Why we are hiring

We run JFrog Artifactory as the single source of truth for all deployable software artifacts across our platform. Every external dependency (npm, PyPI, Go, Docker, Cargo) is pulled through Artifactory, and every image is scanned by JFrog Xray before it is distributed to customers. Artifactory is now business-critical infrastructure, and it has outgrown the way we currently operate it.

Our JFrog usage has been running well beyond its contracted quota, driven overwhelmingly by network egress bandwidth rather than storage. Simply increasing the quota carries a multi-year commitment, so we need to reduce and control consumption rather than buy our way out. In parallel, regulated customers increasingly require deployment artifacts to be mirrored into registries they own (Azure ACR / AWS ECR), which today is handled by manual, customer-specific crane/skopeo scripts that do not scale.

We need a dedicated engineer to take ownership of this domain: bring consumption under control, harden and standardize how we run Artifactory, and design and build the automated mirroring / distribution capability that reduces our dependence on high-cost JFrog egress while keeping JFrog as the authoritative, Xray-scanned source of truth.

What you will own

Cost & consumption optimization (immediate priority)

  • Analyze JFrog bandwidth and storage consumption by repository, image, and cost center to identify the drivers of egress overage.
  • Implement reductions already scoped by the team, e.g. migrating image builds to compiled/transpiled artifacts only (no source code) and pruning storage usage.
  • Establish ongoing monitoring, quota alerting, and reporting so overages are caught early rather than discovered on the monthly invoice.

Artifact distribution & mirroring platform

  • Design and build a standardized, event-driven image mirroring / sync service that distributes promoted artifacts from JFrog Artifactory to customer-owned OCI registries (Azure ACR, AWS ECR), replacing today's manual scripts.
  • Deliver the qualities expected of a production platform service: policy-driven routing, idempotent operations, retries with backoff, digest/manifest verification, dead-letter handling, and full observability.
  • Evaluate and build the alternative distribution path for our highest-bandwidth cost centers, reducing reliance on direct JFrog egress while preserving Xray scanning and provenance.

Artifactory administration & developer enablement

  • Administer Artifactory repositories, access, tokens, and authentication (including secure machine-to-machine auth for CI/CD).
  • Own and improve package-manager configuration across the org (npm/PNPM, PyPI, Go, Docker, Cargo) and keep developer setup guides current.
  • Support supply-chain security posture — the move to Artifactory was driven by the 2025 npm supply-chain attacks — by keeping dependency resolution routed through approved, scanned repositories.

Reliability & operations

  • Manage destination registries and supporting infrastructure as code (Terraform / Terragrunt) on Kubernetes / AKS with Managed Identity and Key Vault integration.
  • Integrate mirroring and promotion events with existing CI/CD (GitHub Actions, JFrog webhooks) and instrument the service with metrics, structured logging, and alerting.

What we are looking for

Must-have

  • Strong hands-on experience administering JFrog Artifactory (repositories, permissions, access tokens, virtual/remote repos) and familiarity with JFrog Xray.
  • Depth in container and OCI artifact tooling: Docker, image registries (ACR and/or ECR), and copy/mirror tools such as skopeo or crane.
  • Solid DevOps engineering skills: CI/CD (GitHub Actions), Kubernetes, and Infrastructure as Code (Terraform / Terragrunt).
  • Working knowledge of package managers and dependency resolution across npm/PNPM, PyPI, Go, and Cargo.
  • A track record of cost or capacity optimization on a cloud or SaaS platform — measuring consumption and driving it down.
  • Ability to design and build a resilient backend service (event-driven, retries, verification, observability), not just script against tools.

Nice-to-have

  • Cloud-native authentication patterns (Managed Identity, OIDC, AcrPull) and secret management (Key Vault).
  • Software supply-chain security: SBOMs, artifact signing, provenance, zero-trust release pipelines.
  • Experience serving regulated / enterprise customers with strict network allowlisting and registry-ownership requirements.
  • Observability tooling (Prometheus, Application Insights, Datadog).

First 90 days — what success looks like

  • Month 1: A clear picture of JFrog consumption by cost center and a set of quick-win reductions in flight; quota alerting live.
  • Month 2: Measurable reduction in monthly egress; a validated design for the standardized mirroring service agreed with the platform team.
  • Month 3: A first automated mirroring path in production for at least one customer, replacing manual scripts, with monitoring and retries.

Senior Platform / DevOps Engineer

Apply Now
Back to search page