Salary Range:$117,600.00 - $196,200.00
This pay range represents the minimum and maximum compensation that the position offers, and final compensation can vary within the range depending on work location, job experience, skills, and relevant educational attainment and/or training.Job Title: Software Development Platform Architect & AdministratorKey ResponsibilitiesPlatform Administration & Governance- Administer and maintain Azure DevOps and GitHub organizations, including projects, repositories, pipelines, permissions, and policies.
- Manage platform governance, including branch protections, environment controls, and repository standards.
- Support onboarding, configuration, and lifecycle management of development tools, integrations, and automation services.
Identity, Access, and Security Management- Manage and govern service principals, managed identities, and application registrations used across CI/CD and automation workflows.
- Implement best practices for token lifecycle management, including PATs, OAuth tokens, GitHub App tokens, and workload identities.
- Enforce secure authentication and authorization patterns, including least privilege access, role-based access control (RBAC), and conditional access policies.
- Monitor and audit identity usage across platforms to detect anomalies, expired credentials, or misconfigurations.
- Partner with security teams to ensure compliance with enterprise identity standards and regulatory requirements.
SDLC & CI/CD Enablement- Support teams in implementing and optimizing SDLC processes aligned with organizational standards.
- Build, maintain, and troubleshoot CI/CD pipelines across Azure DevOps and GitHub Actions.
- Improve build, test, and deployment workflows to increase reliability, repeatability, and speed.
- Promote best practices in automation, artifact management, and release engineering.
Security & Compliance- Implement and maintain security tooling such as SAST, dependency scanning, secrets detection, and policy enforcement.
- Ensure secure configuration of pipelines, runners/agents, and platform integrations.
- Assess, govern, and securely integrate AI-assisted development tools (e.g., copilots, code review assistants, chat/agent automations) into Azure DevOps/GitHub and SDLC workflows by enforcing data protection and access controls (least privilege, secrets isolation, token hygiene), validating vendor/security posture, defining acceptable-use and logging/audit requirements, and mitigating risks such as sensitive data leakage, prompt injection, and supply-chain compromise.
- Participate in incident response and root cause analysis for platform or identity related issues.
- Document standards, patterns, and platform configurations to support operational excellence.
Architecture & Continuous Improvement- Contribute to the design and evolution of the software development platform architecture.
- Evaluate new tools, integrations, and identity models to improve developer productivity and platform scalability.
- Identify opportunities to simplify workflows, reduce friction, and standardize platform usage across teams.
QualificationsRequired- Hands-on experience administering Azure DevOps and GitHub in an enterprise environment.
- Strong understanding of CI/CD concepts, pipelines, and automation workflows.
- Familiarity with SDLC methodologies and development lifecycle tooling.
- Experience managing service principals, tokens, and identity based automation.
- Understanding of identity and access management (IAM) principles, including RBAC, least privilege, birthright, and credential hygiene.
- Ability to troubleshoot platform, pipeline, identity, integration issues, and REST APIs.
- Experience with security tooling such as code scanning, dependency management, or secrets detection.
- Strong communication skills and a collaborative mindset.
- Scripting experience (PowerShell, Bash, Python) for automation and identity governance.
- Applies Azure CLI to manage service principals, role assignments, and identity policies supporting secure DevOps architectures across Azure DevOps, GitHub, and Azure services.
Preferred- Experience with infrastructure-as-code (Terraform, ARM/Bicep) for platform and identity provisioning.
- Knowledge of cloud platforms, especially Azure and Microsoft Entra ID.
- Exposure to workload identity federation and modern token based authentication patterns.
- Experience administering Identity Governance platforms, including ConductorOne and SailPoint, with a focus on enterprise-level access governance and platform administration
- Experience integrating GHAS findings into Azure DevOps, SIEM/SOAR platforms, and secure SDLC pipelines to drive automated remediation and continuous hardening.
- Experience applying Hypervelocity engineering principles to accelerate developer workflows, reduce cognitive load, and streamline platform operations across Azure DevOps and GitHub.
- Experience designing and implementing Azure DevOps pipeline decorators to enforce organization-wide governance, inject mandatory security and compliance tasks, and standardize CI/CD behavior across all pipelines without requiring changes from individual development teams.
If you are in ETAP or RIB, please delete the below and this line.
Hybrid workingWe work in a hybrid way at AVEVA. Most roles are based at a local AVEVA office, with an expectation of being on-site 50% of your working hours to support collaboration and connection. Some positions are fully office-based depending on the nature of the work, and certain roles that support specific customers or markets may be remote. The working arrangement for this position will be confirmed during the hiring process.
Hiring processInterested? Great! Get started by submitting your cover letter and CV through our application portal. AVEVA is committed to recruiting and retaining people with disabilities. Please let us know in advance if you need reasonable support during your application process.
Find out more: aveva.com/en/about/careers/hiring-process