We are looking for a Senior Platform Engineer to join a self-managed, three-person consultant team responsible for establishing the client's central package management platform. This role works hands-on across platform selection, implementation, security, and automation, operating independently within the team's shared backlog with limited day-to-day direction from the client.
Responsibilities
- Deliver hands-on platform engineering, package management, and SaaS administration for the target platform (JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith)
- Implement and maintain security controls: upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
- Build integrations with the client identity and engineering landscape — GitHub Enterprise Cloud, Entra ID security groups, OIDC, access provisioning
- Manage platform configuration, repositories, access models, and policies through Infrastructure-as-Code, APIs, or comparable automation (e.g., Pulumi)
- Support developer enablement across key package ecosystems (NuGet, PyPI, CRAN, Maven/Gradle, npm, Docker/OCI)
- Contribute to requirements gathering, technical validation of candidate platforms, and implementation planning
- Support users of the current interim JFrog Artifactory environment as part of shared team capacity (~10% total team effort)
- Produce clear technical documentation, operational procedures, and runbooks
- Collaborate proactively with the team lead and the other Senior Platform Engineer to plan tasks, surface risks, and maintain delivery momentum
Requirements
- 5+ years of software development experience with practical understanding of how development teams consume, build, publish, and troubleshoot external and internal packages
- Hands-on experience with enterprise package/artifact management platforms — at least one of JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
- Experience operating and managing enterprise SaaS platforms: identity, access management, security, observability, operational processes, and vendor support
- Strong Infrastructure-as-Code / Configuration-as-Code mindset — managing platform configuration, access models, repositories, and policies through APIs, Pulumi, or comparable tooling
- Experience with software supply-chain security controls: public upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, package quarantine, and controlled promotion
- Experience integrating engineering platforms with enterprise identity and modern workload authentication patterns — Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
- Working knowledge across common package ecosystems — several of: NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
- Ability to produce concise technical documentation, architecture decisions, operational procedures, and implementation plans suitable for an enterprise environment
Nice to have
- Experience with GitHub Actions and short-lived workload credentials (avoiding long-lived personal access tokens)
- Experience with enterprise audit, logging, monitoring, and segregation-of-duties controls
- Exposure to regulated industries or enterprise-scale developer platforms (thousands of consuming developers)