Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are forming a central artifact and package management capability and need a Senior Platform Engineer to implement it securely end-to-end. You will operate within a self-managed three-person consultant team, owning automation, integrations, and SaaS administration with limited day-to-day client direction. Apply now to help standardize and secure package delivery.
Responsibilities
- Provide hands-on platform engineering, package management, and SaaS administration for the target platform (JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith)
- Maintain end-to-end security controls such as upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Implement integrations with the client identity and engineering ecosystem, including GitHub Enterprise Cloud, Entra ID security groups, OIDC, and access provisioning
- Automate platform configuration, repositories, access models, and policies via Infrastructure-as-Code, APIs, or comparable tooling such as Pulumi
- Enable developers across major ecosystems including NuGet, PyPI, CRAN, Maven/Gradle, npm, and Docker/OCI
- Participate in requirements gathering, technical validation of candidate platforms, and implementation planning
- Assist users of the interim JFrog Artifactory setup as part of shared team capacity (~10% total team effort)
- Create and maintain technical documentation, operational procedures, and runbooks
- Coordinate with the team lead and the other Senior Platform Engineer to plan work, raise risks early, and keep delivery moving
Requirements
- Extensive 5+ years of software development experience and a practical understanding of how development teams build, publish, consume, and troubleshoot packages
- Practical experience with enterprise artifact/package platforms such as JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith (at least one required)
- Experience running enterprise SaaS platforms, including IAM, security, observability, operational processes, and working with vendor support
- Infrastructure-as-Code / Configuration-as-Code mindset for controlling repositories, policies, configuration, and access models through APIs, Pulumi, or comparable tools
- Proven experience applying software supply-chain security controls like upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Experience integrating engineering platforms with enterprise identity and workload authentication, including Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
- Broad working knowledge of package ecosystems, spanning several of NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
- Strong ability to produce clear technical documentation, architecture decisions, operational procedures, and implementation plans for enterprise stakeholders
Nice to have
- Experience with GitHub Actions and short-lived workload credentials instead of long-lived personal access tokens
- Familiarity with enterprise audit, logging, monitoring, and segregation-of-duties controls
- Exposure to regulated industries or enterprise-scale developer platforms serving thousands of developers
