Offensive Security Engineer
Full-time
Palantir
Responsibilities
- Conduct hybrid web application penetration tests combining source code review with runtime exploitation.
- Perform external network penetration tests against internet-facing infrastructure and internal network and Active Directory assessments.
- Assess cloud and containerized infrastructure, including identity, network, workload, and orchestration configurations.
- Chain findings into realistic attack paths involving privilege escalation, lateral movement, and cloud control-plane access.
- Collaborate with detection engineering to validate telemetry and detection coverage against real-world attack techniques.
- Scope and manage third-party penetration testing engagements, review results, and convert findings into prioritized remediation.
- Partner with engineering teams to reproduce, prioritize, and verify security fixes.
- Design and build offensive security tooling and automation tailored to Palantir’s technology stack.
- Design and validate agentic, LLM-driven offensive security tooling on live assessments.
- Write clear technical and non-technical findings, readouts, business-risk explanations, and prioritized remediation guidance.
Requirements
- At least 4 years of professional experience in offensive security, penetration testing, red teaming, or a closely related field.
- Proficiency in at least one scripting or programming language, such as Python or Go, sufficient to build and adapt testing tooling.
- Demonstrated experience assessing cloud environments including AWS, Azure, or GCP and containerized environments including Docker or Kubernetes.
- Demonstrated strength in web application penetration testing across source code review and runtime testing.
- Demonstrated strength in external and internal network penetration testing, including attack-surface enumeration, exploitation, foothold establishment, and lateral access expansion.
- Working knowledge of CI/CD pipelines, infrastructure-as-code, cloud security, container security, and orchestration security.
- Understanding of identity and cloud attack paths, including Kerberos abuse, Active Directory delegation misconfigurations, ADCS/SCCM exploitation, IMDS abuse, IAM privilege escalation, and SSRF-driven cloud pivots.
- Clear written and verbal communication and the ability to explain vulnerabilities, impacts, and fixes to engineers and other stakeholders.
- Offensive security certifications such as OSCP or OSWE, CTF competition experience, or bug bounty experience are preferred but not required.
- Eligibility and willingness to obtain a U.S. security clearance is preferred.
Benefits
- Medical, dental, vision, and voluntary life insurance options
- Employer-provided basic life, AD&D, and disability insurance
- Commuter benefits and relocation assistance
- Take-what-you-need paid time off, plus two weeks of paid year-end time off subject to business needs
- 10 paid holidays
- Supportive leave of absence program, including military and medical leave
- Paid parental leave and subsidized backup care
- Fertility and family-building benefits
- New-child expense stipend
- 401(k) plan
- Employees are encouraged to work from company offices; many teams offer hybrid work one or two days per week, with limited exceptional remote options
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in Washington DC vacancy
$145k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds... ...children, and more.The RolePalantir's Offensive Security team probes our own products,... ...would. As an Offensive Security Engineer, you will test internal applications and...SuggestedFull timeWork experience placementWork at officeRemote workWork from homeRelocation package$160k - $205k
...work with some of the best information security professionals in the world in challenging... ...Pentester to join a team of world-class offensive security professionals. In this role, you... ...and experience by mentoring junior engineers, and assist with monitoring and response...SuggestedFull timeWork at officeRemote workShift workDay shift- ...disruptions, locate missing children, and more.The Role Palantir's Offensive Security team probes our own products, infrastructure, and cloud... ...the way a real attacker would. As an Offensive Security Engineer, you will test internal applications and infrastructure, chain...Suggested
- ...Description Apogee Global RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role is designed for operators who bring hands‑on offensive tradecraft, current certifications, and recent red...SuggestedFull time
- ...Program Manager, the Web Developer Embeds security across the SDLC for mission-critical... ...management ~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl. .NET... ...more of — AppSec: CSSLP / GWEB / CASE; Offensive: OSWE / OSCP; Foundational: Security+ /...SuggestedFull time
- ...platform and our Autonomous Exposure Validation (AEV) product. About The Role We're looking for a technically strong Sales Engineer with an offensive security background to join our US sales team. You will be the trusted technical voice in the sales cycle, helping clients...Remote job
$135k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds... ....The Role As a Senior Identity Security Engineer on Palantir's Identity Security team,... ...against identity telemetryRed team, offensive security, or incident response background...Full timeWork experience placementWork at officeRemote workWork from homeRelocation packageShift work- ...goals of our clients. Position Title: Web Developer Security Engineer Location: US Congressional Budget Office Ford House... ...(EC-Council Certified Application Security Engineer). Offensive Security: OSWE (OffSec Web Expert); OSCP (Offensive Security...Work at officeLocal areaRemote work
$145k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds... ...Kerberos ticket anomalies, or reverse-engineered a novel persistence mechanism in a... ...in adversary simulation, red teaming, or offensive security research — especially against AD...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package$117.2k - $176.7k
...the future of Salesforce.The ExperienceThe Product Security team is seeking a Mobile Security Engineer who will own the security posture of Salesforce's mobile... ...Mobile Device Security Analyst (GMOB), or general offensive certifications such as Offensive Security Certified...Full time$115k - $190k
...Web Developer Security Engineer Clearance Requirement: Public Trust (Tier 2) Location: Remote/Hybrid (as approved by customer) Position... ...Web Application Penetration Tester (GWEB), OR CASE Offensive Security (One Required): OSWE, OR OSCP Foundational...Remote work$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...InternshipFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...InternshipFlexible hoursShift work$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...InternshipFlexible hours$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$100k - $110k
...enterprise software architectures that support the bank’s information security operations functions. This role performs feedback and... ...bank. The position serves as a technical resource for security engineering initiatives, applying advanced knowledge to evaluate, build, and...Temporary workRemote workFlexible hours$107.93k - $188.9k
Position Summary Deloitte’s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM...Remote work$145k - $192.5k
...Description:Bank of America’s Global Information Security (GIS) team is seeking a Cyber Threat Defense AI Security Senior Engineer to drive the integration of advanced AI... ...candidate will have deep expertise in AI/ML, offensive and defensive security operations, and large...Full timeWork at officeShift workDay shift- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
- ...Responsibilities The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance... ...as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to...Full timeNight shift
$230k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications...Work at officeLocal areaRemote workRelocation packageFlexible hours$120k - $130k
Job DescriptionEverforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a technically experienced Identity Security Engineer to join our security operations division...Work at officeRemote work$5,000 per month
...Candidates who are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated work and will be performed in Dahlgren, Virginia.The Security...Work at office- ...20 years, our team provides expertise in network, system engineering and both offensive and defensive cybersecurity operations.What we do:Our vision... ...the right person to plan, analyze, design, develop, test, secure, integrate, implement, operate, and maintain the custom...Temporary workLocal area
- ...project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...Washington, DCJob DescriptionThe Identity and Authentication Security Engineer/Admin will be responsible for technical support to security...Remote work
$110k - $135k
...00 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk, BloodHound...Full timeTemporary workFor contractorsH1bWorldwide- The Johns Hopkins University Applied Physics Laboratory (APL) seeks researchers to build AI-enabled capabilities for reverse engineering and vulnerability research. This is not traditional software development; it requires designing AI-native architectures, orchestrating...
- ...Maryland is seeking professionals passionate about building AI-enabled capabilities in cybersecurity. The role focuses on reverse engineering and vulnerability research, requiring collaboration with multi-disciplinary experts. Ideal candidates will have strong AI systems...
- ...teams support the federal government’s most critical national security and defense priorities, helping protect the nation, strengthen... ...mission begins. Ardent is seeking a Web Developer Security Engineer to join our team. This position is based in Washington, DC...Full timeLocal areaRemote workFlexible hours
$5,000 per month
...Imagine One Technology & Management, Ltd. is seeking one (1) Security Software Engineer. This position is contingent upon award of the associated... ...Strike Associated Training: Certified Ethical Hacker or Offensive Security Certified Professional and;Documented experience...For contractors
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!
Related searches
- information technology security engineer Washington DC
- application security engineer Washington DC
- senior cloud security engineer Washington DC
- security software engineer Washington DC
- sr security engineer Washington DC
- security infrastructure engineer Washington DC
- security engineer Washington DC
- cloud security engineer Washington DC
- principal security engineer Washington DC
- network security engineer Washington DC



