Skip to content
PalantirPalantir

Information Security Engineer - Insider Risk

Develops detection strategies and automates workflows to identify insider risks and sophisticated threats. Investigates security events using forensics and requires 3+ years experience with platforms like AWS/Linux and tools like SIEM/SOAR.

About the job

Core Responsibilities

  • Engineer and automate end-to-end detection and investigation workflows, continuously improving Detection and Response infrastructure
  • Develop alerting and detection strategies to identify malicious or anomalous behavior, including new and novel defensive techniques that adapt to evolving adversary tactics and tradecraft
  • Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications.
  • Investigate security events and active attacks across the enterprise, uncovering sophisticated threats and identifying patterns of behavior that indicate insider risk
  • Influence and inform security controls designed to safeguard Palantir's most critical assets
  • Partner closely with other members of the Information Security team to lead changes in the company's network defense posture.

What We Value

  • Broad exposure to multiple security subject areas, including a strong background in forensics or threat intelligence
  • Deep exposure in Incident Response or Detection Engineering
  • Desire to further the information security community through substantive contributions (e.g. conference talks, blog posts, public tool development, etc.)
  • Comfort in operating autonomously and engaging across business levels to advise on security outcomes.

What We Require

  • Extensive security experience (3+ years) in at least one major platform (e.g. AWS, Azure, Windows, OS X, Linux, etc.)
  • Proficiency in Python (preferred), PowerShell, or similar
  • Familiarity with endpoint telemetry and log sources from at least one major operating system
  • Experience with common SIEM/SOAR platforms and proficiency writing queries against security event data
  • Active TS/SCI security clearance or eligibility to obtain a security clearance.

Skills

Python, PowerShell, SIEM, Soar, AWS, Azure, Linux, Windows, Forensics, Incident Response

Datadog

Datadog

New York, NY

Security Engineer 2 - Cyber Threat Intelligence
$140k+/yrHybridSecurity Engineering

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

Stripe

Stripe

United States

Security Engineer
No salary listedRemote3+ YOESecurity Engineering

Designs and incubates technical defenses against complex abuse and fraud across Stripe’s payment, onboarding, identity, and Connect surfaces. Requires 3+ years of security or software engineering experience, strong production programming and SQL skills, and expertise in API safeguards and automated testing.

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.