Information Security Engineer - Insider Risk
Develops detection strategies and automates workflows to identify insider risks and sophisticated threats. Investigates security events using forensics and requires 3+ years experience with platforms like AWS/Linux and tools like SIEM/SOAR.
About the job
Core Responsibilities
- Engineer and automate end-to-end detection and investigation workflows, continuously improving Detection and Response infrastructure
- Develop alerting and detection strategies to identify malicious or anomalous behavior, including new and novel defensive techniques that adapt to evolving adversary tactics and tradecraft
- Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications.
- Investigate security events and active attacks across the enterprise, uncovering sophisticated threats and identifying patterns of behavior that indicate insider risk
- Influence and inform security controls designed to safeguard Palantir's most critical assets
- Partner closely with other members of the Information Security team to lead changes in the company's network defense posture.
What We Value
- Broad exposure to multiple security subject areas, including a strong background in forensics or threat intelligence
- Deep exposure in Incident Response or Detection Engineering
- Desire to further the information security community through substantive contributions (e.g. conference talks, blog posts, public tool development, etc.)
- Comfort in operating autonomously and engaging across business levels to advise on security outcomes.
What We Require
- Extensive security experience (3+ years) in at least one major platform (e.g. AWS, Azure, Windows, OS X, Linux, etc.)
- Proficiency in Python (preferred), PowerShell, or similar
- Familiarity with endpoint telemetry and log sources from at least one major operating system
- Experience with common SIEM/SOAR platforms and proficiency writing queries against security event data
- Active TS/SCI security clearance or eligibility to obtain a security clearance.
Skills
Python, PowerShell, SIEM, Soar, AWS, Azure, Linux, Windows, Forensics, Incident Response
Similar jobs
Security Engineering jobsSecurity Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.
Designs and incubates technical defenses against complex abuse and fraud across Stripe’s payment, onboarding, identity, and Connect surfaces. Requires 3+ years of security or software engineering experience, strong production programming and SQL skills, and expertise in API safeguards and automated testing.
The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.