Offensive Security Engineer
Full-time
Palantir
Responsibilities
- Conduct hybrid web application penetration tests combining source code review with runtime exploitation.
- Perform external network penetration tests against internet-facing infrastructure and internal network and Active Directory assessments.
- Assess cloud and containerized infrastructure, including identity, network, workload, and orchestration configurations.
- Chain findings into realistic attack paths involving privilege escalation, lateral movement, and cloud control-plane access.
- Collaborate with detection engineering to validate telemetry and detection coverage against real-world attack techniques.
- Scope and manage third-party penetration testing engagements, review results, and convert findings into prioritized remediation.
- Partner with engineering teams to reproduce, prioritize, and verify security fixes.
- Design and build offensive security tooling and automation tailored to Palantir’s technology stack.
- Design and validate agentic, LLM-driven offensive security tooling on live assessments.
- Write clear technical and non-technical findings, readouts, business-risk explanations, and prioritized remediation guidance.
Requirements
- At least 4 years of professional experience in offensive security, penetration testing, red teaming, or a closely related field.
- Proficiency in at least one scripting or programming language, such as Python or Go, sufficient to build and adapt testing tooling.
- Demonstrated experience assessing cloud environments including AWS, Azure, or GCP and containerized environments including Docker or Kubernetes.
- Demonstrated strength in web application penetration testing across source code review and runtime testing.
- Demonstrated strength in external and internal network penetration testing, including attack-surface enumeration, exploitation, foothold establishment, and lateral access expansion.
- Working knowledge of CI/CD pipelines, infrastructure-as-code, cloud security, container security, and orchestration security.
- Understanding of identity and cloud attack paths, including Kerberos abuse, Active Directory delegation misconfigurations, ADCS/SCCM exploitation, IMDS abuse, IAM privilege escalation, and SSRF-driven cloud pivots.
- Clear written and verbal communication and the ability to explain vulnerabilities, impacts, and fixes to engineers and other stakeholders.
- Offensive security certifications such as OSCP or OSWE, CTF competition experience, or bug bounty experience are preferred but not required.
- Eligibility and willingness to obtain a U.S. security clearance is preferred.
Benefits
- Medical, dental, vision, and voluntary life insurance options
- Employer-provided basic life, AD&D, and disability insurance
- Commuter benefits and relocation assistance
- Take-what-you-need paid time off, plus two weeks of paid year-end time off subject to business needs
- 10 paid holidays
- Supportive leave of absence program, including military and medical leave
- Paid parental leave and subsidized backup care
- Fertility and family-building benefits
- New-child expense stipend
- 401(k) plan
- Employees are encouraged to work from company offices; many teams offer hybrid work one or two days per week, with limited exceptional remote options
Vacancy posted 8 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in Washington DC vacancy
$145k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds... ...children, and more.The RolePalantir's Offensive Security team probes our own products,... ...would. As an Offensive Security Engineer, you will test internal applications and...SuggestedFull timeWork experience placementWork at officeRemote workWork from homeRelocation package$160k - $205k
...work with some of the best information security professionals in the world in challenging... ...Pentester to join a team of world-class offensive security professionals. In this role, you... ...and experience by mentoring junior engineers, and assist with monitoring and response...SuggestedFull timeWork at officeRemote workShift workDay shift- ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Washington, District of Columbia; Seattle, Washington; Charlotte, North Carolina; Jacksonville, Florida; Jersey City, New Jersey; Chicago, Illinois To proceed with your application, you must be at least...SuggestedWork at officeRemote workShift workDay shift
- ...Apogee Global RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role is designed for operators who bring hands‑on offensive tradecraft, current certifications, and recent red‑team experience...SuggestedFull time
- ...Program Manager, the Web Developer Embeds security across the SDLC for mission-critical... ...management ~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl. .NET... ...more of — AppSec: CSSLP / GWEB / CASE; Offensive: OSWE / OSCP; Foundational: Security+ /...SuggestedFull time
$135k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds... ....The Role As a Senior Identity Security Engineer on Palantir's Identity Security team,... ...against identity telemetryRed team, offensive security, or incident response background...Full timeWork experience placementWork at officeRemote workWork from homeRelocation packageShift work$145k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds... ...Kerberos ticket anomalies, or reverse-engineered a novel persistence mechanism in a... ...in adversary simulation, red teaming, or offensive security research — especially against AD...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package$117.2k - $176.7k
...the future of Salesforce.The ExperienceThe Product Security team is seeking a Mobile Security Engineer who will own the security posture of Salesforce's mobile... ...Mobile Device Security Analyst (GMOB), or general offensive certifications such as Offensive Security Certified...Full time$115k - $190k
...Web Developer Security Engineer Clearance Requirement: Public Trust (Tier 2) Location: Remote/Hybrid (as approved by customer) Position... ...Web Application Penetration Tester (GWEB), OR CASE Offensive Security (One Required): OSWE, OR OSCP Foundational...Remote work$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...InternshipFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...InternshipFlexible hoursShift work$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...InternshipFlexible hours$107.93k - $188.9k
Position Summary Deloitte’s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM...Remote work$100k - $110k
...enterprise software architectures that support the bank’s information security operations functions. This role performs feedback and... ...bank. The position serves as a technical resource for security engineering initiatives, applying advanced knowledge to evaluate, build, and...Temporary workRemote workFlexible hours$120k - $130k
Job DescriptionEverforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a technically experienced Identity Security Engineer to join our security operations division...Work at officeRemote work$230k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications...Work at officeLocal areaRemote workRelocation packageFlexible hours- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
- ...Responsibilities The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance... ...as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to...Full timeNight shift
$5,000 per month
...Candidates who are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated work and will be performed in Dahlgren, Virginia.The Security...Work at office- ...20 years, our team provides expertise in network, system engineering and both offensive and defensive cybersecurity operations.What we do:Our vision... ...the right person to plan, analyze, design, develop, test, secure, integrate, implement, operate, and maintain the custom...Temporary workLocal area
- ...project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...Washington, DCJob DescriptionThe Identity and Authentication Security Engineer/Admin will be responsible for technical support to security...Remote work
$110k - $135k
...00 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk, BloodHound...Full timeTemporary workFor contractorsH1bWorldwide- The Johns Hopkins University Applied Physics Laboratory (APL) seeks researchers to build AI-enabled capabilities for reverse engineering and vulnerability research. This is not traditional software development; it requires designing AI-native architectures, orchestrating...
- ...teams support the federal government’s most critical national security and defense priorities, helping protect the nation, strengthen... ...mission begins. Ardent is seeking a Web Developer Security Engineer to join our team. This position is based in Washington, DC...Full timeLocal areaRemote workFlexible hours
$5,000 per month
...Imagine One Technology & Management, Ltd. is seeking one (1) Security Software Engineer. This position is contingent upon award of the associated... ...Strike Associated Training: Certified Ethical Hacker or Offensive Security Certified Professional and;Documented experience...For contractors$320k - $405k
...Security Engineer, Corporate Security San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC About Anthropic Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and...Work at officeVisa sponsorshipFlexible hours$237.6k - $297k
...Security Engineer, Product Security We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security...Full time$160k - $205k
...impact. Join us!Job Description:Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America’s Cyber Security Assurance Offensive Security group. The program provides services to assess the security resilience of the bank...Full timeWork at officeShift workDay shift- ...HVA Assessments using methodology by Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) program with broad and in-depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you...Work at officeLocal areaShift work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!
Related searches
- information technology security engineer Washington DC
- application security engineer Washington DC
- senior cloud security engineer Washington DC
- security software engineer Washington DC
- sr security engineer Washington DC
- security infrastructure engineer Washington DC
- security engineer Washington DC
- cloud security engineer Washington DC
- network security engineer Washington DC
- systems security engineer Washington DC



