# Offensive Security Engineer

**Company**: Palantir
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: $145,000 - $200,000/year
**Category**: IT
**Industry**: Technology

**Apply**: https://jobs.lever.co/palantir/5b1eac37-708b-4eb2-94f0-d2abe7945989?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_6786d6fe-c0e

## Description

Palantir's Offensive Security team probes their own products, infrastructure, and cloud environment like a real attacker would. As an Offensive Security Engineer, you will test internal applications and infrastructure, chain findings into realistic attack paths, and work directly with engineers to get issues closed.

You will also help design and prove out LLM-driven systems that encode operator tradecraft and apply it continuously. Additionally, you will coordinate third-party penetration testing engagements, scope work with external firms, and turn results into concrete remediation.

## Core Responsibilities

- Conduct hybrid web application penetration tests combining source code review with runtime exploitation

- Perform external network penetration tests against internet-facing infrastructure

- Perform internal network and Active Directory security assessments

- Assess cloud and containerized infrastructure security

- Collaborate with detection engineering to validate telemetry and detection coverage

- Scope and manage third-party pentest engagements end-to-end

- Partner with engineering to reproduce, prioritize, and verify fixes for issues surfaced

- Design and build offensive security tooling and automation tailored to Palantir's stack

- Author clear, actionable write-ups and readouts for technical and non-technical stakeholders

## What We Value

- Demonstrated strength in web application penetration testing

- Experience with external and internal network penetration testing

- Hands-on experience with standard offensive security tooling

- Comfortable writing code to automate testing and develop proof-of-concept exploits

- Working knowledge of modern software development and shipping

- Understanding of cloud, container, and orchestration security principles

- Offensive security certifications or a track record in CTF competitions or bug bounty programs

## What We Require

- 4+ years of professional experience in offensive security, penetration testing, or a closely related field

- Proficiency in at least one scripting or programming language

- Demonstrated experience assessing cloud and containerized environments

- Excellent organizational and communication skills

## Additional Information

- Salary: $145,000 - $200,000/year

- Benefits: medical, dental, and vision insurance, commuter benefits, relocation assistance, paid time off, and more

## Skills

### Required
- web application penetration testing
- network penetration testing
- cloud security
- containerized infrastructure
- offensive security tooling
- scripting
- programming

### Nice to have
- offensive security certifications
- CTF competitions
- bug bounty programs

---

Source: [Apply at jobs.lever.co](https://jobs.lever.co/palantir/5b1eac37-708b-4eb2-94f0-d2abe7945989?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
