Strong 5+ years of software development experience with an applied understanding of package build, publishing, consumption, and troubleshooting workflows
Hands-on experience with at least one enterprise artifact management platform: JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
Demonstrated ability to operate enterprise SaaS platforms, including identity, access management, security, observability, operational processes, and vendor support
Deep Infrastructure-as-Code / Configuration-as-Code experience for managing configuration, repositories, policies, and access models using APIs, Pulumi, or similar tooling
Proven track record implementing software supply-chain security controls such as upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
Solid experience integrating engineering platforms with enterprise identity and modern authentication patterns, including Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
Working knowledge across several package ecosystems such as NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
Ability to produce concise technical documentation, architecture decisions, operational procedures, and implementation plans fit for enterprise use
Experience with GitHub Actions and short-lived workload credentials to avoid long-lived personal access tokens
Experience with enterprise audit, logging, monitoring, and segregation-of-duties controls
Exposure to regulated industries or enterprise-scale developer platforms with thousands of consuming developers