Role Overview
As an Insider Threat Detection Engineer, you are responsible for protecting Palantir's people, data, and most sensitive assets across the globe. Your technical expertise is matched by your integrity and genuine passion for security. You work well on a team, are highly motivated, and thrive on solving problems and taking on new challenges.
Your team serves as a critical line of defense, responsible for the 24/7 prevention, detection, and investigation of security events and active threats across Palantir's environment. This role focuses on all aspects of Detection and Response with a strong emphasis on identifying and mitigating insider risks. Your work will directly impact the success of Palantir's mission by making it difficult for adversaries — both external and internal — to compromise our global network.
Core Responsibilities
- Engineer and automate end-to-end detection and investigation workflows, continuously improving Detection and Response infrastructure
- Develop alerting and detection strategies to identify malicious or anomalous behavior, including new and novel defensive techniques that adapt to evolving adversary tactics and tradecraft
- Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications
- Investigate security events and active attacks across the enterprise, uncovering sophisticated threats and identifying patterns of behavior that indicate insider risk
- Influence and inform security controls designed to safeguard Palantir's most critical assets
- Partner closely with other members of the Information Security team to lead changes in the company's network defense posture
What We Value
- Broad exposure to multiple security subject areas, including a strong background in forensics or threat intelligence
- Deep exposure in Incident Response or Detection Engineering
- Desire to further the information security community through substantive contributions (e.g. conference talks, blog posts, public tool development, etc.)
- Comfort in operating autonomously and engaging across business levels to advise on security outcomes
What We Require
- Extensive security experience (3+ years) in at least one major platform (e.g. AWS, Azure, Windows, OS X, Linux, etc.)
- Proficiency in Python (preferred), PowerShell, or similar
- Familiarity with endpoint telemetry and log sources from at least one major operating system
- Experience with common SIEM/SOAR platforms and proficiency writing queries against security event data
- Active TS/SCI security clearance or eligibility to obtain a security clearance
Salary
The estimated salary range for this position is $145,000-$200,000 per year. Total compensation may include Restricted Stock units, sign‑on bonus, and other potential future incentives. The estimate excludes the value of any potential sign‑on bonus, benefits offered, and potential future value of long‑term incentives. Total compensation will be determined by each individual’s relevant qualifications, work experience, skills, and other factors.
Benefits
- Medical, dental, and vision insurance as well as voluntary life insurance for employees and eligible dependents
- Basic life, AD&D and disability insurance for employees
- Commuter benefits
- Relocation assistance
- Paid time off that can be taken as needed, not accrual based
- Two weeks of paid time off built into the end of each year (subject to team and business needs)
- 10 paid holidays throughout the calendar year
- Supportive leave of absence program including time off for military service and medical events
- Paid leave for new parents and subsidized backup care for all parents
- Fertility and family building benefits including adoption, surrogacy, and preservation
- Stipend to help with expenses that come with a new child
- Enrollment in Palantir’s 401(k) plan
Life at Palantir
We want every Palantirian to achieve their best outcomes. Paying attention to the needs of our community enables us to optimize opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well‑being across all areas of Palantirians’ lives is one of the ways we invest in our community.
We believe employees are "better together" and in‑person work affords opportunities for more creative outcomes. Therefore we encourage employees to work from our offices to foster connectivity and innovation. Many teams also offer hybrid options ― working from home one or two days a week. Based on business need, some roles allow remote work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as onsite, you are required to work from an office.
Equal Opportunity Employer
Palantir is proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability.
We will never ask for a payment or financial information to participate in our interview process. If you suspect you've been contacted by a scammer, we recommend you cease all communication with that individual and consider reporting them to the relevant authorities, such as the US FBI Internet Crime Complaint Center (IC3). For more information about how your personal data will be processed by Palantir, see our Privacy Policy.
#J-18808-Ljbffr