Extensive 5+ years of software development experience and a practical understanding of how development teams build, publish, consume, and troubleshoot packages
Practical experience with enterprise artifact/package platforms such as JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith (at least one required)
Experience running enterprise SaaS platforms, including IAM, security, observability, operational processes, and working with vendor support
Infrastructure-as-Code / Configuration-as-Code mindset for controlling repositories, policies, configuration, and access models through APIs, Pulumi, or comparable tools
Proven experience applying software supply-chain security controls like upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
Experience integrating engineering platforms with enterprise identity and workload authentication, including Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
Broad working knowledge of package ecosystems, spanning several of NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
Strong ability to produce clear technical documentation, architecture decisions, operational procedures, and implementation plans for enterprise stakeholders
Experience with GitHub Actions and short-lived workload credentials instead of long-lived personal access tokens
Familiarity with enterprise audit, logging, monitoring, and segregation-of-duties controls
Exposure to regulated industries or enterprise-scale developer platforms serving thousands of developers