Proven 5+ years of software development experience with practical knowledge of how teams consume, build, publish, and troubleshoot internal and external packages
Hands-on experience with enterprise package/artifact management platforms, including at least one of JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
Demonstrated experience operating enterprise SaaS platforms, covering identity, access management, security, observability, operational processes, and vendor support
Strong Infrastructure-as-Code / Configuration-as-Code approach for managing configuration, access models, repositories, and policies via APIs, Pulumi, or similar tooling
Solid background in software supply-chain security controls, including public upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, quarantine, and controlled promotion
Hands-on experience integrating engineering platforms with enterprise identity and modern workload authentication patterns such as Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
Working knowledge across common package ecosystems, including several of NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
Ability to write concise technical documentation, architecture decisions, operational procedures, and implementation plans for an enterprise environment
Experience with GitHub Actions and short-lived workload credentials, avoiding long-lived personal access tokens
Experience with enterprise audit, logging, monitoring, and segregation-of-duties controls
Exposure to regulated industries or enterprise-scale developer platforms with thousands of consuming developers