Platform Engineer - Identity Infrastructure

Socket.dev

Palo Alto (CA)

On-site

USD 135,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision insurance
Life insurance
AD&D and disability insurance
Commuter benefits
Relocation assistance
Paid time off
2 weeks paid time off at year end
10 paid holidays
Parental leave & back-up care
401k plan

Job summary

Palantir Technologies is seeking a Platform Engineer for its Identity Platform team in Palo Alto. You will design, build, and operate secure identity infrastructure and tooling to improve governance, access management, and auditable authorization across environments.

You will work on a high‑performing team delivering scalable identity services for corporate and production infrastructure, focusing on least-privilege access, token workflows, and secure baselines.

Qualifications

  • 3+ years in SRE/DevOps or equivalent with a security focus.
  • Experience deploying containerized services (EKS/ECS/AWS/Azure/GCP).
  • Production APIs experience.
  • Proficiency in Go, Python, or TypeScript.
  • IaC experience with Terraform/Helm/CloudFormation.
  • Active TS/SCI clearance or willingness to obtain.

Responsibilities

  • Develop automation and tooling for identity platforms.
  • Manage geo-redundant containerized services in AWS and Azure.
  • Scale SSO integrations across Entra ID tenants via IaC.
  • Build tooling to standardize workflows across AWS, Azure, and GCP.
  • Extend identity platform to non-human identities with short‑lived credentials.
  • Develop governance layer with entitlements and policy engine.
  • Design token issuance and federation flows with least-privilege access.
  • Research authentication and session security standards.
  • Threat-model designs with Identity Security Engineers.
  • Collaborate with Security Compliance Engineers to simplify compliance.

Skills

Go
Python
TypeScript
Security
SRE
DevOps

Tools

Terraform
Helm
CloudFormation
Kubernetes

Job description

A World-Changing Company

Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.

The Role

As a Platform Engineer on Palantir's Identity Platform team, you will design, build, and operate secure-by-design identity infrastructure and tooling. You will make identity governance and access management easier and more secure to implement for Palantirians and customers worldwide. As part of Palantir's best-in-class Information Security organization, you will research, implement, and scale innovative solutions that help Palantir stay ahead of a dynamic threat landscape.

You will help the team build the next-generation identity platform that treats agents and workload identities as first-class principals: the access graph that makes entitlements legible, the policy engine that makes authorization enforceable and auditable, and the token-issuance layer that keeps access short-lived, scoped, and least-privilege by default. Your work will shape the arc of these components from design to production.

You will join the high-performing Identity Platform team, engineers who are passionate about delivering identity outcomes at scale that reduce risk and friction. The team builds and operates the identity platforms that serve both corporate and production (customer-facing) infrastructure, and the paved-road tooling and secure baselines that teams across Palantir deploy on. Your goal will be to make the secure path the easy path. Your work will directly strengthen the identity substrate beneath Palantir's most critical deployments, from a globally distributed workforce to regulated and air-gapped environments.

Core Responsibilities

  • Develop automation and tooling for corporate and customer-facing identity platforms
  • Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure
  • Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks
  • Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP)
  • Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials
  • Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable
  • Design token-issuance and federation flows that make least-privilege, ephemeral access the default
  • Research and drive adoption of emerging authentication and session security standards (such as device-bound session credentials and continuous access evaluation) in collaboration with Security Engineers
  • Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship
  • Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement

What We Value

  • Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn)
  • Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta
  • Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design
  • Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation
  • Non-human identity experience: workload and machine identity (service-to-service authentication, mTLS, workload attestation), plus interest in agentic identity (agents as principals, delegation and on-behalf-of flows, and attribution across a delegation chain)

What We Require

  • 3+ years of experience in Site Reliability Engineering (SRE), DevOps, software engineering, or an equivalent discipline, with a strong passion for security
  • Experience deploying and operating containerized services (EKS, ECS, or similar) in AWS, Azure, or Google Cloud
  • Experience building and operating production services or APIs, not only automation scripts
  • Expert-level proficiency in a language such as Go (preferred), Python, or TypeScript
  • Experience with infrastructure-as-code (Terraform, Helm, CloudFormation, or similar)
  • An active TS/SCI security clearance, or eligibility and willingness to obtain one
Salary

The salary range for this position is estimated to be $135,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individual's relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.

Our benefits aim to promote health and wellbeing across all areas of Palantirians’ lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies.

  • Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance
  • Employees are automatically covered by Palantir’s basic life, AD&D and disability insurance
  • Commuter benefits
  • Relocation assistance
  • Take what you need paid time off, not accrual based
  • 2 weeks paid time off built into the end of each year (subject to team and business needs)
  • 10 paid holidays throughout the calendar year
  • Supportive leave of absence program including time off for military service and medical events
  • Paid leave for new parents and subsidized back-up care for all parents
  • Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation
  • Stipend to help with expenses that come with a new child
  • Employees can enroll in Palantir’s 401k plan

Learn more at Life at Palantir and note that our offerings may vary by region.

In keeping consistent with Palantir’s values and culture, we believe employees are “better together” and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for “Remote” work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office.

Palantir values excellence regardless of background. We are proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.

Please note that you will never be asked to submit a payment or share financial information to participate in our interview process. If you suspect that you've been contacted by a scammer, we recommend you cease all communication with the individual and consider reporting them to the relevant authorities, such as the US FBI Internet Crime Complaint Center (IC3).

If you would like to understand more about how your personal data will be processed by Palantir, please see our Privacy Policy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Engineer - Identity Infrastructure
Platform Engineer - Identity Infrastructure

Palantir Technologies • New York (NY)

On-site
USD 135,000 - 200,000
Relocation assistance
PTO time off
Paid holidays
+7
Platform Engineer - Identity Infrastructure
Platform Engineer - Identity Infrastructure

Palantir Technologies • Washington

Hybrid
USD 135,000 - 200,000
Relocation assistance
Commuter benefits
401k plan
+1
Platform Engineer - Identity Infrastructure
Platform Engineer - Identity Infrastructure

Palantir Technologies • Palo Alto (CA)

Hybrid
USD 135,000 - 200,000
Relocation assistance
Commuter benefits
401k plan
+1
Senior Identity Security Engineer
Senior Identity Security Engineer

Palantir Technologies • New York (NY)

On-site
USD 95,000 - 142,000
Medical, dental, and vision insurance
Paid time off
401k plan
Security Engineer: Threat Detection & Incident Response
Security Engineer: Threat Detection & Incident Response

Palantir • New York (NY)

Hybrid
USD 135,000 - 200,000
Medical, dental, vision insurance
Relocation assistance
Commuter benefits
+2
Backend Software Engineer - Infrastructure
Backend Software Engineer - Infrastructure

Palantir Technologies • New York (NY)

On-site
USD 135,000 - 200,000
Medical, dental, and vision insurance
Relocation assistance
Paid time off
+2
Technical Program Manager - Security
Technical Program Manager - Security

Palantir Technologies • New York (NY)

Hybrid
USD 93,000 - 160,000
Medical, dental, and vision insurance
Commuter benefits
Paid time off (PTO)
+3
Technical Program Manager - Security
Technical Program Manager - Security

Palantir Technologies • Seattle (WA)

On-site
USD 93,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Forward Deployed Software Engineer - Tactical Edge
Forward Deployed Software Engineer - Tactical Edge

Palantir Technologies • Washington

Hybrid
USD 135,000 - 200,000
Medical, dental, and vision insurance
Paid time off and holidays
401k plan
+1
Security Program Manager, Threat & Incident Readiness
Security Program Manager, Threat & Incident Readiness

Palantir Technologies • Seattle (WA)

On-site
USD 93,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+5