A World-Changing Company
Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.
The Role
As a Defensive Security Analyst, you are responsible for the security of Palantir’s people and infrastructure around the globe. Your technical expertise is second only to your integrity and real passion for security and technology in general. Our ideal candidate works well on a team, is highly motivated, and enjoys solving problems and taking on new challenges.
In this role, you'll independently manage SOC systems that are essential to our security posture, ensuring they are properly engineered, maintained, and monitored.
Core Responsibilities
Build, run, and own infrastructure and automation to detect, contain, and eradicate security threatsDevelop alerting and detection strategies to identify malicious or anomalous behaviorDevelop comprehensive and accurate reports and presentations for both technical and executive audiencesDevelop new and novel defensive techniques to identify or counteract changes in adversary techniques and tacticsDissect network, host, memory, and other artifacts originating from multiple operating systems and applicationsPerform enterprise-wide operations to uncover sophisticated and undetected threatsPartner closely with other members of the Information Security team to lead changes in the company's network defense postureProvide expertise in a supporting capacity for incident response activities and digital forensics state preservation, including the capture and preservation of system logs, volatile memory captures, and hard drive (physical or virtual) image capturesConduct host forensics, network, forensics, log analysis, and malware triage in support of hunt operationsInterface with client contact(s) and staff in a constructive and professional mannerUtilize common forensic and incident response toolsWhat We Value
Knowledge of operating and maintaining a SIEMKnowledge of cloud architectures, particularly AWSExperience in penetration testingAbility to quickly learn new technologies and have an ongoing desire to stay current with the latest technologiesAbility to train others on the use of forensic and incident response techniques and toolsWhat We Require
TS/SCI ClearanceEstablished experience in operating in SOC environment, either through relevant experience or qualificationsExperience with programming or scripting languages such as PowerShell, Python, and BashWillingness and ability to commute to our Georgetown office within one hour when on-call