2 months ago
Palo Alto, CA, USAMid Level
H1B sponsor
Base Salary
$135k - $200k/yr
Responsibilities
- Develop automation and tooling for corporate and customer-facing identity platforms.
- Build, secure, and manage geo-redundant containerized services in EKS and ECS across AWS and Azure.
- Scale SSO integrations across multiple Entra ID tenants using infrastructure-as-code frameworks.
- Standardize operational workflows across AWS, Azure, and GCP.
- Extend the identity platform to workload, machine, and AI-agent identities using scoped, short-lived credentials.
- Build an access graph and policy engine for legible, enforceable, and auditable authorization decisions.
- Design token-issuance and federation flows that make least-privilege, ephemeral access the default.
- Research and adopt emerging authentication and session-security standards, including device-bound session credentials and continuous access evaluation.
- Threat-model implementations with Identity Security Engineers before production release.
- Partner with Security Compliance Engineers to reduce the cost and complexity of compliance enforcement.
Requirements
- At least 3 years of experience in SRE, DevOps, software engineering, or an equivalent discipline, with a strong interest in security.
- Experience deploying and operating containerized services such as EKS or ECS in AWS, Azure, or Google Cloud.
- Experience building and operating production services or APIs rather than only automation scripts.
- Expert-level proficiency in Go, Python, or TypeScript, with Go preferred.
- Experience with infrastructure-as-code tools such as Terraform, Helm, or CloudFormation.
- Technical proficiency with SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, and WebAuthn.
- Experience managing identity and governance workflows with Entra ID, Keycloak, AWS Cognito, or Okta.
- Experience with policy engines, authorization-as-code, relationship-based access modeling, or entitlement graph design.
- Experience with token issuance, federation, OAuth 2.0 token exchange, short-lived credentials, and workload identity federation.
- Experience with workload and machine identity, service-to-service authentication, mTLS, and workload attestation; interest in agentic identity and delegation flows is valued.
- An active TS/SCI security clearance or eligibility and willingness to obtain one.
Benefits
- Medical, dental, vision, and voluntary life insurance options for employees and eligible dependents.
- Automatic basic life, AD&D, and disability insurance coverage.
- Commuter benefits and relocation assistance.
- Take-what-you-need paid time off, plus two weeks of paid time off at the end of each year subject to business needs.
- Ten paid holidays annually.
- Supportive leave of absence program, including military and medical leave.
- Paid parental leave and subsidized backup care for parents.
- Fertility and family-building benefits, including adoption, surrogacy, and preservation support.
- New-child expense stipend and access to a 401(k) plan.
- Primarily office-based work, with many teams offering hybrid work one or two days per week and exceptional remote arrangements for select roles.
Tech Stack
About Palantir
Palantir builds data-integration and AI-driven analytics platforms used by governments and large enterprises to run operations and make decisions. Its core products, including Gotham and Foundry (with Apollo for deployment), are sold via software subscriptions and implementation services. Founded in 2003 and headquartered in Miami, it is NYSE-listed and deployed across defense, intelligence, healthcare, and industrial sectors.
