Primary record

Platform Engineer - Identity Infrastructure

Palantir Indexed employerNew York, NY
Source-hosted applyChecked 1h agoFull-Time
Apply at Palantir

Palantir receives this application through Lever. Babu Careers does not claim delivery.

Workplace

hybrid

Employment

Full-Time

Published

Jul 28, 2026

Closes

No date supplied

The role

A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.

Requirements

Core Responsibilities: Develop automation and tooling for corporate and customer-facing identity platforms Build, secure, and manage geo-redundant containerized services (EKS and ECS) in AWS and Azure Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud Platform (GCP) Extend the identity platform to non-human identities, treating workloads and AI agents as first-class principals with scoped, short-lived credentials Build the governance layer: an access graph that makes entitlements legible and a policy engine that makes authorization decisions enforceable and auditable Design token-issuance and federation flows that make least-privilege, ephemeral access the default Research and drive adoption of emerging authentication and session security standards (such as device-bound session credentials and continuous access evaluation) in collaboration with Security Engineers Pressure-test designs and partner with Identity Security Engineers to threat model implementations before they ship Partner with Security Compliance Engineers to build services that reduce the cost and complexity of compliance enforcement What We Value: Technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, WebAuthn) Experience managing identities and governance workflows on platforms such as Entra ID, Keycloak, AWS Cognito, or Okta Experience with policy engines and authorization-as-code, and with relationship-based access modeling or entitlement graph design Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation Non-human identity experience: workload and machine identity (service-to-service authentication, mTLS, workload attestation), plus interest in agentic identity (agents as principals, delegation and o