
Platform Engineer - Identity Infrastructure
Real job — pulled straight from Palantir’s careers page · Verified August 12, 2026 · No reposts.
Job description
Palantir is hiring a Platform Engineer - Identity Infrastructure — a full-time, based in Washington, D.C. role ($135k–$200k). Apply directly on Palantir's careers page below.
Platform Engineer - Identity Infrastructure
Team: Information Security
Location: Washington, D.C.
Commitment: Full-time
Workplace Type: hybrid
The Role
You will help the team build the next-generation identity platform that treats agents and workload identities as first-class principals: the access graph that makes entitlements legible, the policy engine that makes authorization enforceable and auditable, and the token-issuance layer that keeps access short-lived, scoped, and least-privilege by default. Your work will shape the arc of these components from design to production.
You will join the high-performing Identity Platform team, engineers who are passionate about delivering identity outcomes at scale that reduce risk and friction. The team builds and operates the identity platforms that serve both corporate and production (customer-facing) infrastructure, and the paved-road tooling and secure baselines that teams across Palantir deploy on. Your goal will be to make the secure path the easy path. Your work will directly strengthen the identity substrate beneath Palantir's most critical deployments, from a globally distributed workforce to regulated and air-gapped environments.
Core Responsibilities
- Develop automation and tooling for corporate and customer-facing identity platforms
- Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure
- Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks
- Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP)
- Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials
- Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable
- Design token-issuance and federation flows that make least-privilege, ephemeral access the default
- Research and drive adoption of emerging authentication and session security standards (such as device-bound session credentials and continuous access evaluation) in collaboration with Security Engineers
- Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship
- Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement
What We Value
- Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn)
- Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta
- Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design
- Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation
- Non-human identity experience: workload and machine identity (service-to-service authentication, mTLS, workload attestation), plus interest in agentic identity (agents as principals, delegation and on-behalf-of flows, and attribution across a delegation chain)
What We Require
- 3+ years of experience in Site Reliability Engineering (SRE), DevOps, software engineering, or an equivalent discipline, with a strong passion for security
- Experience deploying and operating containerized services (EKS, ECS, or similar) in AWS, Azure, or Google Cloud
- Experience building and operating production services or APIs, not only automation scripts
- Expert-level proficiency in a language such as Go (preferred), Python, or TypeScript
- Experience with infrastructure-as-code (Terraform, Helm, CloudFormation, or similar)
- An active TS/SCI security clearance, or eligibility and willingness to obtain one
Salary
If you would like to understand more about how your personal data will be processed by Palantir, please see our Privacy Policy.
Get DevOps Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What is the salary for Platform Engineer - Identity Infrastructure at Palantir?
The estimated salary range for Platform Engineer - Identity Infrastructure at Palantir is $135,000 - $200,000 USD per year.
What skills are required for Platform Engineer - Identity Infrastructure at Palantir?
The required skills for Platform Engineer - Identity Infrastructure at Palantir include: SAML, LDAP, Go, Python, TypeScript, Terraform, Helm, CloudFormation, EKS, ECS, AWS, Azure, GCP, API.
What is the seniority level for Platform Engineer - Identity Infrastructure at Palantir?
Platform Engineer - Identity Infrastructure at Palantir is a Mid Level / Senior level position.
How do I apply for Platform Engineer - Identity Infrastructure at Palantir?
You can view the full description and apply for Platform Engineer - Identity Infrastructure at Palantir on EchoJobs: https://echojobs.io/job/palantir-platform-engineer-identity-infrastructure-yg7mc.