Platform Engineer - Identity and Access Management (IAM)

Apply Now

Company: Palantir

Location: York New Salem, PA 17371

Description:

A World-Changing Company


Palantir builds the worlds leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.


The Role


As a Platform Engineer on Palantir's Identity Security team, you will design, build and run secure-by-design identity infrastructure and tooling. You will make it easier and more secure to implement identity governance and access management for Palantirians and our customers all over the world. As part of Palantir's best-in-class Information Security organization, you will research, implement, and scale innovative solutions to help Palantir stay ahead of a dynamic threat landscape.


The Identity team consists of Engineers who are passionate about reducing risk, friction and eliminating toil. The team's primary focus is the development and management of identity platforms for both corporate and production (customer-facing) infrastructure. As part of the team, you will build novel web services that help Palantirians stay compliant while minimizing impact on their productivity flows. Your work will directly impact and improve the resilience of critical Palantir infrastructure that enables and empowers a globally distributed workforce.

Core Responsibilities

Develop automation for corporate and customer-facing identity platforms across multiple compliance boundaries (FedRAMP, IL5, IL6, etc.)

Build, secure and manage geo-redundant systems and services in AWS and Azure

Scale the implementation of Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks

Build tooling to standardize and scale operational workflows in AWS, Azure and Google Cloud Platform (GCP)

Research and drive the implementation of emerging authentication protocols (like passwordless auth) by collaborating with Security Engineers

Partner with Security Compliance Engineers to help build novel services that reduce the cost of compliance enforcement

What We Value

Technical proficiency in identity protocols (SAML, OIDC, LDAP, Kerberos, FIDO2, WebAuthN)

Experience managing identities and governance workflows on platforms like Entra ID, AWS Cognito, Okta

Familiarity with risk management and understanding of regulatory compliance frameworks (e.g., ISO/SOC/NIST)

What We Require

Minimum 3 years experience in Site Reliability Engineering (SRE), DevOps or equivalent field with a deep passion for security

Experience deploying and running Linux or Windows based infrastructure in AWS, Azure, or Google Cloud

Expert level proficiency with a language such as Go, Python, PowerShell, TypeScript, etc.

Experience with infrastructure-as-code frameworks such as Terraform, CloudFormation, Ansible, Puppet, or PowerShell DSC

Willingness and eligibility to obtain a U.S. security clearance, or active TS//SCI.

Salary


The estimated salary range for this position is estimated to be $135,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individuals relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.


Our benefits aim to promote health and wellbeing across all areas of Palantirians lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies.


Benefits


Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance

Employees are automatically covered by Palantirs basic life, AD&D and disability insurance

Commuter benefits

Relocation assistance

Take what you need paid time off, not accrual based

2 weeks paid time off built into the end of each year (subject to team and business needs)

10 paid holidays throughout the calendar year

Supportive leave of absence program including time off for military service and medical events

Paid leave for new parents and subsidized back-up care for all parents

Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation

Stipend to help with expenses that come with a new child

Employees can enroll in Palantirs 401k plan


Life at Palantir


We want every Palantirian to achieve their best outcomes, thats why we celebrate individuals strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians lives is just one of the ways were investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region.


In keeping consistent with Palantirs values and culture, we believe employees are better together and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for Remote work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office.


Similar Jobs