Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are standing up an enterprise package management platform and need a Senior Platform Engineer to deliver secure implementation and automation. You will work independently in a self-managed three-person consultant team, covering platform administration, integrations, and developer enablement with minimal client supervision. Apply now to help modernize software supply-chain controls.
Responsibilities
- Execute hands-on platform engineering, package management, and SaaS administration for the chosen platform (JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith)
- Implement and operate security controls including upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Integrate the platform with the client identity and engineering environment, including GitHub Enterprise Cloud, Entra ID security groups, OIDC, and access provisioning
- Maintain platform configuration, repositories, access models, and policies through Infrastructure-as-Code, APIs, or comparable automation such as Pulumi
- Support developer enablement across ecosystems including NuGet, PyPI, CRAN, Maven/Gradle, npm, and Docker/OCI
- Assist with requirements gathering, technical validation of candidate platforms, and implementation planning
- Provide support for users of the interim JFrog Artifactory environment as part of shared team capacity (~10% total team effort)
- Write clear technical documentation, operational procedures, and runbooks
- Partner with the team lead and the other Senior Platform Engineer to plan tasks, surface risks, and sustain delivery momentum
Requirements
- Strong 5+ years of software development experience with an applied understanding of package build, publishing, consumption, and troubleshooting workflows
- Hands-on experience with at least one enterprise artifact management platform: JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
- Demonstrated ability to operate enterprise SaaS platforms, including identity, access management, security, observability, operational processes, and vendor support
- Deep Infrastructure-as-Code / Configuration-as-Code experience for managing configuration, repositories, policies, and access models using APIs, Pulumi, or similar tooling
- Proven track record implementing software supply-chain security controls such as upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Solid experience integrating engineering platforms with enterprise identity and modern authentication patterns, including Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
- Working knowledge across several package ecosystems such as NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
- Ability to produce concise technical documentation, architecture decisions, operational procedures, and implementation plans fit for enterprise use
Nice to have
- Experience with GitHub Actions and short-lived workload credentials to avoid long-lived personal access tokens
- Experience with enterprise audit, logging, monitoring, and segregation-of-duties controls
- Exposure to regulated industries or enterprise-scale developer platforms with thousands of consuming developers
