The opportunity
The estimated salary range for this position is estimated to be $145,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives.
What you'll do
Conduct hybrid web application penetration tests that combine source code: review with runtime exploitation across our products and internal tooling.
Perform external network penetration tests against internet-facing: infrastructure, identifying exposed services, misconfigurations, and paths to obtain an initial foothold.
Perform internal network and Active Directory security assessments,: identifying privilege escalation paths, lateral movement opportunities, and misconfigurations.
Assess the security of cloud and containerized infrastructure, including: identity, network, and workload configurations.
Collaborate with detection engineering to validate telemetry and detection: coverage against real-world attack techniques uncovered during engagements.
Scope and manage third-party pentest engagements end-to-end, critically: review results, and work cross-functionally to convert findings into prioritized, actionable remediation.
What they're looking for
- Partner with engineering to reproduce, prioritize, and verify fixes for the issues that are surfaced.
- Design and build offensive security tooling and automation tailored to Palantir's stack.
- Author clear, actionable write-ups and readouts for technical and: non-technical stakeholders, translating findings into business risk and prioritized action.
- Demonstrated strength in web application penetration testing, with the: ability to move fluidly between source code review and runtime testing.