Demonstrated 5+ years of software development experience and practical knowledge of how engineering teams build, publish, consume, and debug package artifacts
Hands-on experience with enterprise package/artifact platforms, using at least one of JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
Experience managing enterprise SaaS platforms with focus on identity, access management, security, observability, operational processes, and vendor engagement
Strong Infrastructure-as-Code / Configuration-as-Code skills to manage repositories, access models, configuration, and policies via APIs, Pulumi, or comparable tooling
Hands-on experience with software supply-chain security controls including upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
Experience integrating engineering platforms with enterprise identity and modern workload authentication patterns, including Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
Working knowledge across common package ecosystems, including several of NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
Ability to create concise technical documentation, architecture decisions, operational procedures, and implementation plans for an enterprise environment
Experience with GitHub Actions and short-lived workload credentials, avoiding long-lived personal access tokens
Familiarity with enterprise audit, logging, monitoring, and segregation-of-duties controls
Exposure to regulated industries or enterprise-scale developer platforms serving thousands of developers