CareerPlanGet AI match score →

Information Security Engineer - Insider Risk

New York, NY💼 Full-time💰 $145,000–$145,000🗓 2026-04-14 → 2026-07-31

Core

Engineer and automate end-to-end detection and investigation workflows to prevent, detect, and investigate security events and insider risks across the enterprise.

Role type

Senior IC insider threat detection engineer

Builds

Detection and Response infrastructure and alerting strategies

Domain

Cybersecurity / Insider Threat / Threat Intelligence

Deliverable

production ML models | product features | dashboards & analysis | infrastructure

Required skills

Security forensics, Threat intelligence, Incident response, SIEM/SOAR query writing, Endpoint telemetry analysis, Network/host/memory artifact analysis, Python, PowerShell, Multi-platform OS experience (AWS/Azure/Windows/Linux/macOS)

Preferred skills

Conference talks, Public tool development, Autonomous operation

Technologies

SIEM, SOAR, Python, PowerShell, AWS, Azure, Windows, OS X, Linux

Responsibilities

Engineer and automate detection and investigation workflows, Develop alerting strategies for malicious or anomalous behavior, Dissect network/host/memory artifacts, Investigate security events and active attacks, Influence security controls, Partner with the Information Security team to lead defense posture changes

Seniority

Senior, hands-on IC

Rewrite
## Responsibilities - Engineer and automate end-to-end detection and investigation workflows, continuously improving Detection and Response infrastructure - Develop alerting and detection strategies to identify malicious or anomalous behavior, including new and novel defensive techniques that adapt to evolving adversary tactics and tradecraft - Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications - Investigate security events and active attacks across the enterprise, uncovering sophisticated threats and identifying patterns of behavior that indicate insider risk - Influence and inform security controls designed to safeguard Palantir's most critical assets - Partner closely with other members of the Information Security team to lead changes in the company's network defense posture ## Requirements - Extensive security experience (3+ years) in at least one major platform (e.g. AWS, Azure, Windows, OS X, Linux, etc.) - Proficiency in Python (preferred), PowerShell, or similar - Familiarity with endpoint telemetry and log sources from at least one major operating system - Experience with common SIEM/SOAR platforms and proficiency writing queries against security event data - Active TS/SCI security clearance or eligibility to obtain a security clearance ## Nice to Have - Broad exposure to multiple security subject areas, including a strong background in forensics or threat intelligence - Deep exposure in Incident Response or Detection Engineering - Desire to further the information security community through substantive contributions (e.g. conference talks, blog posts, public tool development, etc.) - Comfort in operating autonomously and engaging across business levels to advise on security outcomes ## Benefits - Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance - Employees are automatically covered by Palantir’s basic life, AD&D and disability insurance - Commuter benefits - Relocation assistance - Take what you need paid time off, not accrual based - 2 weeks paid time off built into the end of each year (subject to team and business needs) - 10 paid holidays throughout the calendar year - Supportive leave of absence program including time off for military service and medical events - Paid leave for new parents and subsidized back-up care for all parents - Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation - Stipend to help with expenses that come with a new child - Employees can enroll in Palantir’s 401k plan Life at Palantir We want every Palantirian to achieve their best outcomes, that’s why we celebrate individuals’ strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians’ lives is just one of the ways we’re investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region. In keeping consistent with Palantir’s values and culture, we believe employees are “better together” and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for “Remote” work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work onsite.
Sourced via lever · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Lever ↗