Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Engineer - Endpoint

$145k - $200k

Palantir Technologies

Information Security Engineer Focused on Windows and Active Directory

Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.

The Role

We're looking for someone who has spent years thinking adversarially about Windows and Active Directory — not just operating them, but understanding every layer of how they can be abused, detected, and hardened. If you've written detections for DCSync, built hunting pipelines around Kerberos ticket anomalies, or reverse-engineered a novel persistence mechanism in a Windows kernel driver, this is the team you want to be on. As an Information Security Engineer focused on Windows and Active Directory, you'll own the security of Palantir's global Windows infrastructure. Your team runs 24/7 prevention, detection, and investigation of security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.

Core Responsibilities

  • Own the security posture of Palantir's Windows and Active Directory estate — hardening, configuration standards, and ongoing validation that those standards hold.
  • Reduce attack surface across AD: audit and remediate misconfigurations, legacy protocol exposure, excessive privilege, Kerberos delegation abuse, and tier model violations.
  • Evaluate, deploy, and own the configuration of defensive tooling across the Windows environment: EDR, PAM, identity threat detection, and endpoint hardening controls.
  • Build and maintain automation for security operations across Windows infrastructure — patching pipelines, configuration drift monitoring, access reviews, and credential hygiene.
  • Partner with Identity and Infrastructure teams to drive architectural improvements: tiered administration, Protected Users, LAPS, Credential Guard, and authentication policy silos.
  • Translate findings from assessments and red team exercises into durable fixes — configuration changes, architectural improvements, and policy updates that reduce recurrence.

What We're Looking For

Active Directory
  • Deep, working knowledge of AD architecture: sites and services, replication, trust relationships, delegation models, and the LDAP schema.
  • Hands-on experience investigating and detecting AD attacks across the full kill chain — from initial enumeration through domain dominance.
  • Familiarity with attack tooling (BloodHound, Impacket, Rubeus, Mimikatz, CrackMapExec) and, critically, what they leave behind.
  • Experience hardening AD environments: tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos.
Windows Internals
  • Thorough understanding of Windows security architecture: access tokens, privilege model, integrity levels, LSASS and credential storage, SAM, and the Security Reference Monitor.
  • Ability to read and interpret Windows kernel structures, driver behavior, and undocumented APIs when necessary.
  • Proficiency with low-level analysis tools: WinDbg, Process Monitor, Process Hacker, Volatility, and x64dbg.
  • Experience with ETW-based telemetry pipelines and building detections on top of raw Windows event data.
Detection & Response
  • Proven track record writing high-fidelity detection logic, not just tuning vendor signatures.
  • Experience leading complex incident response investigations, including those involving nation-state or sophisticated criminal actors.
  • Strong forensic fundamentals across disk, memory, and network artifacts on Windows systems.

What We Value

  • Experience with Entra ID (Azure AD), hybrid identity architectures, and cloud-based attack paths that pivot through on-prem AD.
  • Prior work in adversary simulation, red teaming, or offensive security research — especially against AD targets.
  • Public contributions: conference talks (BlueHat, BSides, SANS, etc.), blog posts, or open-source tooling.

What We Require

  • 5+ years of hands-on security experience, with the majority focused on Windows environments and Active Directory.
  • Proficiency in Python or PowerShell for detection development, automation, and forensic tooling.
  • Active TS/SCI security clearance, or eligibility and willingness to obtain one.
  • A portfolio of real work: detections you've written, research you've published, tools you've built, or incidents you've led.
Salary

The estimated salary range for this position is estimated to be $145,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individual's relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.

Our benefits aim to promote health and wellbeing across all areas of Palantirians' lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies.

Benefits

• Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance

• Employees are automatically covered by Palantir's basic life, AD&D and disability insurance

• Commuter benefits

• Take what you need paid time off, not accrual based

• 2 weeks paid time off built into the end of each year (subject to team and business needs)

• 10 paid holidays throughout the calendar year

• Supportive leave of absence program including time off for military service and medical events

• Paid leave for new parents and subsidized back-up care for all parents

• Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation

• Stipend to help with expenses that come with a new child

• Employees can enroll in Palantir's 401k plan

Life at Palantir

We want every Palantirian to achieve their best outcomes, that's why we celebrate individuals' strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians' lives is just one of the ways we're investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region.

In keeping consistent with Palantir's values and culture, we believe employees are "better together" and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for "Remote" work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office.

If you want to empower the world's most important institutions, you belong here. Palantir values excellence regardless of background. We are proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.

Please note that you will never be asked to submit a payment or share financial information to participate in our interview process. If you suspect that you've been contacted by a scammer, we recommend you cease all communication with the individual and consider reporting them to the relevant authorities, such as the US FBI Internet Crime Complaint Center (IC3). If you would like to understand more about how your personal data will be processed by Palantir, please see our

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Information Security Engineer - Endpoint in Washington DC vacancy
  •  ...Description We are seeking an experienced Information Security Engineer to help strengthen our enterprise security program. This role is responsible...  ...Support enterprise security initiatives across networks, endpoints, identity platforms, and office environments Lead... 
    Suggested
    Work at office

    Municipal Securities Rulemaking Board

    Washington DC
    5 days ago
  • $145k - $200k

     ...an Insider Threat Detection Engineer, you are responsible for protecting...  ...and genuine passion for security. You work well on a team, are...  ...insider risk Influence and inform security controls designed to...  ...similar Familiarity with endpoint telemetry and log sources from... 
    Suggested
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    1 day ago
  •  ...Information Security Engineer IV The Information Security Engineer IV is a key member of the cyber security team that is responsible for designing...  ...infrastructure, cloud and on-premise applications, user endpoints, and other Technology Resources. The ideal candidate is... 
    Suggested
    Full time

    Dechert

    Washington DC
    1 day ago
  • $166k - $253k

     ...ABOUT THE JOB We're seeking a Security Software Engineer to develop novel security tooling for...  ...candidate can develop, test, and debug an endpoint detection and response agent with...  ...recovery, and whatever comes next. For more information, Explore Our Benefits. Protecting... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    1 day ago
  • $52 - $58 per hour

     ...Description: Short Description: The Endpoint Engineer/Administrator shall assist with implementing and operating Endpoint Security infrastructure to protect the DCGOV IT...  ...and macOS. • Provide up to date information on SW updates and alerts. • Support team... 
    Suggested
    Hourly pay
    Permanent employment

    AHU Technologies, Inc.

    Washington DC
    5 days ago
  •  ...interface and collaborate with other Cybersecurity/Information Assurance (IA) professionals (ISSMs, ISSOs), Security professionals (CPSOs, FSOs), and System...  ...experience related to Information Assurance/Cyber Engineering requirements, development, and implementation.... 

    MRINetwork

    Arlington, VA
    1 day ago
  •  ...solutions in Digital Transformation, Advanced Engineering, Physical Sciences Research, Platform...  ...to query, retrieve, and analyze information to complete assignments. Strong attention...  ...able to obtain and maintain a Secret security clearance. Due to the sensitivity of... 
    Work experience placement
    Work at office
    Local area

    First Command Financial Services

    Washington DC
    5 days ago
  •  ...Government customer to provide rapid deployment and management of secure cloud-based engagement kits for cyber incident response...  ...digital infrastructure when it matters most. The Information Security Engineer will ensure the security, compliance, and resilience of... 
    Contract work
    Local area

    Nightwing

    Arlington, VA
    1 day ago
  •  ...Validating required fields and ensure applicable CIM (Common Information Model) compliance. Implement requirements on source hosts to...  ...Update documentation as required. Collaborate with other Cyber Security Operations teams to document and implement logging and... 
    Work experience placement

    Saxon Global

    Washington DC
    1 day ago
  •  ...Information Security Engineering Manager Manage AWS Security tools (such as GuardDuty, Trusted Advisor, Secret Manager, Parameter Store, Inspector) Create AWS CloudFormation and manage AWS Security Groups. Implement Python code and AWS Lambda function to automate security... 

    Omni Inclusive

    Washington DC
    1 day ago
  • A leading defense contractor in Bethesda, Maryland seeks an experienced Information Systems Security Engineer (ISSE) SME. You will design and implement secure information systems that protect mission operations. This role requires collaboration with multidisciplinary teams... 
    For contractors

    Leidos

    Bethesda, MD
    1 day ago
  • $94.4k - $198.2k

     ...Job Title: Information Assurance Security Engineer/Information System Security Engineer Level 2 Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10%... 
    Full time
    Contract work
    Work experience placement
    Local area
    Flexible hours

    CACI International

    Suitland, MD
    5 days ago
  • $140k - $231k

     ...wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and...  ...their greatest potential. Title and Summary Lead Information Security Engineer Overview: The Lead Security Architect candidate... 
    Full time
    Part time
    Work experience placement
    Worldwide
    Flexible hours

    MasterCard

    Arlington, VA
    1 day ago
  • $114.08k - $152.11k

     ...growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture...  ...and issue posture and assessment reports This Lead Information Security Engineer position operates in a supportive role implementing security... 
    Temporary work
    Worldwide

    Lumen Inc

    Washington DC
    2 days ago
  • $152k - $241.5k

     ...make a lasting impact on the world. NVIDIA is looking for a Security Engineer to harden our products, services, and software development lifecycle...  ...to see: BS, MS, or PhD in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent experience. 5+... 
    Full time

    NVIDIA

    Washington DC
    22 hours ago
  • A prominent defense contractor is seeking a qualified Information System Security Engineer to lead security engineering efforts for DOJ IT environments. This senior role involves implementing security assessments, managing risk, and providing expert advisory services to... 
    For contractors

    Agile Defense, Inc.

    Washington DC
    5 days ago
  • $114.6k - $192.5k

    A leading cybersecurity firm is seeking an Information Systems Security Engineer to support a Law Enforcement organization in Washington, DC. The role requires an active Top-Secret security clearance and involves identifying security needs, defining requirements, and designing... 

    Smxtech

    Washington DC
    3 days ago
  • $86.8k - $198k

     ...Data Security Engineer Key Role: Architect, deploy, and configure data security solutions across various clients for DoD, IC, and civilian...  ...with containerization solutions Knowledge of federal information security policies, standards, procedures, directives, frameworks... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    5 days ago
  • $86.8k - $198k

     ...Job Number: R0231043 Data Security Engineer Key Role: Architect, deploy, and configure data security solutions across various clients...  ...with containerization solutions Knowledge of federal information security policies, standards, procedures, directives,... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    1 day ago
  •  ...Job Title: Security Endpoint Engineer/Admin Location:200 I St, SE- Washington DC Duration: 12+ Months Description: The Endpoint Engineer/Administrator will be intimately familiar with next generation Endpoint management/protection platforms... 

    InstantServe LLC

    Washington DC
    3 days ago
  •  ...Job Title: Security Endpoint Engineer/Admin Location: Washington DC (ONSITE) Job Description: Specific knowledge, skills, and abilities required by the incumbent to successfully fulfill the Major Duties and perform the Tasks required for... 

    InstantServe LLC

    Washington DC
    3 days ago
  • $161k - $266k

     ...digital payments choices, making transactions secure, simple, smart and accessible. Our...  ...and Summary Lead Data & AI Security Engineer Who is Mastercard? Mastercard is a...  ...initiatives. The BSE team is a worldwide group of information security experts focused on helping... 
    Full time
    Part time
    Worldwide
    Flexible hours

    MasterCard

    Arlington, VA
    21 days ago
  • $149k - $248k

     ...regulated commercial clients to design, engineer, and operate modern security capabilities that enable mission...  .... Design and implement endpoint and device security controls, integrating...  ...Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related... 
    Temporary work
    Remote work
    Flexible hours

    Guidehouse

    Washington DC
    1 day ago
  •  ...Sr. Endpoint Security Engineer Category: Analytics and Emerging Digital Technologies Main location: United States, District of Columbia...  ...to be successful in this role: • Bachelor’s degree in information technology, Cybersecurity, Computer Science, Information... 
    Full time
    Local area

    CGI Technologies and Solutions, Inc.

    Washington DC
    5 days ago
  • $55 - $65 per hour

     ...IT - Systems Engineer III Location: Home, District of Columbia (Onsite) Employment Type: Contract Role Overview This position is for a Senior Information Systems Engineer focused on Endpoint Security and Certification & Accreditation (C&A). The role involves... 
    Contract work

    Apex Systems

    Washington DC
    4 days ago
  •  ...services. Your Role ~ As the IT Security Engineer, you will work collaboratively with the...  ...Certification, active CISSP (Certified Information Systems Security Professional)...  ...application coding, firewall rule management, endpoint detection and response tools, Anti-... 
    Flexible hours
    Weekend work

    IntraFi

    Arlington, VA
    4 days ago
  • $84 - $90 per hour

     ...Description: Short Description: Information Assurance and Security Specialist - Master Hybrid, full-...  ...technologies using Azure cloud. Cloud Engineer leads the design and support of...  ...• Good understanding of server/endpoint operating system (Required)... 
    Hourly pay
    Permanent employment
    Full time
    Work from home
    Flexible hours

    AHU Technologies, Inc.

    Washington DC
    4 days ago
  •  ...Senior Security Engineer Job Locations US-MD-Bethesda Job ID 2026-37...  ...security impact analysis. Optimize endpoint security using tools like HCL BigFix for...  ...standards and guidelines. Implement Information Security Continuous Monitoring (ISCM)... 
    Full time
    Local area
    Immediate start

    NetImpact Strategies

    Bethesda, MD
    5 days ago
  •  ...Information Security Cloud Engineer Location: Greenbelt, MD Position Type: Contract Required Experience: • Amazon Web Services (AWS) platform capabilities and best practices architectures, and engineering solutions within multiple Cloud Service Experience working... 
    Contract work

    Staffing the Universe

    Greenbelt, MD
    5 days ago
  •  ...Associate Security Engineer AAMVA's Security team is looking for a highly motivated, self-...  ...primarily tasked with the monitoring of information security systems in the Microsoft...  ...from Azure Monitor, Entra ID, NSGs, and endpoint agents to identify anomalous or suspicious... 
    Work experience placement
    Flexible hours

    AAMVA (American Association of Motor Vehicle Administrators)

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Engineer - Endpoint. Be the first to apply!