Application Security Engineer

Palantir Palantir · Enterprise · Washington, DC · Information Security

Application Security Engineer at Palantir, focusing on product security reviews, architecture, strategic initiatives, and vulnerability identification to ensure the security of Palantir's mission-critical software for defense, intelligence, and commercial applications.

What you'd actually do

  1. Perform full-scope security reviews of our current and future product and service portfolio.
  2. Be the security subject matter expert for product architects and engineers.
  3. Own transformational security initiatives that impact the whole company.
  4. Be responsible for finding new and novel ways to identify and resolve security vulnerabilities in our products.

Skills

Required

  • Development or software engineering experience
  • Deep passion for information security
  • Experience with a modern high-level programming language (e.g. Java, Golang, Javascript, Python, etc.)
  • Demonstrated experience evaluating code for vulnerabilities and weaknesses
  • Experience with complex architectures and codebases (e.g. SOA or micro-services)
  • Experience utilizing/with CodeQL or other static code analysis platforms
  • Experience performing black-box testing of web applications

Nice to have

  • whitebox, greybox, and blackbox assessments
  • offensive security teams
  • engineering teams
  • InfoSec organization
  • product architects
  • security subject matter expert
  • security controls and mitigations
  • incident response team
  • software supply chain security controls (e.g., in-toto)
  • hardware-backed GPG key signing for commits
  • security automation
  • static and dynamic code analysis
  • security scanning
  • bug bounty program
  • product security issues and incidents
  • security improvements
  • curiosity
  • tenacity
  • drive to be a world-class security engineer
  • deep architecture and security reviews on highly complex products
  • lead engineering teams in feature design
  • threat modeling
  • security-critical code and architecture
  • develop and implement automation to eliminate entire classes of weaknesses across the organization
  • drive decision-making by determining the tradeoffs between security and product design
  • lead implementation of strategic security initiatives that improve security across Palantir
  • self motivated
  • experience in solving complex problems
  • history and experience designing and shipping production-ready software
  • strong communication and collaboration skills
  • comfortable working closely with engineering teams
  • ability to learn and apply new technologies quickly and in complex deployments

What the JD emphasized

  • mission-critical information
  • advanced persistent threats
  • mission critical work
  • security reviews
  • threat model
  • security controls and mitigations
  • secure-by-default
  • security initiatives
  • software supply chain security
  • security automation
  • security problems
  • security vulnerabilities
  • product security issues and incidents
  • security improvements
  • world-class security engineer
  • security reviews
  • threat modeling
  • security-critical code and architecture
  • security across the organization
  • security and product design
  • security initiatives
  • information security
  • evaluating code for vulnerabilities and weaknesses
  • complex architectures and codebases
  • static code analysis platforms
  • black-box testing