Platform Engineer Identity Infrastructure
Job Location:
Palo Alto, CA - USA
Yearly Salary:
$ 135000 - 200000
Posted:
6 August 2026 (8 hours ago)
Application Deadline:
3 November 2026
Vacancies:
1 Vacancy
Job Summary
A World-Changing Company
Palantir builds the worlds leading software for data-driven decisions and operations. By bringing the right data to the people who need it our platforms empower our partners to develop lifesaving drugs forecast supply chain disruptions locate missing children and more.
The Role
As a Platform Engineer on Palantirs Identity Platform team you will design build and operate secure-by-design identity infrastructure and tooling. You will make identity governance and access management easier and more secure to implement for Palantirians and customers worldwide. As part of Palantirs best-in-class Information Security organization you will research implement and scale innovative solutions that help Palantir stay ahead of a dynamic threat landscape.
You will help the team build the next-generation identity platform that treats agents and workload identities as first-class principals: the access graph that makes entitlements legible the policy engine that makes authorization enforceable and auditable and the token-issuance layer that keeps access short-lived scoped and least-privilege by default. Your work will shape the arc of these components from design to production.
You will join the high-performing Identity Platform team engineers who are passionate about delivering identity outcomes at scale that reduce risk and friction. The team builds and operates the identity platforms that serve both corporate and production (customer-facing) infrastructure and the paved-road tooling and secure baselines that teams across Palantir deploy on. Your goal will be to make the secure path the easy path. Your work will directly strengthen the identity substrate beneath Palantirs most critical deployments from a globally distributed workforce to regulated and air-gapped environments.
You will help the team build the next-generation identity platform that treats agents and workload identities as first-class principals: the access graph that makes entitlements legible the policy engine that makes authorization enforceable and auditable and the token-issuance layer that keeps access short-lived scoped and least-privilege by default. Your work will shape the arc of these components from design to production.
You will join the high-performing Identity Platform team engineers who are passionate about delivering identity outcomes at scale that reduce risk and friction. The team builds and operates the identity platforms that serve both corporate and production (customer-facing) infrastructure and the paved-road tooling and secure baselines that teams across Palantir deploy on. Your goal will be to make the secure path the easy path. Your work will directly strengthen the identity substrate beneath Palantirs most critical deployments from a globally distributed workforce to regulated and air-gapped environments.
Core Responsibilities
- Develop automation and tooling for corporate and customer-facing identity platforms
- Build secure and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure
- Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks
- Build tooling to standardize and scale operational workflows across AWS Azure and Google Cloud Platform (GCP)
- Extend the identity platform to non-human identities treating workloads and AI agents as first-class principals with scoped short-lived credentials
- Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable
- Design token-issuance and federation flows that make least-privilege ephemeral access the default
- Research and drive adoption of emerging authentication and session security standards (such as device-bound session credentials and continuous access evaluation) in collaboration with Security Engineers
- Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship
- Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement
What We Value
- Technical proficiency in identity protocols (SAML OIDC OAuth 2.0 LDAP Kerberos FIDO2 WebAuthn)
- Experience managing identities and governance workflows on platforms such as Entra ID Keycloak AWS Cognito or Okta
- Experience with policy engines and authorization-as-code and with relationship-based access modeling or entitlement graph design
- Experience with token issuance and federation including OAuth 2.0 token exchange short-lived credentials and workload identity federation
- Non-human identity experience: workload and machine identity (service-to-service authentication mTLS workload attestation) plus interest in agentic identity (agents as principals delegation and on-behalf-of flows and attribution across a delegation chain)
What We Require
- 3 years of experience in Site Reliability Engineering (SRE) DevOps software engineering or an equivalent discipline with a strong passion for security
- Experience deploying and operating containerized services (EKS ECS or similar) in AWS Azure or Google Cloud
- Experience building and operating production services or APIs not only automation scripts
- Expert-level proficiency in a language such as Go (preferred) Python or TypeScript
- Experience with infrastructure-as-code (Terraform Helm CloudFormation or similar)
- An active TS/SCI security clearance or eligibility and willingness to obtain one
Salary
The salary range for this position is estimated to be $135000 - $200000/year. Total compensation for this position may also include Restricted Stock units sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individuals relevant qualifications work experience skills and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.
Our benefits aim to promote health and wellbeing across all areas of Palantirians lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies.
Benefits
Employees (and their eligible dependents) can enroll in medical dental and vision insurance as well as voluntary life insurance
Employees are automatically covered by Palantirs basic life AD&D and disability insurance
Commuter benefits
Relocation assistance
Take what you need paid time off not accrual based
2 weeks paid time off built into the end of each year (subject to team and business needs)
10 paid holidays throughout the calendar year
Supportive leave of absence program including time off for military service and medical events
Paid leave for new parents and subsidized back-up care for all parents
Fertility and family building benefits including but not limited to adoption surrogacy and preservation
Stipend to help with expenses that come with a new child
Employees can enroll in Palantirs 401k plan
Life at Palantir
We want every Palantirian to achieve their best outcomes thats why we celebrate individuals strengths skills and interests from your first interview to your longterm growth rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians lives is just one of the ways were investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region.
In keeping consistent with Palantirs values and culture we believe employees are better together and in-person work affords the opportunity for more creative outcomes. Therefore we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week) allowing our employees to strike the right trade-off for their personal productivity. Based on business need there are a few roles that allow for Remote work on an exceptional basis. If you are applying for one of these roles you must work from the state in which you are employed. If the posting is specified as Onsite you are required to work from an office.
If you want to empower the worlds most important institutions you belong here. Palantir values excellence regardless of background. We are proud to be an Equal Opportunity Employer for all including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process please reach out and let us know how we can help.
Please note that you will never be asked to submit a payment or share financial information to participate in our interview process. If you suspect that youve been contacted by a scammer we recommend you cease all communication with the individual and consider reporting them to the relevant authorities such as the US FBI Internet Crime Complaint Center (IC3).
If you would like to understand more about how your personal data will be processed by Palantir please see our .
If you would like to understand more about how your personal data will be processed by Palantir please see our .
Required Experience:
IC
About Company
We build software that empowers organizations to effectively integrate their data, decisions, and operations.