Application Security Engineer

Palantir Palantir · Enterprise · Seattle, WA · Information Security

Application Security Engineer responsible for product security reviews, architecture and design, strategic security initiatives, and vulnerability identification and analysis. Focuses on enabling developers to produce secure software for Palantir's mission-critical products.

What you'd actually do

  1. Perform full-scope security reviews of our current and future product and service portfolio.
  2. Be the security subject matter expert for product architects and engineers.
  3. Own transformational security initiatives that impact the whole company.
  4. Finding new and novel ways to identify and resolve security vulnerabilities in our products.

Skills

Required

  • Development or software engineering experience
  • Deep passion for information security
  • Experience with a modern high-level programming language (e.g. Java, Golang, Javascript, Python, etc.)
  • Demonstrated experience evaluating code for vulnerabilities and weaknesses
  • Experience with complex architectures and codebases (e.g. SOA or micro-services)
  • Experience utilizing/with CodeQL or other static code analysis platforms
  • Experience performing black-box testing of web applications

Nice to have

  • Curiosity
  • Tenacity
  • Drive to be a world-class security engineer
  • Self motivated
  • Experience in solving complex problems
  • History and experience designing and shipping production-ready software
  • Strong communication and collaboration skills
  • Ability to learn and apply new technologies quickly and in complex deployments

What the JD emphasized

  • advanced persistent threats
  • mission-critical information
  • mission-critical work
  • secure-by-default
  • security reviews
  • security subject matter expert
  • security initiatives
  • security automation
  • security problems
  • security improvements
  • security engineer
  • software engineering experience
  • information security
  • code for vulnerabilities
  • complex architectures
  • static code analysis
  • black-box testing