Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are delivering a centralized artifact management service and need a Senior Platform Engineer to implement it with strong security and automation. You will be part of a self-managed three-person consultant team, working hands-on from platform validation through rollout with limited day-to-day client direction. Apply now to improve developer workflows and governance.
Responsibilities
- Deliver platform engineering, package management, and SaaS administration for the target platform (JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith)
- Operate and improve security controls such as upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Create integrations with the client identity and engineering landscape, including GitHub Enterprise Cloud, Entra ID security groups, OIDC, and access provisioning
- Automate platform configuration, repositories, access models, and policies using Infrastructure-as-Code, APIs, or comparable tooling like Pulumi
- Enable developers across key ecosystems including NuGet, PyPI, CRAN, Maven/Gradle, npm, and Docker/OCI
- Contribute to requirements gathering, technical validation of candidate platforms, and implementation planning
- Provide user support for the interim JFrog Artifactory environment as part of shared team capacity (~10% total team effort)
- Develop clear technical documentation, operational procedures, and runbooks
- Collaborate with the team lead and the other Senior Platform Engineer to plan work, raise risks, and maintain delivery momentum
Requirements
- Demonstrated 5+ years of software development experience and practical knowledge of how engineering teams build, publish, consume, and debug package artifacts
- Hands-on experience with enterprise package/artifact platforms, using at least one of JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
- Experience managing enterprise SaaS platforms with focus on identity, access management, security, observability, operational processes, and vendor engagement
- Strong Infrastructure-as-Code / Configuration-as-Code skills to manage repositories, access models, configuration, and policies via APIs, Pulumi, or comparable tooling
- Hands-on experience with software supply-chain security controls including upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Experience integrating engineering platforms with enterprise identity and modern workload authentication patterns, including Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
- Working knowledge across common package ecosystems, including several of NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
- Ability to create concise technical documentation, architecture decisions, operational procedures, and implementation plans for an enterprise environment
Nice to have
- Experience with GitHub Actions and short-lived workload credentials, avoiding long-lived personal access tokens
- Familiarity with enterprise audit, logging, monitoring, and segregation-of-duties controls
- Exposure to regulated industries or enterprise-scale developer platforms serving thousands of developers
