Description
As a Platform Engineer on Palantir's Identity Platform team, you will design, build, and operate secure-by-design identity infrastructure and tooling.
You will make identity governance and access management easier and more secure to implement for Palantirians and customers worldwide.
As part of Palantir's best-in-class Information Security organization, you will research, implement, and scale innovative solutions that help Palantir stay ahead of a dynamic threat landscape.
Your goal will be to make the secure path the easy path.
Core Responsibilities:
- Develop automation and tooling for corporate and customer-facing identity platforms
- Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure
- Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks
- Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP)
- Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials
- Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable
- Design token-issuance and federation flows that make least-privilege, ephemeral access the default
- Research and drive adoption of emerging authentication and session security standards
- Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship
- Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement
What We Value:
- Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn)
- Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta
- Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design
- Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation
- Non-human identity experience: workload and machine identity
What We Require:
- 3+ years of experience in Site Reliability Engineering (SRE), DevOps, software engineering, or an equivalent discipline, with a strong passion for security
- Experience deploying and operating containerized services (EKS, ECS, or similar) in AWS, Azure, or Google Cloud
- Experience building and operating production services or APIs, not only automation scripts
- Expert-level proficiency in a language such as Go (preferred), Python, or TypeScript
- Experience with infrastructure-as-code (Terraform, Helm, CloudFormation, or similar)
- An active TS/SCI security clearance, or eligibility and willingness to obtain one
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://jobs.lever.co/palantir/cf08f44c-bf75-45ed-9fab-f4836e51013e