Platform Engineer - Identity Infrastructure
Palantir · Palo Alto, CA
Skills in this posting
The posting
A World-Changing Company
Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.
The Role
As a Platform Engineer on Palantir's Identity Platform team, you will design, build, and operate secure-by-design identity infrastructure and tooling. You will make identity governance and access management easier and more secure to implement for Palantirians and customers worldwide. As part of Palantir's best-in-class Information Security organization, you will research, implement, and scale innovative solutions that help Palantir stay ahead of a dynamic threat landscape.
You will help the team build the next-generation identity platform that treats agents and workload identities as first-class principals: the access graph that makes entitlements legible, the policy engine that makes authorization enforceable and auditable, and the token-issuance layer that keeps access short-lived, scoped, and least-privilege by default. Your work will shape the arc of these components from design to production.
You will join the high-performing Identity Platform team, engineers who are passionate about delivering identity outcomes at scale that reduce risk and friction.
The team builds and operates the identity platforms that serve both corporate and production (customer-facing) infrastructure, and the paved-road tooling and secure baselines that teams across Palantir deploy on. Your goal will be to make the secure path the easy path.
Your work will directly strengthen the identity substrate beneath Palantir's most critical deployments, from a globally distributed workforce to regulated and air-gapped environments.
Core Responsibilities
Develop automation and tooling for corporate and customer-facing identity platforms
Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure
Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks
Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP)
Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials
Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable
Design token-issuance and federation flows that make least-privilege, ephemeral access the default
Research and drive adoption of emerging authentication and session security standards (such as device-bound session credentials and continuous access evaluation) in collaboration with Security Engineers
Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship
Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement
What We Value
Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn)
Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta
Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design
Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation
Non-human identity experience: workload and machine identity (service-to-service authentication, mTLS, workload attestation), plus interest in agentic identity (agents as principals, delegation and on-behalf-of flows, and attribution across a delegation chain)
What We Require
3+ years of experience in Site Reliability Engineering (SRE), DevOps, software engineering, or an equivalent discipline, with a strong passion for security
Experience deploying and operating containerized services (EKS, ECS, or similar) in AWS, Azure, or Google Cloud
Experience building and operating production services or APIs, not only automation scripts
Expert-level proficiency in a language such as Go (preferred), Python, or TypeScript
Experience with infrastructure-as-code (Terraform, Helm, CloudFormation, or similar)
An active TS/SCI security clearance, or eligibility and willingness to obtain one
The PivotHop read
- What a devops engineer actually earnsmedian, seniority, by country
- What devops engineers do insteadevery measured route out
- All open devops engineer rolesthe full board
Where these skills also reach
- 534 open systems administrator roles58% readiness from devops engineer
- 600 open solutions architect roles51% readiness from devops engineer
- 569 open backend developer roles45% readiness from devops engineer
- 111 open network engineer roles44% readiness from devops engineer
More devops engineer roles
DevOps Engineer (Intern) at MactoresAnywhere · RemoteTodayApply
Cloud Engineer (Intern) at MactoresAnywhere · RemoteTodayApply
AWS DevOps Engineer (Senior) - Migration Project (VMware to AWS) at MactoresAnywhere · RemoteTodayApply
AWS DevOps Engineer (Freelancer) at MactoresUSA · RemoteTodayApply- Senior DevOps Engineer (all genders) | Data Platform at Real DigitalRemote oder Köln / Darmstadt / Düsseldorf / BerlinTodayApply
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.