Information Security Engineer - Insider Risk

Palantir Palantir · Enterprise · Seattle, WA · Information Security

Information Security Engineer focused on insider threat detection and response, involving engineering and automating detection workflows, developing alerting strategies, investigating security events, and influencing security controls. Requires experience in security platforms, Python/PowerShell, endpoint telemetry, and SIEM/SOAR.

What you'd actually do

  1. Engineer and automate end-to-end detection and investigation workflows, continuously improving Detection and Response infrastructure
  2. Develop alerting and detection strategies to identify malicious or anomalous behavior, including new and novel defensive techniques that adapt to evolving adversary tactics and tradecraft
  3. Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications.
  4. Investigate security events and active attacks across the enterprise, uncovering sophisticated threats and identifying patterns of behavior that indicate insider risk
  5. Influence and inform security controls designed to safeguard Palantir's most critical assets

Skills

Required

  • Python
  • PowerShell
  • Endpoint telemetry
  • SIEM
  • SOAR
  • Forensics
  • Threat intelligence
  • Incident Response
  • Detection Engineering
  • AWS
  • Azure
  • Windows
  • OS X
  • Linux

Nice to have

  • Python (preferred)

What the JD emphasized

  • Extensive security experience (3+ years) in at least one major platform (e.g. AWS, Azure, Windows, OS X, Linux, etc.)
  • Proficiency in Python (preferred), PowerShell, or similar
  • Familiarity with endpoint telemetry and log sources from at least one major operating system
  • Experience with common SIEM/SOAR platforms and proficiency writing queries against security event data
  • Active TS/SCI security clearance or eligibility to obtain a security clearance.