Skip to content
PalantirPalantirPalo Alto, CA

Platform Engineer - Identity Infrastructure

Build and operate secure identity infrastructure, governance, authorization, and token-issuance systems across corporate and customer-facing cloud environments. Requires 3+ years in SRE, DevOps, or software engineering, production service experience, cloud and container expertise, infrastructure-as-code proficiency, and security focus.

Salary not listed
Hybrid5+ YOESecurity Engineering

About the role

Responsibilities

  • Develop automation and tooling for corporate and customer-facing identity platforms.
  • Build, secure, and manage geo-redundant containerized services using EKS and ECS in AWS and Azure.
  • Scale Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks.
  • Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud.
  • Extend the identity platform to non-human identities, including workloads and AI agents, with scoped, short-lived credentials.
  • Build an access graph and policy engine to make entitlements legible and authorization decisions enforceable and auditable.
  • Design token-issuance and federation flows that make least-privilege, ephemeral access the default.
  • Research and drive adoption of emerging authentication and session security standards, including device-bound session credentials and continuous access evaluation.
  • Pressure-test designs and threat-model implementations with Identity Security Engineers.
  • Partner with Security Compliance Engineers to reduce the cost and complexity of compliance enforcement.

Requirements

  • 3+ years of experience in Site Reliability Engineering, DevOps, software engineering, or an equivalent discipline, with a strong passion for security.
  • Experience deploying and operating containerized services such as EKS or ECS in AWS, Azure, or Google Cloud.
  • Experience building and operating production services or APIs, not only automation scripts.
  • Expert-level proficiency in Go, Python, or TypeScript; Go is preferred.
  • Experience with infrastructure-as-code such as Terraform, Helm, or CloudFormation.
  • Active TS/SCI security clearance, or eligibility and willingness to obtain one.

Nice to Haves

  • Technical proficiency in SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, and WebAuthn.
  • Experience managing identities and governance workflows with Entra ID, Keycloak, AWS Cognito, or Okta.
  • Experience with policy engines, authorization-as-code, relationship-based access modeling, or entitlement graph design.
  • Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation.
  • Experience with workload and machine identity, service-to-service authentication, mTLS, and workload attestation.
  • Interest in agentic identity, including agents as principals, delegation and on-behalf-of flows, and attribution across delegation chains.

Skills

GoPythonTypeScriptAWSAzureGCPEKSECSTerraformHelmCloudFormationSAMLOIDCoauth 2.0Kubernetes
Front

Security Operations Engineer

FrontSan Francisco, CA

Protects the company’s customers, employees, and platform by leading incident response, improving detection coverage, automating security operations, and hardening cloud, endpoint, identity, and SaaS environments. Requires 5+ years of security operations or related experience and strong cross-functional communication.

180k – 260k/yrHybrid5+ YOESecurity Engineering
Wiz

Threat Intelligence Researcher (Cloud)

WizUnited States

Researches and tracks sophisticated state-backed and financially motivated threats targeting cloud environments, using telemetry, infrastructure analysis, malware analysis, and threat intelligence techniques. Requires at least five years of security or threat research experience.

160k – 220k/yrRemote5+ YOESecurity Engineering
Cloudflare

Product Security Engineer

CloudflareAustin, TX

The Product Security Engineer builds AI-driven security automation, conducts threat modeling and security reviews, manages vulnerability remediation, and triages bug bounty findings. The role requires 5+ years of product or application security experience in cloud or SaaS environments plus hands-on AI/LLM engineering experience.

Salary not listedHybrid5+ YOESecurity Engineering
Pave

IT Manager

PaveSan Francisco, CA

Owns corporate security architecture and automation across identity, compliance, endpoint protection, SaaS, and internal IT systems. The role requires 5+ years of security engineering experience, deep IdP design expertise, audit control ownership, and a track record of impactful automation.

220k+/yrHybrid5+ YOESecurity Engineering
MongoDB

Product Security Engineer, Server

MongoDBNew York, NY +1

Strengthen MongoDB’s server products through product security assessments, threat modeling, vulnerability research, and security controls. The role requires application or product security experience, C++ expertise with low-level codebases, scripting ability, and strong cross-team communication.

106k – 209k/yrRemote5+ YOESecurity Engineering