Padmi
Palantir logo
Palantir

data integration platforms · operational intelligence

Information Security Engineer - DLP

New York · HybridPosted 3 months ago
SecurityUnspecifiedFull Time
Apply at Palantir

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Data Loss Prevention

Deep, working knowledge of DLP architecture: endpoint agents, network inspection, cloud API integrations, policy engines, and content-aware detection across structured and unstructured data.

Hands-on experience investigating and detecting data exfiltration across the full kill chain — from reconnaissance and staging through exfiltration via web, email, removable media, and cloud sync channels.

Familiarity with common evasion techniques (encoding, steganography, covert channels, cloud storage abuse) and, critically, what they leave behind.

Experience building and maturing DLP programs: classification taxonomies, policy tiering by data sensitivity, incident workflow design, and false-positive reduction methodologies.

Data Security Fundamentals

Thorough understanding of data security architecture: content inspection techniques, regular expression and fingerprinting-based detection, optical character recognition (OCR) for image-based data, and contextual policy enforcement.

Ability to assess data flows across complex environments — SaaS, IaaS, on-premises, and hybrid — and identify where controls are absent or insufficient.

Proficiency with log analysis and forensic investigation tools to reconstruct data movement and user behavior across endpoints and network infrastructure.

Experience building telemetry pipelines and detections on top of raw DLP event data beyond out-of-the-box vendor alerting.

Detection & Response

Proven track record writing high-fidelity detection logic for data exfiltration and insider threat scenarios, not just tuning vendor signatures.

Experience leading complex incident response investigations involving insider threats, compromised credentials being used to stage and exfiltrate data, or sophisticated external actors.

Strong forensic fundamentals across endpoint artifacts, network captures, and cloud audit logs relevant to data movement investigations.

More at Palantir

Related open roles

View all roles