Application Security Engineer

Palantir Palantir · Enterprise · New York, NY · Information Security

Application Security Engineer responsible for product security reviews, architecture and design, strategic security initiatives, and vulnerability identification and analysis for Palantir's software products, which are used in defense, intelligence, and commercial applications.

What you'd actually do

  1. Perform deep architecture and security reviews on highly complex products to identify vulnerabilities
  2. Lead engineering teams in feature design, threat modeling, and security-critical code and architecture
  3. Develop and implement automation to eliminate entire classes of weaknesses across the organization
  4. Drive decision-making by determining the tradeoffs between security and product design
  5. Lead implementation of strategic security initiatives that improve security across Palantir

Skills

Required

  • Development or software engineering experience
  • deep passion for information security
  • Experience with a modern high-level programming language (e.g. Java, Golang, Javascript, Python, etc.)
  • Demonstrated experience evaluating code for vulnerabilities and weaknesses
  • Experience with complex architectures and codebases (e.g. SOA or micro-services)
  • Experience utilizing/with CodeQL or other static code analysis platforms
  • Experience performing black-box testing of web applications

Nice to have

  • Self motivated
  • experience in solving complex problems
  • History and experience designing and shipping production-ready software
  • Strong communication and collaboration skills
  • Ability to learn and apply new technologies quickly and in complex deployments

What the JD emphasized

  • dedicated adversaries
  • mission-critical information
  • mission critical work
  • secure-by-default
  • massive-scale security problems
  • world-class security engineer
  • security-critical code
  • security improvements