Information Security Engineer - DLP
Job Description
Team: Information Security
A World-Changing Company
Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.
The Role
We're looking for someone who has spent years thinking adversarially about how sensitive data moves, leaks, and gets exfiltrated — not just enforcing policies, but understanding every layer of how data can be abused, detected, and protected. If you've built content inspection pipelines, tuned classification policies against real insider threat cases, or reverse-engineered an exfiltration channel that bypassed existing controls, this is the team you want to be on.As an Information Security Engineer focused on Data Loss Prevention, you'll own the security of Palantir's global data protection program. Your team runs 24/7 prevention, detection, and investigation of data security events across our entire environment. The adversaries we face are sophisticated. We need someone who is more so.
Core Responsibilities
What We're Looking For
Data Loss Prevention
Deep, working knowledge of DLP architecture: endpoint agents, network inspection, cloud API integrations, policy engines, and content-aware detection across structured and unstructured data.
Hands-on experience investigating and detecting data exfiltration across the full kill chain — from reconnaissance and staging through exfiltration via web, email, removable media, and cloud sync channels.
Familiarity with common evasion techniques (encoding, steganography, covert channels, cloud storage abuse) and, critically, what they leave behind.
Experience building and maturing DLP programs: classification taxonomies, policy tiering by data sensitivity, incident workflow design, and false-positive reduction methodologies.
Data Security Fundamentals
Thorough understanding of data security architecture: content inspection techniques, regular expression and fingerprinting-based detection, optical character recognition (OCR) for image-based data, and contextual policy enforcement.
Ability to assess data flows across complex environments — SaaS, IaaS, on-premises, and hybrid — and identify where controls are absent or insufficient.
Proficiency with log analysis and forensic investigation tools to reconstruct data movement and user behavior across endpoints and network infrastructure.
Experience building telemetry pipelines and detections on top of raw DLP event data beyond out-of-the-box vendor alerting.
Detection & Response
Proven track record writing high-fidelity detection logic for data exfiltration and insider threat scenarios, not just tuning vendor signatures.
Experience leading complex incident response investigations involving insider threats, compromised credentials being used to stage and exfiltrate data, or sophisticated external actors.
Strong forensic fundamentals across endpoint artifacts, network captures, and cloud audit logs relevant to data movement investigations.
What We Value
What We Require
Explore More
Apply Now
Back to Job Listings
Add To Job List
Company Profile
View Company Reviews
Date Posted
04/15/2026
Views
0
Neutral
Subjectivity Score: 0
Similar Jobs
Senior Machine Learning Engineer - Personalization - Spotify
Views in the last 30 days - 0
View DetailsSenior Machine Learning Engineer, Zeitgeist, Personalization - Spotify
Views in the last 30 days - 0
View Details