Palantir

Platform Engineer - Identity Infrastructure

Palantir
Apply
2 months ago
New York, NY, USAMid Level
H1B sponsor

Responsibilities

  • Develop automation and tooling for corporate and customer-facing identity platforms
  • Build, secure, and manage geo-redundant containerized services in AWS and Azure
  • Scale SSO integrations across Entra ID tenants using infrastructure-as-code
  • Standardize operational workflows across AWS, Azure, and Google Cloud
  • Extend identity infrastructure to workloads and AI agents using scoped, short-lived credentials
  • Build access graphs and policy engines for legible, enforceable, and auditable entitlements
  • Design token-issuance and federation flows that support least-privilege ephemeral access
  • Research and drive adoption of emerging authentication and session-security standards
  • Threat-model implementations with Identity Security Engineers before deployment
  • Partner with Security Compliance Engineers to reduce the complexity and cost of compliance enforcement

Requirements

  • At least 3 years of experience in SRE, DevOps, software engineering, or an equivalent discipline, with a strong interest in security
  • Experience deploying and operating containerized production services using EKS, ECS, or similar technologies in AWS, Azure, or Google Cloud
  • Experience building and operating production services or APIs, beyond automation scripts
  • Expert-level proficiency in Go, Python, TypeScript, or a similar language; Go is preferred
  • Experience with infrastructure-as-code tools such as Terraform, Helm, or CloudFormation
  • Active TS/SCI security clearance or eligibility and willingness to obtain one
  • Proficiency with identity protocols including SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, and WebAuthn
  • Experience managing identity and governance workflows with Entra ID, Keycloak, AWS Cognito, or Okta
  • Experience with policy engines, authorization-as-code, relationship-based access models, or entitlement graph design
  • Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation
  • Experience with workload and machine identity, service-to-service authentication, mTLS, and workload attestation; interest in agentic identity and delegation flows

Benefits

  • Medical, dental, vision, voluntary life, basic life, AD&D, and disability insurance options
  • Commuter benefits and relocation assistance
  • Take-what-you-need paid time off, plus two weeks of paid time off at year end subject to team and business needs
  • Ten paid holidays
  • Supportive leave of absence program, including military and medical leave
  • Paid parental leave and subsidized backup care
  • Fertility and family-building benefits, including adoption, surrogacy, and preservation support
  • New-child expense stipend and 401(k) plan
  • Work is encouraged from company offices, with some teams offering hybrid work one or two days per week and exceptional remote roles requiring work from the employing state
Palantir

About Palantir

5,001-10,000 employees

Palantir builds data-integration and AI-driven analytics platforms used by governments and large enterprises to run operations and make decisions. Its core products, including Gotham and Foundry (with Apollo for deployment), are sold via software subscriptions and implementation services. Founded in 2003 and headquartered in Miami, it is NYSE-listed and deployed across defense, intelligence, healthcare, and industrial sectors.

Contact me