Source description
About the role
Active Directory
Deep, working knowledge of AD architecture: sites and services, replication, trust relationships, delegation models, and the LDAP schema.
Hands-on experience investigating and detecting AD attacks across the full kill chain — from initial enumeration through domain dominance.
Familiarity with attack tooling (BloodHound, Impacket, Rubeus, Mimikatz, CrackMapExec) and, critically, what they leave behind.
Experience hardening AD environments: tiered administration, Protected Users, LAPS, Credential Guard, PAM trusts, and authentication policy silos.
Windows Internals
Thorough understanding of Windows security architecture: access tokens, privilege model, integrity levels, LSASS and credential storage, SAM, and the Security Reference Monitor.
Ability to read and interpret Windows kernel structures, driver behavior, and undocumented APIs when necessary.
Proficiency with low-level analysis tools: WinDbg, Process Monitor, Process Hacker, Volatility, and x64dbg.
Experience with ETW-based telemetry pipelines and building detections on top of raw Windows event data.
Detection & Response
Proven track record writing high-fidelity detection logic, not just tuning vendor signatures.
Experience leading complex incident response investigations, including those involving nation-state or sophisticated criminal actors.
Strong forensic fundamentals across disk, memory, and network artifacts on Windows systems.
More at Palantir
Related open roles
Senior Identity Security Engineer
United States · Hybrid
Senior Identity Security Engineer
San Francisco Bay Area · Hybrid
Senior Identity Security Engineer
New York · Hybrid
Information Security Engineer - Endpoint
United States · Hybrid
Information Security Engineer - DLP
United States · Hybrid
Information Security Engineer - DLP
New York · Hybrid
