{"tool":"get_job","result":{"requisitionId":"546158_external_USA-NC-Salisbury","client":"Ahold Delhaize USA - PROD","title":"Principal Platform Engineer -Infrastructure Automation & Agentic Engineering","description":"<b>Category/Area of Expertise:</b> IT & Technology<br><b>Job Requisition:</b> 546158<br> <b>Address: </b>USA-NC-Salisbury-2110 Executive Drive <br><b>Store Code: </b>Infrastructure - Hosting (5118678) <br><br>Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which includes five leading omnichannel grocery brands - Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Our associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.<br><br><b><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Primary Purpose</span></b><br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">The Principal Platform Engineer is an enterprise-level individual contributor within the Technology Infrastructure Hosting team. The role shapes hosting-platform vision, strategy, roadmaps, governance, priorities, investment recommendations, and delivery outcomes for complex, business-critical initiatives across multiple teams and systems. It develops reusable modules, golden paths, self-service capabilities, engineering standards, evaluation methods, and operational controls across Windows Server, Active Directory and identity integrations; AIX/POWER and Linux; VMware, Nutanix, Hyper-V and related compute; storage, backup, SAN and NAS; middleware; networking and firewalls; Datadog, Nagios and related observability; ServiceNow CMDB, ITSM and workflow integrations; and adjacent infrastructure services. The engineer remains hands-on with code and production systems and converts approved designs, domain standards, runbooks, lifecycle obligations, and recurring work into secure, scalable, reliable, cost-effective, and version-controlled capabilities using IaC, configuration management, CI/CD, deterministic orchestration, and governed AI where it adds value.</span><br><br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">This role operates with broad decision-impacting opportunities over platform engineering priorities and outcomes without direct people-management responsibility. It aligns senior leaders and cross-functional stakeholders, establishes governance for consistent delivery, coaches senior technical leaders and engineers, resolves systemic cross-domain problems, and challenges unsupported completion claims with evidence. Engineering-whether manual, scripted, IaC-based, or AI-assisted-must improve scalability, developer and operator experience, reliability, security, lifecycle currency, recoverability, observability, auditability, service and financial outcomes.</span><br><br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Our flexible/hybrid work schedule includes 3 in-person days in our Salisbury, NC office and 2 remote days. </span><br><br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Applicants must be currently authorized to work in the United States on a full-time basis.</span><br><b><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Core Responsibilities</span></b><ul><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Platform strategy and roadmap. </strong>Define and execute the enterprise hosting-platform vision, multi-year roadmap, capability priorities, target outcomes, and investment sequencing. Use business analysis, demand, risk, lifecycle, service performance, experience, and cost data to recommend priorities and align senior stakeholders.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Governance and portfolio leadership. </strong>Establish decision rights, engineering standards, intake and prioritization methods, delivery controls, scorecards, and review forums for consistent platform outcomes. Lead complex initiatives across internal teams and external partners using Lean-Agile and SAFe-aligned planning, user stories, estimation, dependency management, and incremental delivery.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Cross-domain platform engineering. </strong>Translate approved designs into reusable implementation patterns, automation, and acceptance criteria spanning Windows/AD, AIX/Linux, VMware/Nutanix/Hyper-V, storage/backup/SAN/NAS, middleware, network/firewall, observability, and ServiceNow. Identify upstream and downstream dependencies, raise material design gaps to the accountable design authority, and verify implementation readiness.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Platform product and experience management. </strong>Treat shared infrastructure capabilities as products with defined users, service levels, adoption targets, roadmaps, documentation, support models, and feedback loops. Enable self-service through service catalogs, APIs, golden paths, and internal developer portal capabilities that reduce friction without weakening controls.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Infrastructure as Code and CI/CD. </strong>Implement approved designs with domain owners through secure IaC delivery pipelines using version control, peer review, automated validation, policy checks, plan/review/apply controls, secrets handling, artifact traceability, release gates, rollback, and drift detection. Work across Terraform or OpenTofu, Ansible, PowerShell, Python, ARM/Bicep, and applicable platform-native automation.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Runbook-to-automation engineering. </strong>Identify high-volume, high-risk, and toil-heavy runbooks; decompose procedures into deterministic steps; define prerequisites, approvals, validations, error handling, rollback, evidence capture, and exception paths; then deliver production-ready orchestration.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Generative and Agentic AI for operations. </strong>Design and implement governed AI-assisted workflows that can interpret approved runbooks, assemble execution plans, invoke tools, preserve state, request approvals, produce evidence, and stop safely when confidence, policy, or environmental conditions are not met.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Prompt and context engineering. </strong>Create version-controlled system instructions, task prompts, tool descriptions, retrieval/context strategies, structured outputs, and prompt test suites. Manage prompt injection, data-boundary, hallucination, and tool-misuse risks through least privilege, allowlists, approvals, and validation.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Agent harnesses and orchestration. </strong>Engineer the runtime scaffolding around agents, including tool interfaces, session state, memory, planning, bounded loops, approval policies, observability, error recovery, and human-in-the-loop handoffs. Separate model reasoning from deterministic control logic and privileged execution.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Continuous agentic improvement. </strong>Establish bounded self-improvement loops in which production telemetry, failed cases, reviewer feedback, and test results propose changes to prompts, policies, tools, or workflows. Require evaluation, versioning, peer review, approval, and controlled rollout before promotion. Do not permit unreviewed self-modification in production.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Evaluation and quality engineering. </strong>Build offline and pre-production evaluation harnesses for task success, tool choice, policy compliance, grounding, security, latency, cost, failure recovery, and reproducibility. Maintain representative test cases, regression suites, red-team scenarios, and release thresholds.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Financial and capacity stewardship. </strong>Apply financial analysis and FinOps practices to platform planning and delivery, including demand and capacity forecasting, unit-cost and consumption visibility, cost allocation, vendor and licensing trade-offs, optimization opportunities, and benefit realization. Balance resilience, performance, technical debt, experience, and cost in recommendations.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Security, risk, and compliance by design. </strong>Coordinate with Security and Governance to embed approved identity, secrets, least privilege, MFA, logging, audit evidence, encryption, policy-as-code, vulnerability controls, and exception-management requirements within automation and agent solutions. Align AI lifecycle controls to approved enterprise risk practices and NIST-aligned governance.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Reliability and observability. </strong>Define SLIs, SLOs, telemetry, traces, dashboards, alerts, run histories, change evidence, and operational health measures for pipelines and agents. Lead troubleshooting and systemic correction for high-impact platform and automation failures.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Platform lifecycle and resilience. </strong>Set and enforce lifecycle practices for provisioning, configuration, patching, upgrades, currency, backup, restore, high availability, disaster recovery, decommissioning, documentation, and operational reporting. Ensure lifecycle risk and recovery readiness are visible in roadmaps and governance decisions.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Basis Engineering and Definition of Done. </strong>Translate domain specifications into pipelines, controls, scorecards, reference implementations, and acceptance criteria. A capability is not done until authoritative inventory and ownership are recorded; supported lifecycle and compatibility are verified; security and privileged-access controls pass; testing covers normal, failure, rollback, and recovery paths; monitoring, logging, SLI/SLO and alert routing are operational; ServiceNow CI, dependency, change and knowledge records are complete; runbooks and support handoffs are current; evidence is retained; and exceptions have accountable owners and expiry dates.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Technical leadership and organizational capability. </strong>Set the technical bar, lead implementation and operational-readiness reviews, coach senior platform leaders and engineers, and strengthen capability across internal and supplier teams. Independently verify completion claims using artifacts, telemetry, CMDB records, test results, monitoring coverage, recovery evidence, financial outcomes, and change results; communicate material risks, trade-offs, and recommendations to senior leadership.</span></li></ul><b><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Required Infrastructure Domain Breadth</span></b> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong><span style=\"color: white;\">Domain</span></strong></span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong><span style=\"color: white;\">Principal-level evidence expected</span></strong></span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong><span style=\"color: black;\">Windows and identity</span></strong></span><br> <br><span style=\"color: black; font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Windows Server lifecycle, Active Directory/GPO, DNS, privileged access, patching, configuration baselines, hybrid identity dependencies, PowerShell/DSC and recovery.</span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>AIX and Linux</strong></span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">AIX/POWER, HMC/PowerVM/NIM, RHEL or equivalent Linux, package and kernel lifecycle, SSH/PAM/sudo, Ansible, filesystem and multipath dependencies, patching and recovery.</span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong><span style=\"color: black;\">Compute and virtualization</span></strong></span><br> <br><span style=\"color: black; font-family: arial, helvetica, sans-serif; font-size: 12pt;\">VMware vSphere/vCenter/ESXi, Nutanix AOS/Prism, Hyper-V or comparable platforms; capacity, firmware/compatibility, cluster resilience, migration, lifecycle and automation.</span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Storage, backup and SAN</strong></span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Block/file/storage services, Fibre Channel zoning and multipath, SAN/NAS lifecycle, backup policy, immutable protection, capacity, replication and tested restore or failover.</span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong><span style=\"color: black;\">Middleware and runtime</span></strong></span><br> <br><span style=\"color: black; font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Application servers, web tiers, messaging, integration runtimes or comparable middleware; configuration, certificates, dependencies, patching, HA, logging and performance.</span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Networking and firewalls</strong></span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">IP/DNS/load-balancing dependencies, routing, segmentation, firewall policy, ports and protocols, network change validation, telemetry and rollback coordination.</span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong><span style=\"color: black;\">Observability</span></strong></span><br> <br><span style=\"color: black; font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Datadog, Nagios or comparable platforms; coverage, tagging, service checks, metrics/logs/traces, SLI/SLO, actionable alerts, dependency suppression, synthetic health and evidence retention.</span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\"><strong>Service management</strong></span><br> <br><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">ServiceNow CMDB/Discovery, CI identification and reconciliation, completeness/correctness/compliance, service mapping, catalog/workflow, change, incident, problem and knowledge integration.</span><br> <b><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Required Qualifications</span></b><ul><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">12+ years of progressive infrastructure, platform, site reliability, or infrastructure software engineering experience, including principal-level ownership of complex cross-platform outcomes in large enterprise production environments.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Demonstrated production experience across at least four hosting-domain groups-Windows/AD; AIX/Linux; VMware/Nutanix/Hyper-V; storage/backup/SAN; middleware; networking/firewalls; observability; and ServiceNow-with deep hands-on expertise in at least two.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Hands-on ability to design, code, test, deploy and operate production automation using Python and at least two of PowerShell, Ansible, Terraform/OpenTofu, ARM/Bicep, shell scripting or comparable technologies.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Demonstrated experience applying Generative AI to engineering or operational workflows, including prompt engineering, context management, structured outputs, retrieval grounding, tool calling, and evaluation.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Direct experience designing or operating agentic workflows or autonomous/semi-autonomous systems with tool integration, state/memory, human approvals, observability, bounded execution, and failure recovery.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Experience creating evaluation harnesses, regression suites, test datasets, red-team cases, and measurable release gates for AI-enabled workflows.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Expert ability to define platform strategy and roadmaps, establish governance, lead complex multi-team initiatives, and align senior business and technology stakeholders around priorities and measurable outcomes.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Working mastery of Lean-Agile or SAFe principles, platform product management, business analysis, experience design, user stories, estimation, planning, dependency management, and incremental delivery.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Demonstrated financial analysis and FinOps capability, including demand and capacity forecasting, unit-cost and consumption analysis, cost allocation, licensing and vendor trade-offs, optimization, and benefits realization.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Strong knowledge of platform resource provisioning and configuration, CMDB and service mapping, patch and update management, incident/change/problem management, monitoring and logging, lifecycle and capacity management, documentation and reporting, security administration, backup, disaster recovery, high availability, runbook engineering, and production support.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Ability to translate ambiguous operational problems and approved direction into reusable engineering products, measurable outcomes, implementation patterns, and clear technical standards.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Proven ability to influence senior engineers, suppliers, technical stakeholders, and leaders and to challenge design assumptions through implementation evidence.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Bachelor's degree in computer science, engineering, information systems, or a related field, or equivalent demonstrable experience.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Able to work in the office a minimum of 3 days per week including every Tuesday, and Wednesday (excluding holidays & paid time off). </span></li></ul><b><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Preferred Qualifications</span></b><ul><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Experience engineering and automating hybrid hosting estates spanning enterprise data centers, retail or edge compute, cloud, managed-service delivery, and multiple supplier boundaries.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Experience with Microsoft Agent Framework, Azure AI/Foundry agent services, Semantic Kernel, LangGraph, or comparable orchestration frameworks.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Experience integrating ServiceNow CMDB, Discovery, service mapping, catalog/workflow, change, incident and knowledge processes with source control, IaC, observability and operational automation.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Experience with container platforms, Kubernetes, GitOps, golden paths, platform engineering, software supply-chain security, and artifact provenance.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Familiarity with NIST AI RMF and the Generative AI Profile, CIS Benchmarks, NIST Cybersecurity Framework, zero trust, PCI-related controls, and regulated enterprise environments.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Experience building self-service infrastructure products used by multiple engineering teams.</span></li><li><span style=\"font-family: arial, helvetica, sans-serif; font-size: 12pt;\">Published technical writing, implementation guidance, open-source contributions, conference participation, or a sustained technical community presence.</span></li><li><span style=\"font-size: 12pt; line-height: 107%; font-family: arial, helvetica, sans-serif;\">Relevant advanced certifications or directly equivalent demonstrated depth in Microsoft/Windows, Red Hat or IBM AIX, VMware, Nutanix, storage/SAN, networking/security, ServiceNow, observability, cloud, DevOps, Kubernetes or Terraform.</span></li></ul><br><span style=\"font-size: 12pt; line-height: 107%; font-family: arial, helvetica, sans-serif;\"><span xml:lang=\"EN-US\" data-contrast=\"auto\"><strong>Salary Range:</strong> </span><span xml:lang=\"EN-US\" data-contrast=\"auto\">$163,280 - $244,920</span><span data-ccp-props=\"{\"201341983\":0,\"335559731\":720,\"335559739\":0,\"335559740\":240,\"335572079\":6,\"335572080\":1,\"335572081\":4278190080,\"469789806\":\"single\"}\"> </span></span><br><br> Actual compensation offered to a candidate may vary based on their unique qualifications and experience, internal equity, and market conditions. Final compensation decisions will be made in accordance with company policies and applicable laws. <br><br><span style=\"color: white;\">#LI-Hybrid #LI-CW1</span><br><br>At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.<br><br>Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies.<br><br>Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work.<br><br>We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business.","department":"IT & Technology","departmentId":"669037b7dc60a8004b1930c7","employmentType":[{"value":"Full Time"}],"datePosted":"2026-08-31T00:00:00.000Z","applyUrl":"https://aholddelhaizeapply.appvault.com/external/home?jobId=546158&company=Ahold Delhaize USA Services, LLC","attributes":[""],"recruiterAssigned":null,"address":[{"city":"Salisbury","state":"NC","country":"USA","zipCode":"","address1":"2110 Executive Drive","location":{"type":"Point","coordinates":["",""]}}],"city":"Salisbury","state":"NC","zipCode":"","country":"USA","salaryMin":null,"salaryMax":null,"salRateType":null,"brandId":1037378,"createdAt":"2026-08-31T00:00:00.000Z","updatedAt":"2026-08-31T15:58:36.505Z"},"summary":"Job details for Principal Platform Engineer -Infrastructure Automation & Agentic Engineering"}