Company Description MSD Animal Health Tech Solutions R&D is the technology division of MSD Animal Health, focused on developing advanced animal health management solutions. The team includes around 450 specialists, such as scientists, AI experts, and engineers in software, hardware, and mechanics, working closely with veterinarians and animal experts. Its products and platforms analyze trends and predict health outcomes for hundreds of millions of animals worldwide, including pets, poultry, farm animals, and fish. Operating in 150 markets, the company provides actionable insights that help professionals care for animals more effectively. Applicants joining MSD Animal Health Tech Solutions R&D can expect to work in an environment that combines pioneering science, technology, and a strong commitment to animal well-being.
Position Overview
We are looking for a Platform Engineer to join our DevEx Platform team — a champion who collaborates, innovates, and treats every problem as a mission to be completed. You will help build and operate the internal platform that other engineering teams depend on: GitOps delivery, Kubernetes-based runtime, infrastructure automation, and developer self-service capabilities.
This is a role for builders. We don't need a person who waits to be told what to do. We need someone who picks up a mission, drives it across teams, brings the right people in, and ships outcomes — not tickets.
If you are a team player who is assertive, takes new tasks as missions, and refuses to leave a problem half-solved — your place is with us.
You will work shoulder-to-shoulder with CloudOps, DevSecOps, FinOps, and SRE functions, and you will use AI and Agentic AI as everyday tools to accelerate everything you do — code generation, automation, troubleshooting, documentation, and platform tooling. We expect AI fluency, not curiosity.
Who You Are
- Team player and collaborator — you build with people, not around them
- Assertive and decisive — you propose, defend, and drive technical direction
- Mission-driven — every task is a mission; you finish what you start
- Innovator and champion — you bring new ideas in and rally the team around them
- AI-native — you use AI assistants and agentic workflows daily to multiply your output
- Curious and continuous — you treat learning as part of the job, not extra credit
Our Environment
This full-time Platform Engineer role is based in Prague in a hybrid work setting, combining on-site collaboration with flexibility for some work from office.
You will operate in a modern, multi-account AWS landing zone:
- AWS Control Tower as the landing-zone foundation, with guardrails and account vending
- AWS IAM Identity Center (formerly AWS SSO) for federated access across accounts
- Multi-account strategy — separate accounts per environment, workload, and team (production, staging, dev, sandbox, shared services, security, logging)
- Sandbox accounts for experimentation and proof-of-concept work, with cost and security guardrails
- Multi-VPC topologies connected via Transit Gateway, with VPC endpoints for private service access
- EKS as the runtime for platform and product workloads
- GitOps with ArgoCD as the delivery model
- Terraform / OpenTofu as the IaC layer
- Crossplane-powered control planes — modern, Kubernetes-native infrastructure management with composed APIs that turn cloud resources into self-service primitives
- GitHub as a managed platform surface — the platform team owns GitHub org management end-to-end:
- Org, teams, and repo lifecycle (templates, naming, archival, ownership)
- GitHub Actions for CI, reusable workflows, environment-scoped secrets, OIDC federation to AWS
- Branch & environment protections, code-owners-driven reviews, signed commits, required checks
- CI bots for PR validation, auto-labeling, auto-assignment, and auto-merge on green builds
- Copilot org policies and custom Copilot instructions baked into repos to standardize AI-assisted development
- AI-augmented development with Copilot and Claude wired into the daily flow
- JFrog Artifactory as the artifact backbone — container images, Helm charts, language-package registries (Maven, npm, PyPI), with Xray scanning, retention policies, and signed/promoted artifacts moving through environments
Key ResponsibilitiesPlatform Engineering (Core)
- Build and operate the internal platform: GitOps delivery, Kubernetes runtime, infrastructure automation, and developer self-service capabilities
- Apply platform-as-product thinking — product teams are your customers; developer experience is the metric
- Contribute to the team's evolution toward IDP capabilities on Port, Crossplane, and self-service control planes
- Maintain and extend Infrastructure as Code (Terraform / OpenTofu) for platform components
- Ship POCs that turn into platform capabilities
AI & Agentic AI in Daily Work
- Use AI coding assistants (Claude, Copilot, or similar) for code, IaC, and platform automation
- Design and use agentic AI workflows to automate repetitive platform tasks — investigation, remediation, documentation, scaffolding
- Build AI-augmented tooling into the platform itself where it accelerates product teams
- Set the bar for the team on responsible, effective use of AI in engineering work
Cloud, AWS & Networking (Foundational)
- Operate confidently in AWS: EKS, IAM, S3, RDS, Lambda, CloudWatch
- Networking proficiency is required: VPC design, subnets, CIDR planning, route tables, security groups, NACLs, peering, Transit Gateway, VPC endpoints, DNS (Route53)
- Troubleshoot connectivity, ingress/egress, and cross-account/cross-VPC traffic flows
- Apply networking knowledge to Kubernetes: Services, Ingress, Network Policies, CNI behavior
GitOps & Kubernetes (Day-One Operational)
- Operate ArgoCD as a core platform capability: GitOps workflows, application/infrastructure delivery, multi-environment promotion
- Own ApplicationSets-driven multi-version, branch, and PR deployment patterns — providing the platform capability while product teams consume it
- Deploy, troubleshoot, and instrument Kubernetes workloads
- Apply progressive delivery patterns (canary, blue-green) where they fit
GitHub Org & Artifact Management (Platform-Owned)
- Manage the GitHub organization as a platform service: orgs, teams, repos, templates, code owners, branch and environment protections, secrets, OIDC to AWS
- Build and maintain reusable GitHub Actions workflows that product teams consume out of the box
- Operate CI bots for PR validation, auto-labeling, auto-merge on green, and policy enforcement
- Curate Copilot org policies and custom Copilot instructions so AI assistance is consistent and safe across repos
- Operate JFrog Artifactory as the artifact backbone: registries, retention, promotion paths, Xray scanning, and signed artifacts flowing through environments
Collaboration & Leadership
- Collaborate with CloudOps, DevSecOps, FinOps, and SRE — peer-to-peer, not siloed
- Mentor team members; deliver POCs, technical presentations, and documentation
- Bring innovation to the team: new tools, new patterns, new ways of working
- Champion shared standards across the platform community
Required QualificationsMust-Have Skills
- 7+ years in Platform Engineering, SRE, or closely related roles
- Platform mindset — you build platforms and self-service capabilities; you do not run a ticket queue
- AI fluency: hands-on daily use of AI coding assistants and agentic AI workflows to deliver engineering work
- AWS proficiency: EKS, IAM, S3, RDS, Lambda, CloudWatch, and the operational fundamentals
- AWS networking: VPC, subnets, CIDR planning, route tables, security groups, NACLs, peering / Transit Gateway, VPC endpoints, Route53 — confident designing and troubleshooting multi-VPC topologies
- Kubernetes: strong operational proficiency — deploying, troubleshooting, and instrumenting workloads (not cluster architecture)
- ArgoCD & GitOps: multi-environment Kubernetes deployments, ApplicationSets, progressive delivery
- Terraform / OpenTofu: proficiency with declarative infrastructure management
- CI/CD: tool-agnostic pipeline design (Azure DevOps, GitHub Actions, or both)
- GitHub as a platform: org/team/repo administration, reusable Actions workflows, branch and environment protections, OIDC to AWS, CI bots for PR validation and auto-merge, and Copilot org policies / custom Copilot instructions
- Artifact management: hands-on with JFrog Artifactory (or directly comparable, e.g., Nexus, GitHub Packages at scale) — registries, retention, promotion, vulnerability scanning
- Scripting: Python, Go, Bash, or similar for automation and tooling
- Team player and assertive collaborator: works effectively across Platform, CloudOps, DevSecOps, FinOps, and SRE functions; takes initiative and finishes missions
Highly Desirable Skills (Big Advantages)
- IDP tools (Stack Port, Backstage) — central to where the team is heading
- Crossplane for Kubernetes-based infrastructure management
- Argo ecosystem depth (Rollouts, Workflows, Events)
- SRE practices: SLOs, SLIs, error budgets, incident response, post-incident reviews
- DORA metrics: defining, tracking, and driving measurable delivery improvement
- Building or operating internal AI-powered developer tools
Additional Valuable Skills (Plus)
- Observability: Datadog, OpenTelemetry, Prometheus & Grafana — instrumentation, dashboards, alerting (a Plus, not a requirement)
- Service mesh (Istio, Linkerd)
- FinOps practices and cloud cost optimization tooling
- Policy as Code (OPA, Kyverno)
- Certifications: CKA/CKAD, AWS Solutions Architect/DevOps Engineer/Advanced Networking, HashiCorp Terraform
- If you are a team player, assertive, mission-driven, and you build with AI as a daily partner — your place is with us. This is a contractor position. Know anybody who might be interested? Refer this job.