Skip to content

Senior Identity Security Engineer

Senior Identity Security Engineer responsible for securing Palantir's workforce, customer, workload, and agent identity infrastructure. Requires 5+ years in IAM/security with deep protocol expertise and hands-on experience with enterprise IdPs.

New York, NYSecurity EngineeringHybrid5+ YOE

About the role

Core Responsibilities

  • Own the day-to-day identity security posture across corporate, production, customer, and US Government identity planes
  • Drive the rollout of agent identity infrastructure - short-lived credentials, lifecycle bound to a human principal, controlled workload onboarding
  • Architect authentication, federation, and authorization systems - including SAML, OIDC, and policy-driven access control models (RBAC, ABAC, policy-as-code) - across workforce and workload identity
  • Scale non-human identity patterns across service, workload, and agent populations - short-lived credentials, mTLS, identity-based networking
  • Drive adoption of just-in-time access patterns across the identity program, partnering with platform and engineering teams on governance rollout and policy enforcement
  • Lead identity threat modeling on a regular cadence; publish findings and track remediation
  • Serve as a primary security reviewer on identity architecture decisions and cross-team RFCs
  • Research and drive adoption of emerging identity security primitives and standards in partnership with Security Engineers across InfoSec
  • Partner with engineering teams across Palantir to reduce the attack surface of identity integrations at scale

What We Value

  • Experience with cloud IAM and workload identity patterns - service accounts and identity-based access in distributed environments
  • Experience designing or evaluating non-human identity (NHI) architectures - service, workload, and agent - and a strong point of view on where the industry is headed
  • Familiarity with privileged access management and secrets management patterns at scale
  • A track record of reducing standing access and shifting organizations toward just-in-time access postures in production environments
  • Experience with identity governance platforms and a clear-eyed view of their security implications
  • Identity threat detection and response experience, including detection engineering against identity telemetry
  • Red team, offensive security, or incident response background - especially with an identity focus
  • Exposure to regulated environments (FedRAMP, SOX, IL-levels)
  • Desire to further the identity security community through substantive contributions (e.g. conference talks, blog posts, public tool development, RFCs)
  • Current US security clearance, or eligibility to obtain clearance

What We Require

  • 5+ years of experience in Information Security, Identity and Access Management, or an equivalent discipline, with demonstrated depth in identity-specific security
  • Hands-on production experience with at least one enterprise identity provider (Entra ID, Okta, or equivalent), including its governance and security surface
  • Deep technical proficiency in identity protocols (SAML, OIDC, OAuth 2.0, SCIM, FIDO2, WebAuthn) and their attack surface
  • Working proficiency in Go, Python, PowerShell, or TypeScript - enough to prototype tooling, analyze identity-handling code for security defects, scale automation across the environment, and engage in code review
  • Strong communication skills and ability to communicate to a wide-ranging audience - from engineer-facing design reviews to leadership-facing risk calls

Skills

Entra IdOktaSAMLOIDCOauth 2.0SCIMFido2WebauthnGoPythonPowerShellTypeScriptRBACAbacIAM

Senior Platform Engineer, Security

Build and secure Doxel's internal developer platform on GCP. Own cloud security posture, embed security into CI/CD pipelines, and drive adoption of secure golden paths across engineering teams.

175k – 220kSan Francisco, CASecurity EngineeringHybrid6+ YOEGoGCP

Senior Product Security Engineer

Hands-on security engineer building product security guardrails, tooling, and SDLC integrations for a multi-product HR/IT/Finance platform. Requires 5+ years in product security, fluency in Python/React/DRF, and experience leading cross-team vulnerability remediation.

151k – 280kSan Francisco, CA +3Security EngineeringHybrid5+ YOESSOSAML

Senior Software Security Engineer

Senior security engineer building and maintaining identity, secrets, and cloud security systems for AI infrastructure. Requires 5+ years experience, strong Python/Go/Rust skills, and cloud security expertise.

320k – 405kSan Francisco, CA +2Security EngineeringHybrid5+ YOEGoIAM

Software Engineer - Security Platform

Build and operate secure distributed systems for secrets/key management, PKI, and machine identity across Cloudflare's global network. Requires 8+ years experience in software development, distributed systems, and security implementation.

168k – 275kAustin, TX +5Security EngineeringHybrid8+ YOEGoPki

Security Engineer, Cloud

Security Engineer building and hardening cloud-native security controls, infrastructure-as-code, and CI/CD pipelines for a scalable platform. Requires 8+ years in infrastructure/platform security and deep expertise in AWS/GCP and Kubernetes.

208k – 312kUnited StatesSecurity EngineeringRemote8+ YOEAWSGCP