Description
Palantir builds the world's leading software for data-driven decisions and operations. As a Platform Engineer on Palantir's Identity Platform team, you will design, build, and operate secure-by-design identity infrastructure and tooling.
Your goal will be to make the secure path the easy path. You will join the high-performing Identity Platform team, engineers who are passionate about delivering identity outcomes at scale that reduce risk and friction.
Core Responsibilities
- Develop automation and tooling for corporate and customer-facing identity platforms
- Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure
- Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks
- Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP)
- Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials
- Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable
- Design token-issuance and federation flows that make least-privilege, ephemeral access the default
- Research and drive adoption of emerging authentication and session security standards
- Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship
- Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement
What We Value
- Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn)
- Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta
- Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design
- Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation
- Non-human identity experience: workload and machine identity
What We Require
- 3+ years of experience in Site Reliability Engineering (SRE), DevOps, software engineering, or an equivalent discipline, with a strong passion for security
- Experience deploying and operating containerized services (EKS, ECS, or similar) in AWS, Azure, or Google Cloud
- Experience building and operating production services or APIs, not only automation scripts
- Expert-level proficiency in a language such as Go, Python, or TypeScript
- Experience with infrastructure-as-code (Terraform, Helm, CloudFormation, or similar)
- An active TS/SCI security clearance, or eligibility and willingness to obtain one
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://jobs.lever.co/palantir/a80afc2b-2564-4a98-84c2-34cdcc0402df