> Markdown version of [/jobs/ext/2718544-information-security-engineer-insider-risk](https://www.wearedevelopers.com/jobs/ext/2718544-information-security-engineer-insider-risk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - Insider Risk - **Company:** Palantir Technologies - **Location:** New York, United States (Remote available) - **Experience:** Experienced - **Salary:** $145,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Cyber Security, Database Queries, Linux, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Security Information and Event Management - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/information-security-engineer-insider-risk-palantir-7927633 ## About the Role * Extensive security experience (3+ years) in at least one major platform (e.g. AWS, Azure, Windows, OS X, Linux, etc.) * Proficiency in Python (preferred), PowerShell, or similar * Familiarity with endpoint telemetry and log sources from at least one major operating system * Experience with common SIEM/SOAR platforms and proficiency writing queries against security event data ## Description As an Insider Threat Detection Engineer, you are responsible for protecting Palantir's people, data, and most sensitive assets across the globe. Your technical expertise is matched by your integrity and genuine passion for security. You work well on a team, are highly motivated, and thrive on solving problems and taking on new challenges. Your team serves as a critical line of defense, responsible for the 24/7 prevention, detection, and investigation of security events and active threats across Palantir's environment. This role focuses on all aspects of Detection and Response with a strong emphasis on identifying and mitigating insider risks. Your work will directly impact the success of Palantir's mission by making it difficult for adversaries - both external and internal - to compromise our global network. Core Responsibilities * Engineer and automate end-to-end detection and investigation workflows, continuously improving Detection and Response infrastructure * Develop alerting and detection strategies to identify malicious or anomalous behavior, including new and novel defensive techniques that adapt to evolving adversary tactics and tradecraft * Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications. * Investigate security events and active attacks across the enterprise, uncovering sophisticated threats and identifying patterns of behavior that indicate insider risk * Influence and inform security controls designed to safeguard Palantir's most critical assets * Partner closely with other members of the Information Security team to lead changes in the company's network defense posture. What We Value * Broad exposure to multiple security subject areas, including a strong background in forensics or threat intelligence * Deep exposure in Incident Response or Detection Engineering * Desire to further the information security community through substantive contributions (e.g. conference talks, blog posts, public tool development, etc.) * Comfort in operating autonomously and engaging across business levels to advise on security outcomes. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)