Job Title: Platform Engineer – DevOps Tooling & GitHub Enterprise

About the Role

We are looking for a Platform Engineer to join the team responsible for managing our core DevOps tooling ecosystem — GitHub Cloud, GitHub Enterprise Server, and Azure DevOps — along with the security, automation, and CI/CD tooling built around them. This role sits at the intersection of platform administration and hands-on engineering: you'll help operate and secure these platforms, build reusable pipeline and automation frameworks, and support internal engineering teams (including less-technical consumers of the platform) as they adopt new tools and processes. Day-to-day operational tasks are handled by a separate Ops team; this role is focused on the engineering-level work — building, securing, and scaling the platform.


Responsibilities

  • Administer and support GitHub Cloud, GitHub Enterprise Server, and Azure DevOps, including managing the ongoing migration of repositories, pipelines, and work item history (e.g., Azure Boards) from ADO to GitHub Enterprise.
  • Design, build, and maintain CI/CD pipelines and reusable GitHub Actions workflows (and Azure DevOps YAML pipelines where still required), including secret scanning, SAST, dependency/image scanning, and approval-gated deployment stages.
  • Build and manage self-hosted runner/agent infrastructure, including scalable, Kubernetes-backed runner solutions (e.g., Actions Runner Controller) to replace GitHub-hosted runners for teams affected by network/IP restrictions.
  • Integrate and maintain security tooling across the SDLC: secret scanning (GitLeaks), SAST (SonarQube), dependency and container image scanning (Trivy, Snyk, Checkmarx, Wiz), and DAST (OWASP ZAP).
  • Implement and enforce governance and guardrails, including secrets management via Azure Key Vault/AWS Secrets Manager, policy-as-code enforcement (e.g., OPA), Dependabot, and CodeQL.
  • Support containerized deployments to Kubernetes-based platforms (AKS, EKS/ECS, or OpenShift/ARO), including writing and maintaining Helm charts and Kubernetes manifests.
  • Develop and maintain Infrastructure-as-Code using Terraform, and automate recurring platform tasks using Python and Shell scripting.
  • Build reporting/analytics processes to track platform usage (e.g., AI coding assistant consumption and billing data) and deliver that data to relevant teams.
  • Evaluate and integrate AI development tools (GitHub Copilot, Cursor, Claude Code, and similar) into engineering workflows, and help pilot/roll out new AI platforms as they're adopted.
  • Partner directly with engineering teams — including less technically-oriented consumers of the platform — to troubleshoot issues, build self-service processes, and support adoption of new tooling and pipeline changes.

Required Skills and Qualifications

  • 5+ years of experience in a DevOps, Platform Engineering, or DevSecOps role.
  • Hands-on experience with GitHub (Actions, Enterprise administration, self-hosted runners) and Azure DevOps (pipelines, agent pools).
  • Practical experience with CI/CD pipeline design, including integrating security and quality gates (SAST, secret scanning, dependency/image scanning) directly into the pipeline.
  • Experience with container technologies and orchestration platforms (Kubernetes, Docker), including writing deployment manifests and/or Helm charts.
  • Experience integrating and managing secrets via a vault solution (Azure Key Vault or AWS Secrets Manager).
  • Working knowledge of at least one Infrastructure-as-Code tool (Terraform preferred).
  • Proficiency in Python and/or Shell scripting for automation.
  • Experience with artifact/package management tools (JFrog Artifactory, GitHub Packages, Nexus, or similar).
  • Practical, hands-on experience using AI coding assistants (GitHub Copilot, Cursor, Claude Code, or similar) as part of daily engineering work.
  • Strong troubleshooting skills and the ability to communicate technical concepts clearly to both technical and non-technical stakeholders.
  • A demonstrated ability to learn new platforms and tools quickly, and to build reusable, scalable processes rather than one-off fixes.

Preferred Skills and Qualifications

  • Experience leading or heavily contributing to a large-scale CI/CD platform migration (e.g., Azure DevOps to GitHub Enterprise, or Jenkins to Tekton).
  • Experience with GitOps deployment patterns and tools such as Argo CD.
  • Experience with cloud-native, Kubernetes-based CI/CD tooling (e.g., Tekton).
  • Experience managing self-scaling, Kubernetes-backed runner/agent pools (e.g., Actions Runner Controller, VM scale sets).
  • Familiarity with DAST tooling (OWASP ZAP) and static analysis tools beyond SonarQube (Checkmarx, CodeQL).
  • Experience monitoring infrastructure and applications using Datadog or a comparable observability platform.
  • Exposure to building internal AI-assisted tools (e.g., using an LLM API or a platform like Microsoft Copilot Studio) to support engineering or business processes.
  • AWS experience (IAM roles/policies, hardened AMIs, EKS/ECS) is a plus for teams working in hybrid Azure/AWS environments.