Application Security Engineer

Palantir Palantir · Enterprise · Remote: United States · Information Security

Application Security Engineer role focused on product security reviews, architecture and design, strategic security initiatives, and vulnerability identification and analysis for Palantir's software products. This role involves hands-on security assessments and influencing product design to ensure security by default, with a focus on protecting mission-critical information against advanced threats.

What you'd actually do

  1. Product security reviews. You will perform full-scope security reviews of our current and future product and service portfolio. This includes whitebox, greybox, and blackbox assessments. You will work with offensive security teams, engineering teams, and other members of the InfoSec organization to harden our products against our dedicated adversaries.
  2. Architecture and design. You will be the security subject matter expert for product architects and engineers. You will threat model, assess risks, and help implement security controls and mitigations to address identified issues. You will directly steer the design of our products to ensure we are secure-by-default.
  3. Strategic security initiatives. You will be empowered to own transformational security initiatives that impact the whole company. Members of the Application Security Team have implemented software supply chain security controls (e.g., in-toto), implemented hardware-backed GPG key signing for commits, developed new security services, implemented security automation, or worked on massive-scale security problems.
  4. Vulnerability identification and analysis. You will be responsible for finding new and novel ways to identify and resolve security vulnerabilities in our products. This includes static and dynamic code analysis, security scanning, investigation of security reports from InfoSec, our bug bounty program, or other trusted partners, and direct work with our incident response team on product security issues and incidents.

Skills

Required

  • Application security
  • Security reviews (whitebox, greybox, blackbox)
  • Threat modeling
  • Risk assessment
  • Security controls implementation
  • Software supply chain security
  • Static and dynamic code analysis
  • Security scanning
  • Incident response

Nice to have

  • Curiosity
  • Tenacity
  • Drive to be a world-class security engineer

What the JD emphasized

  • mission-critical information
  • advanced persistent threats
  • secure-by-default
  • security subject matter expert
  • security reviews
  • vulnerability identification and analysis
  • security initiatives