5+ years of software development experience with practical understanding of how development teams consume, build, publish, and troubleshoot external and internal packages
Hands-on experience with enterprise package/artifact management platforms — at least one of JFrog Artifactory, Sonatype Nexus Repository, or Cloudsmith
Experience operating and managing enterprise SaaS platforms: identity, access management, security, observability, operational processes, and vendor support
Strong Infrastructure-as-Code / Configuration-as-Code mindset — managing platform configuration, access models, repositories, and policies through APIs, Pulumi, or comparable tooling
Experience with software supply-chain security controls: public upstream proxying, vulnerability and malware scanning, policy enforcement, license controls, package quarantine, and controlled promotion
Experience integrating engineering platforms with enterprise identity and modern workload authentication patterns — Entra ID, security groups, SSO, OIDC, GitHub Apps, or other short-lived credentials
Working knowledge across common package ecosystems — several of: NuGet/.NET, Python/PyPI, R/CRAN, Java/Maven/Gradle, JavaScript/npm, Docker/OCI
Ability to produce concise technical documentation, architecture decisions, operational procedures, and implementation plans suitable for an enterprise environment
Experience with GitHub Actions and short-lived workload credentials (avoiding long-lived personal access tokens)
Experience with enterprise audit, logging, monitoring, and segregation-of-duties controls
Exposure to regulated industries or enterprise-scale developer platforms (thousands of consuming developers)