
Platform Engineer - Identity Infrastructure
Job description
About the role
You will design and operate secure-by-design identity infrastructure that underpins access decisions for Palantir's most critical workloads. You will own the implementation of identity governance and access management tooling, making it easier and more secure for thousands of users and systems. You will research and scale innovative controls that keep Palantir resilient against a constantly evolving threat landscape. You will shape the architecture of authorization graphs, policy engines, and token-issuance systems from initial design through production rollout. You will collaborate closely with security and platform teams to ensure identity primitives are treated as first-class infrastructure. You will contribute to the paved-road tooling that standardizes secure identity deployments across the company. Your work will directly reduce risk and friction for both internal teams and external customers using Palantir platforms. You will own key components of the identity platform end-to-end, from requirements and design to implementation, testing, and operations.
Key facts
What you'll do
Design and implement authorization graphs that make entitlements legible, discoverable, and manageable across distributed systems.
Build and operate token-issuance layers that issue short-lived, scoped credentials aligned with least-privilege principles.
Develop policy engines that enforce authorization decisions and generate audit trails suitable for compliance review.
Create self-service workflows and paved roads that enable teams to adopt secure identity patterns without deep expertise.
Instrument identity infrastructure for reliability, performance, and security to support both corporate and production environments.
Partner with Information Security to research, evaluate, and implement controls that address emerging threats to identity systems.
Collaborate with platform and customer teams to ensure identity services meet the needs of regulated and air-glocked environments.
Drive operational excellence by automating identity lifecycle management, access reviews, and incident response playbooks.
Implement tooling that makes secure identity the default and easiest path for engineers building on Palantir infrastructure.
Lead design discussions and translate requirements into robust identity primitives that scale globally.
Contribute to architectural decisions that balance security, usability, and operational overhead across the identity stack.
Work on the foundational systems that underpin access for a globally distributed workforce and critical customer deployments.
Participate in on-call rotations to respond to identity-related incidents and improve platform reliability.
Help define and evolve best practices for identity and access management across the company.
Requirements
Must be eligible to work in the United States now and in the future.
Must be able to commute to or relocate to Palo Alto, CA for the role.
Must have at least a Bachelor's degree in Computer Science, Engineering, or a related field.
Must have at least eight years of professional experience in software engineering, platform, or infrastructure roles.
Must have deep experience designing, building, and operating identity, access, or security infrastructure at scale.
Must have hands-on implementation with authorization systems, including policies, roles, and attribute-based access control.
Must have experience with authentication protocols and token formats such as OAuth 2.0, OIDC, SAML, and JWT.
Must be proficient in at least one general-purpose programming language and comfortable managing infrastructure as code.
Must have a strong understanding of security and compliance principles relevant to identity and access management.
Nice to have
Experience with open-source identity standards and protocols.
Background in regulated industries such as finance, healthcare, or government.
Contributions to identity-related open-source projects.
Experience with cloud platforms and container orchestration for identity services.
Practical notes
This is a full-time role based in Palo Alto, California.
Candidates must be able to work in the United States now and into the future.
The role may require occasional travel within the United States.
Employment is contingent on successful completion of background checks and authorization to work in the United States.
Visa sponsorship is not available for this position at this time.