
Senior Identity Security Engineer
Job description
About the role
You will own the security posture of the identity infrastructure that Palantirians, customers, and services rely on every day. The role grants you the rare ability to architect, threat model, and drive security outcomes across the full identity surface, including workforce, customer, workload, and agentic identities. You will help shape the technical direction for identity security at Palantir and reduce standing access across critical systems. You will lead identity threat modeling initiatives and contribute to the next generation of identity primitives such as agent identity, JIT-native governance, and unified policy enforcement. This position sits within Palantir's best-in-class Information Security organization, where you will research, architect, and scale solutions to keep the company ahead of a dynamic identity threat landscape. You will partner closely with cross-functional teams to turn complex security challenges into scalable platform capabilities. The work requires deep expertise in identity protocols, attack paths, and risk remediation at an enterprise scale. Your decisions will directly influence how identity security evolves across products and internal operations.
Key facts
What you'll do
Design and maintain identity security controls for workforce, customer, workload, and agentic identities across all environments.
Perform in-depth threat modeling for identity-related risks and attack paths, translating findings into actionable security improvements.
Drive initiatives to reduce standing access, enforce least privilege, and implement zero trust principles across identity platforms.
Collaborate with platform and product teams to integrate identity security into architecture reviews, design documents, and delivery milestones.
Own security outcomes for identity primitives, including agent identity, JIT access, and dynamic authorization mechanisms.
Develop and maintain tools, scripts, and automation to monitor, detect, and respond to identity-based threats and anomalies.
Partner with the Information Security organization to align identity security roadmaps with enterprise risk priorities and compliance frameworks.
Investigate identity-related incidents, determine root causes, and define remediation strategies to prevent recurrence.
Contribute to the evolution of identity governance models, including policy unification and centralized oversight across systems.
Lead proof-of-concept projects that evaluate emerging identity technologies, protocols, and defensive techniques.
Define metrics and reporting mechanisms to measure identity security posture, risk reduction, and control effectiveness.
Work with engineering and security teams to embed identity security best practices into CI/CD pipelines and deployment workflows.
Document security requirements, architectural decisions, and operational procedures to ensure clarity and continuity.
Champion identity security best practices across the organization through training, guidance, and hands-on support.
Requirements
Demonstrate expertise in identity security concepts, including authentication, authorization, federation, and access management.
Possess deep knowledge of identity protocols such as OAuth, OpenID Connect, SAML, and related standards.
Show strong understanding of identity attack paths, threat models, and mitigation strategies for workforce and system identities.
Have experience designing and implementing security controls for cloud identity platforms, including Azure AD, Okta, or similar systems.
Exhibit proficiency in scripting and automation using languages commonly used in security and identity tooling.
Bring a proven track record of reducing standing access, enforcing least privilege, and improving identity posture in complex environments.
Display strong collaboration skills, with the ability to work effectively with engineering, product, and security stakeholders.
Commit to adhering to Palantir's security policies, operational procedures, and compliance requirements at all times.
Nice to have
Experience with agent identity, JIT access models, and policy unification across workforce and customer IAM.
Familiarity with identity governance platforms and automated access certification workflows.
Knowledge of security operations practices and experience driving incident response for identity-related events.
Understanding of regulated environments and the implications for identity security in highly controlled industries.
Practical notes
This is a full-time role based in New York, NY.
The position may require travel, adherence to local working hours, and compliance with standard visa requirements as applicable.
Candidates must meet the outlined eligibility criteria without exception.