Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are building a secure central package management platform and need a Senior Platform Engineer to drive selection, rollout, and automation. You will work hands-on in a self-managed three-person consultant team across implementation, security, and integrations with minimal daily client oversight. Apply now to help deliver a reliable enterprise platform.
Responsibilities
- Deliver hands-on platform engineering, package management, and SaaS administration for the selected platform (JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith)
- Implement and maintain security controls including upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Build integrations across the client identity and engineering landscape, including GitHub Enterprise Cloud, Entra ID security groups, OIDC, and access provisioning
- Manage platform configuration, repositories, access models, and policies using Infrastructure-as-Code, APIs, or comparable automation such as Pulumi
- Support developer enablement across core ecosystems including NuGet, PyPI, CRAN, Maven/Gradle, npm, and Docker/OCI
- Contribute to requirements gathering, technical validation of candidate platforms, and implementation planning
- Support users of the current interim JFrog Artifactory environment as part of shared team capacity (~10% total team effort)
- Produce clear technical documentation, operational procedures, and runbooks
- Collaborate proactively with the team lead and the other Senior Platform Engineer to plan tasks, surface risks, and maintain delivery momentum
Requirements
- Proven 5+ years of software development experience with practical knowledge of how teams consume, build, publish, and troubleshoot internal and external packages
- Hands-on experience with enterprise package/artifact management platforms, including at least one of JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
- Demonstrated experience operating enterprise SaaS platforms, covering identity, access management, security, observability, operational processes, and vendor support
- Strong Infrastructure-as-Code / Configuration-as-Code approach for managing configuration, access models, repositories, and policies via APIs, Pulumi, or similar tooling
- Solid background in software supply-chain security controls, including public upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Hands-on experience integrating engineering platforms with enterprise identity and modern workload authentication patterns such as Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
- Working knowledge across common package ecosystems, including several of NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
- Ability to write concise technical documentation, architecture decisions, operational procedures, and implementation plans for an enterprise environment
Nice to have
- Experience with GitHub Actions and short-lived workload credentials, avoiding long-lived personal access tokens
- Experience with enterprise audit, logging, monitoring, and segregation-of-duties controls
- Exposure to regulated industries or enterprise-scale developer platforms with thousands of consuming developers
