Skip to content
PalantirPalantir

Platform Engineer - Identity Infrastructure

Build and operate secure identity infrastructure, governance, authorization, and token-issuance systems across corporate and customer-facing cloud environments. Requires 3+ years in SRE, DevOps, or software engineering, production service experience, cloud and container expertise, infrastructure-as-code proficiency, and security focus.

About the job

Responsibilities

  • Develop automation and tooling for corporate and customer-facing identity platforms.
  • Build, secure, and manage geo-redundant containerized services using EKS and ECS in AWS and Azure.
  • Scale Single Sign-On (SSO) integrations across multiple Entra ID tenants using infrastructure-as-code frameworks.
  • Build tooling to standardize and scale operational workflows across AWS, Azure, and Google Cloud.
  • Extend the identity platform to non-human identities, including workloads and AI agents, with scoped, short-lived credentials.
  • Build an access graph and policy engine to make entitlements legible and authorization decisions enforceable and auditable.
  • Design token-issuance and federation flows that make least-privilege, ephemeral access the default.
  • Research and drive adoption of emerging authentication and session security standards, including device-bound session credentials and continuous access evaluation.
  • Pressure-test designs and threat-model implementations with Identity Security Engineers.
  • Partner with Security Compliance Engineers to reduce the cost and complexity of compliance enforcement.

Requirements

  • 3+ years of experience in Site Reliability Engineering, DevOps, software engineering, or an equivalent discipline, with a strong passion for security.
  • Experience deploying and operating containerized services such as EKS or ECS in AWS, Azure, or Google Cloud.
  • Experience building and operating production services or APIs, not only automation scripts.
  • Expert-level proficiency in Go, Python, or TypeScript; Go is preferred.
  • Experience with infrastructure-as-code such as Terraform, Helm, or CloudFormation.
  • Active TS/SCI security clearance, or eligibility and willingness to obtain one.

Nice to Haves

  • Technical proficiency in SAML, OIDC, OAuth 2.0, LDAP, Kerberos, FIDO2, and WebAuthn.
  • Experience managing identities and governance workflows with Entra ID, Keycloak, AWS Cognito, or Okta.
  • Experience with policy engines, authorization-as-code, relationship-based access modeling, or entitlement graph design.
  • Experience with token issuance and federation, including OAuth 2.0 token exchange, short-lived credentials, and workload identity federation.
  • Experience with workload and machine identity, service-to-service authentication, mTLS, and workload attestation.
  • Interest in agentic identity, including agents as principals, delegation and on-behalf-of flows, and attribution across delegation chains.

Skills

Go, Python, TypeScript, AWS, Azure, GCP, EKS, ECS, Terraform, Helm, CloudFormation, SAML, OIDC, Oauth 2.0, Kubernetes

Stripe

Stripe

United States

Security Incident Response Engineer
No salary listedRemote3+ YOESecurity Engineering

Build and improve security analytics, detection, and incident response capabilities by analyzing telemetry, investigating threats, and developing scalable behavioral models and pipelines. Requires 3+ years of security analytics experience, strong Python and SQL skills, and expertise in incident response and forensics.

Ambient.ai

Ambient.ai

Redwood City, CA

Data Verification Operator
$50k+/yrOn-siteSecurity Engineering

Reviews and validates real-time physical security alerts, analyzes incident data, documents findings, and escalates potential threats. The role requires strong communication, analytical ability, computer proficiency, attention to detail, and flexibility for overnight or weekend shifts.

Datadog

Datadog

New York, NY

Security Engineer 2 - Cyber Threat Intelligence
$140k+/yrHybridSecurity Engineering

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

Stripe

Stripe

United States

Security Engineer
No salary listedRemote3+ YOESecurity Engineering

Designs and incubates technical defenses against complex abuse and fraud across Stripe’s payment, onboarding, identity, and Connect surfaces. Requires 3+ years of security or software engineering experience, strong production programming and SQL skills, and expertise in API safeguards and automated testing.

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.