# Platform Engineer - Identity Infrastructure

**Company**: Palantir
**Location**: Washington, D.C.
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: $135,000 - $200,000/year
**Category**: Engineering
**Industry**: Technology

**Apply**: https://jobs.lever.co/palantir/a80afc2b-2564-4a98-84c2-34cdcc0402df?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_b8c13714-97b

## Description

Palantir builds the world's leading software for data-driven decisions and operations. As a Platform Engineer on Palantir's Identity Platform team, you will design, build, and operate secure-by-design identity infrastructure and tooling.

Your goal will be to make the secure path the easy path. You will join the high-performing Identity Platform team, engineers who are passionate about delivering identity outcomes at scale that reduce risk and friction.

## Core Responsibilities

- Develop automation and tooling for corporate and customer-facing identity platforms

- Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure

- Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks

- Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP)

- Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials

- Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable

- Design token-issuance and federation flows that make least-privilege, ephemeral access the default

- Research and drive adoption of emerging authentication and session security standards

- Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship

- Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement

## What We Value

- Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn)

- Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta

- Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design

- Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation

- Non-human identity experience: workload and machine identity

## What We Require

- 3+ years of experience in Site Reliability Engineering (SRE), DevOps, software engineering, or an equivalent discipline, with a strong passion for security

- Experience deploying and operating containerized services (EKS, ECS, or similar) in AWS, Azure, or Google Cloud

- Experience building and operating production services or APIs, not only automation scripts

- Expert-level proficiency in a language such as Go, Python, or TypeScript

- Experience with infrastructure-as-code (Terraform, Helm, CloudFormation, or similar)

- An active TS/SCI security clearance, or eligibility and willingness to obtain one

## Skills

### Required
- identity protocols
- containerized services
- infrastructure-as-code
- policy engines
- authorization-as-code

### Nice to have
- Go
- Python
- TypeScript
- Entra ID
- Keycloak
- AWS Cognito
- Okta

---

Source: [Apply at jobs.lever.co](https://jobs.lever.co/palantir/a80afc2b-2564-4a98-84c2-34cdcc0402df?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
