Platform Engineer – Enterprise Golden Paths & Automated Governance
astrazeneca
Job Description
-
Golden Paths & Shared GitHub Actions: Design, build, and version enterprise-grade shared GitHub Actions (Composite Actions and Reusable Workflows) and standardized delivery templates to create secure, automated "Golden Paths" across product teams.
-
Reusable Infrastructure-as-Code: Build and maintain secure, modular Terraform modules and IaC assets, versioned and documented for broad reuse and easy consumption.
-
Embedded DevSecOps Controls: Integrate SAST, DAST, SCA, SBOM generation, and supply chain protections into default delivery workflows, shifting security left through automation and policy-as-code guardrails.
-
Secure CI/CD Patterns: Create scalable, resilient CI/CD patterns aligned to enterprise standards, applying least privilege and reducing configuration risk to strengthen operational reliability.
-
Automation and Internal Tooling: Develop automation services and developer tooling in Python or Golang that enable self-service onboarding, secure defaults, and consistent quality checks.
-
Multi-Environment Architecture: Chip in to solutions spanning cloud, serverless, containerized, compute, and hybrid environments, producing reference architectures, diagrams, and implementation guidance that accelerate adoption.
-
Testing and Quality Engineering: Define and execute testing strategies for infrastructure code and automation (unit, integration, and environment validation) to ensure repeatable, high-quality delivery.
-
Adoption and Continuous Improvement: Partner with product and platform consumers to drive adoption, capture feedback, and iterate on patterns and assets to enhance developer experience and business value.
-
AI-Enabled Engineering: Apply AI tools and techniques where appropriate to improve development speed, quality, secure design, and innovation, sharing learning and elevating team practices.
Essential Skills/Experience:
-
Significant 6+ years of experience in platform engineering, cloud engineering, DevSecOps, or a related technical engineering discipline.
-
GitHub Actions Platform Development: Hands-on experience authoring, testing, and maintaining centralized, reusable GitHub Actions (Composite Actions, Reusable Workflows) across an enterprise organization.
-
Pipeline Versioning & Security: Understanding of Semantic Versioning for GitHub Actions (@v1, @v2), supply chain pinning, and securing pipeline-to-AWS authentication using OpenID Connect (OIDC)
-
Strong experience with AWS, including services related to compute, networking, security, and serverless architectures.
-
Advanced expertise in Terraform and reusable infrastructure-as-code design.
-
Strong scripting or software engineering capability in Python or Golang.
-
Strong understanding of DevSecOps principles and controls, including SAST, DAST, SCA, SBOM, and software supply chain security.
-
Experience designing and implementing secure CI/CD pipelines within enterprise environments.
-
Solid grasp of security-by-design, the least privilege, and secure architecture principles.
-
Experience building scalable, reusable, modular platform solutions rather than one-off implementations.
-
Ability to create clear and effective user documentation and architecture artefacts.
-
Collaboration skills and ability to work optimally across engineering, security, and architecture teams.
-
Bachelor’s degree in Computer Science, Software Engineering, Information Technology, or a related field, or equivalent practical experience.
-
Relevant certifications in cloud, security, infrastructure, or DevOps/DevSecOps would be advantageous.
-