Information Security Engineer - Infrastructure SecurityActive$145K–$200K

The opportunity

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.

What you'll do

  • Design, implement, and improve defensive security controls across endpoints,: servers, identity systems, cloud services, SaaS applications, networks, and data flows

  • Own or contribute to security posture improvements, including hardening: standards, configuration management, vulnerability remediation, access controls, monitoring, and ongoing validation

  • Evaluate security risks in new platforms, products, architectures, vendors,: and services, and translate findings into practical recommendations and engineering work

  • Build and maintain automation for security operations, such as configuration: validation, drift monitoring, patching, access reviews, policy enforcement, alert triage, and security hygiene

  • Partner closely with Identity, Infrastructure, Engineering, Legal, and other: Information Security teams to improve security architecture and reduce recurring risk

  • Translate findings from assessments, red team exercises, incident: investigations, and operational reviews into durable fixes—including configuration changes, architectural improvements, policy updates, and automation

What they're looking for

  • Experience securing one or more major infrastructure domains, such as: Windows, macOS, Linux, Active Directory, cloud platforms, SaaS applications, networking, identity systems, or enterprise endpoints
  • A broad infrastructure security mindset and curiosity about systems outside your primary area of expertise
  • Understanding of common infrastructure attack paths, adversary tactics,: techniques, and procedures, and the security controls used to prevent, detect, and contain them
  • Ability to assess complex environments and identify how weaknesses in: identity, endpoints, applications, networks, cloud services, or data flows can combine to create security risk
  • Experience evaluating security tooling and validating that controls are: deployed effectively and continue to work as intended
  • Familiarity with infrastructure-as-code, configuration management, CI/CD, or: other approaches to making security controls repeatable and scalable