Responsibilities
- Develop automation and tooling for corporate and customer-facing identity platforms
- Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure
- Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks
- Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP)
- Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials
- Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable
- Design token-issuance and federation flows that make least-privilege, ephemeral access the default
- Research and drive adoption of emerging authentication and session security standards (such as device-bound session credentials and continuous access evaluation) in collaboration with Security Engineers
- Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship
- Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement
Requirements
- 3+ years of experience in Site Reliability Engineering (SRE), DevOps, software engineering, or an equivalent discipline, with a strong passion for security
- Experience deploying and operating containerized services (EKS, ECS, or similar) in AWS, Azure, or Google Cloud
- Experience building and operating production services or APIs, not only automation scripts
- Expert-level proficiency in a language such as Go (preferred), Python, or TypeScript
- Experience with infrastructure-as-code (Terraform, Helm, CloudFormation, or similar)
- An active TS/SCI security clearance, or eligibility and willingness to obtain one
- Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn)
- Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta
- Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design
- Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation
- Non-human identity experience: workload and machine identity (service-to-service authentication, mTLS, workload attestation), plus interest in agentic identity (agents as principals, delegation and on-behalf-of flows, and attribution across a delegation chain)
the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity.
Based on business need, there are a few roles that allow for "Remote" work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office.
If you want to empower the world's most important institutions, you belong here. Palantir values excellence regardless of background. We are proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities.
Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.
Please note that you will never be asked to submit a payment or share financial information to participate in our interview process. If you suspect that you've been contacted by a scammer, we recommend you cease all communication with the individual and consider reporting them to the relevant authorities, such as the US FBI Internet Crime Complaint Center (IC3).
If you would like to understand more about how your personal data will be processed by Palantir, please see our Privacy Policy.