# Offensive Security Engineer

**Company:** [Palantir](https://hotfix.jobs/companies/palantir)
**Location:** Washington, DC, New York, NY
**Role:** Security Engineering
**Experience:** 4+ years
**Skills:** Python, Go, burp suite, bloodhound, sharphound, certipy, impacket, responder, pacu, scoutsuite, nuclei, AWS, Azure, GCP, Kubernetes
**Posted:** 2026-08-14

> The engineer conducts web, network, Active Directory, cloud, and container penetration tests, develops offensive security automation, and drives remediation with engineering and external testing partners. The role requires at least four years of offensive security experience plus scripting or programming proficiency.

## Job Description

## Responsibilities
- Conduct hybrid web application penetration tests combining source code review with runtime exploitation across products and internal tooling.
- Perform external network penetration tests against internet-facing infrastructure, identifying exposed services, misconfigurations, and paths to obtain an initial foothold.
- Perform internal network and Active Directory security assessments, identifying privilege escalation paths, lateral movement opportunities, and misconfigurations.
- Assess cloud and containerized infrastructure, including identity, network, and workload configurations.
- Collaborate with detection engineering to validate telemetry and detection coverage against real-world attack techniques.
- Scope and manage third-party penetration testing engagements end-to-end, critically review results, and convert findings into prioritized remediation.
- Partner with engineering to reproduce, prioritize, and verify fixes.
- Design and build offensive security tooling and automation.
- Author clear, actionable write-ups and readouts for technical and non-technical stakeholders.

## Requirements
- 4+ years of professional experience in offensive security, penetration testing, red teaming, or a closely related field.
- Proficiency in at least one scripting or programming language, such as Python or Go, sufficient to build and adapt testing tooling.
- Experience assessing cloud environments such as AWS, Azure, or Google Cloud and containerized environments such as Docker and Kubernetes.
- Strength in web application penetration testing, including source code review and runtime testing.
- Strength in external and internal network penetration testing.
- Experience with offensive security tooling, including Burp Suite, BloodHound, SharpHound, Certipy, Impacket, Responder, Pacu, ScoutSuite, and Nuclei.
- Working knowledge of CI/CD pipelines and infrastructure as code.
- Working knowledge of cloud, container, and orchestration security principles.
- Understanding of identity and cloud attack paths, including Kerberos abuse, delegation misconfigurations, ADCS/SCCM exploitation, IMDS abuse, IAM privilege escalation, and SSRF-driven pivots.
- Strong organizational, written, and verbal communication skills.
- Willingness and eligibility to obtain a U.S. security clearance preferred.

## Nice to Have
- Offensive security certifications such as OSCP or OSWE.
- Experience with CTF competitions or bug bounty programs.

## Similar roles

- [Security Engineer](https://hotfix.jobs/jobs/1e77fe13-74e5-4087-ba99-691ee95d0e2a) - AlertMedia - Remote
- [Security Analyst, Third-Party Ecosystem Risk Management](https://hotfix.jobs/jobs/04d279a2-cca0-4b85-9c84-c8fb7b794013) - Plaid - New York, NY - $119k – $176k/yr
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Governance, Risk, and Compliance Manager](https://hotfix.jobs/jobs/5e407075-824a-4639-96f7-821772a6f497) - Decagon - San Francisco, CA - $190k – $275k/yr
- [Third-Party Risk Analyst](https://hotfix.jobs/jobs/04264cf4-1589-4c8e-a154-029c4db08751) - OpenRouter - Remote

**Apply:** https://hotfix.jobs/jobs/6767105b-558a-4ede-a843-af431cb19f26
**Canonical:** https://hotfix.jobs/jobs/6767105b-558a-4ede-a843-af431cb19f26