Crack Map Exec ) and, critically, what they leave behind.
  • Experience hardening AD environments: tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos.
Windows Internals
  • Thorough understanding of Windows security architecture: access tokens, privilege model, integrity levels, LSASS and credential storage, SAM, and the Security Reference Monitor.
  • Ability to read and interpret Windows kernel structures, driver behavior, and undocumented APIs when necessary.
  • Proficiency with low‑level analysis tools:
    Win Dbg, Process Monitor, Process Hacker, Volatility, and x64dbg.
  • Experience with ETW‑based telemetry pipelines and building detections on top of raw Windows event data.
Detection & Response
  • Proven track record writing high‑fidelity detection logic, not just tuning vendor signatures.
  • Experience leading complex incident response investigations, including those involving nation‑state or sophisticated criminal actors.
  • Strong forensic fundamentals across disk, memory, and network artifacts on Windows systems.
What We Value
  • Experience with Entra  (Azure AD), hybrid identity architectures, and cloud‑based attack paths that pivot through on‑prem AD.
  • Prior work in adversary simulation, red teaming, or offensive security research - especially against AD targets.
  • Public contributions: conference talks (Blue Hat, BSides, SANS, etc.), blog posts, or open‑source tooling.
What We Require
  • 5+ years of hands‑on security experience, with the majority focused on Windows environments and Active Directory.
  • Proficiency…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary