3 months ago
Palo Alto, CA, USASenior
Base Salary
$95k - $142k/yr
Responsibilities
- Own day-to-day identity security posture across corporate, production, customer, and US Government identity planes.
- Drive rollout of agent identity infrastructure using short-lived credentials, human-principal-bound lifecycles, and controlled workload onboarding.
- Architect authentication, federation, and authorization systems across workforce and workload identity using SAML, OIDC, and policy-driven access controls.
- Scale non-human identity patterns across service, workload, and agent populations, including short-lived credentials, mTLS, and identity-based networking.
- Drive adoption of just-in-time access patterns with platform and engineering teams through governance rollout and policy enforcement.
- Lead recurring identity threat modeling, publish findings, and track remediation.
- Serve as a primary security reviewer for identity architecture decisions and cross-team RFCs.
- Research and drive adoption of emerging identity security primitives and standards.
- Partner with engineering teams to reduce the attack surface of identity integrations at scale.
Requirements
- 5+ years of experience in Information Security, Identity and Access Management, or an equivalent discipline, with demonstrated depth in identity-specific security.
- Hands-on production experience with at least one enterprise identity provider such as Entra ID or Okta, including its governance and security surface.
- Deep technical proficiency in SAML, OIDC, OAuth 2.0, SCIM, FIDO2, and WebAuthn and their attack surfaces.
- Working proficiency in Go, Python, PowerShell, or TypeScript for prototyping tooling, analyzing identity-handling code, scaling automation, and participating in code review.
- Strong communication skills for engineer-facing design reviews and leadership-facing risk calls.
- Experience with cloud IAM, workload identity, service accounts, and identity-based access in distributed environments is valued.
- Experience designing or evaluating service, workload, and agent non-human identity architectures is valued.
- Familiarity with privileged access management, secrets management, identity governance platforms, and just-in-time access programs is valued.
- Identity threat detection and response, detection engineering, red team, offensive security, or identity-focused incident response experience is valued.
- Exposure to FedRAMP, SOX, or IL-level regulated environments is valued.
- Current US security clearance or eligibility to obtain clearance is valued.
- Contributions to the identity security community through talks, blog posts, public tools, or RFCs are valued.
Benefits
- Medical, dental, vision, voluntary life, basic life, AD&D, and disability insurance options.
- Commuter benefits, take-what-you-need paid time off, 10 paid holidays, and two weeks of year-end paid time off subject to team and business needs.
- Supportive leave programs, paid new-parent leave, subsidized backup care, fertility and family-building benefits, and a new-child expense stipend.
- 401(k) plan.
- Employees are encouraged to work from Palantir offices; many teams offer hybrid work one or two days per week, with exceptional remote arrangements available for some roles.
Tech Stack
Categories
About Palantir
AI-powered automation for every decision. At Palantir, our software powers AI-driven decisions in critical government and commercial enterprises in the West, from the factory floors to the front lines. Our platforms feature advanced tools for data protection, governance, responsible use of AI, and civilian protection capabilities for defense applications. Dominate your most complex problems with Palantir.