Offensive Security Engineer
Core
Probes Palantir's products, infrastructure, and cloud environment as a real attacker to identify vulnerabilities and chain findings into realistic attack paths.
Role type
Senior IC offensive security engineer (red teaming & tooling)
Builds
Agentic offensive security tooling (LLM-driven systems), automation for testing, and proof-of-concept exploits
Domain
Cybersecurity, offensive security, cloud security, container security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
web application penetration testing, external network penetration testing, internal network and Active Directory security assessments, cloud and containerized infrastructure security assessment, scripting/programming (Python, Go), CI/CD pipeline security, identity and cloud attack path chaining
Preferred skills
offensive security certifications (OSCP, OSWE), CTF competition experience, bug bounty program experience
Technologies
Burp Suite, BloodHound/SharpHound, Certipy, Impacket, Responder, Pacu/ScoutSuite, Nuclei, AWS, Azure, GCP, Docker, Kubernetes
Responsibilities
Conduct hybrid web application penetration tests combining source code review with runtime exploitation. Perform external network penetration tests against internet-facing infrastructure. Perform internal network and Active Directory security assessments. Assess security of cloud and containerized infrastructure. Collaborate with detection engineering to validate telemetry and detection coverage. Scope and manage third-party pentest engagements end-to-end. Partner with engineering to reproduce, prioritize, and verify fixes. Design and build offensive security tooling and automation. Author clear, actionable write-ups and readouts for stakeholders.
Seniority
Senior, hands-on IC