Ahold Delhaize USA
Jobs
Principal Platform Engineer -Infrastructure Automation & Agentic Engineering
Ahold Delhaize USA
Principal Platform Engineer -Infrastructure Automation & Agentic Engineering
Be an Early Applicant
Owns enterprise hosting-platform strategy, governance, roadmaps, and cross-domain engineering outcomes. Designs reusable infrastructure automation, IaC pipelines, self-service capabilities, observability, lifecycle controls, and governed generative or agentic AI workflows. Leads evaluation, reliability, security, FinOps, disaster recovery, and operational readiness while influencing senior stakeholders and coaching technical teams. The role spans Windows, Linux, AIX, virtualization, storage, middleware, networking, ServiceNow, and production infrastructure across a large enterprise.
Category/Area of Expertise: IT & Technology
Job Requisition: 546158
Address: USA-NC-Salisbury-2110 Executive Drive
Store Code: Infrastructure - Hosting (5118678)
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which includes five leading omnichannel grocery brands - Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Our associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.
Primary Purpose
The Principal Platform Engineer is an enterprise-level individual contributor within the Technology Infrastructure Hosting team. The role shapes hosting-platform vision, strategy, roadmaps, governance, priorities, investment recommendations, and delivery outcomes for complex, business-critical initiatives across multiple teams and systems. It develops reusable modules, golden paths, self-service capabilities, engineering standards, evaluation methods, and operational controls across Windows Server, Active Directory and identity integrations; AIX/POWER and Linux; VMware, Nutanix, Hyper-V and related compute; storage, backup, SAN and NAS; middleware; networking and firewalls; Datadog, Nagios and related observability; ServiceNow CMDB, ITSM and workflow integrations; and adjacent infrastructure services. The engineer remains hands-on with code and production systems and converts approved designs, domain standards, runbooks, lifecycle obligations, and recurring work into secure, scalable, reliable, cost-effective, and version-controlled capabilities using IaC, configuration management, CI/CD, deterministic orchestration, and governed AI where it adds value.
This role operates with broad decision-impacting opportunities over platform engineering priorities and outcomes without direct people-management responsibility. It aligns senior leaders and cross-functional stakeholders, establishes governance for consistent delivery, coaches senior technical leaders and engineers, resolves systemic cross-domain problems, and challenges unsupported completion claims with evidence. Engineering-whether manual, scripted, IaC-based, or AI-assisted-must improve scalability, developer and operator experience, reliability, security, lifecycle currency, recoverability, observability, auditability, service and financial outcomes.
Our flexible/hybrid work schedule includes 3 in-person days in our Salisbury, NC office and 2 remote days.
Applicants must be currently authorized to work in the United States on a full-time basis.
Core Responsibilities
Domain
Principal-level evidence expected
Windows and identity
Windows Server lifecycle, Active Directory/GPO, DNS, privileged access, patching, configuration baselines, hybrid identity dependencies, PowerShell/DSC and recovery.
AIX and Linux
AIX/POWER, HMC/PowerVM/NIM, RHEL or equivalent Linux, package and kernel lifecycle, SSH/PAM/sudo, Ansible, filesystem and multipath dependencies, patching and recovery.
Compute and virtualization
VMware vSphere/vCenter/ESXi, Nutanix AOS/Prism, Hyper-V or comparable platforms; capacity, firmware/compatibility, cluster resilience, migration, lifecycle and automation.
Storage, backup and SAN
Block/file/storage services, Fibre Channel zoning and multipath, SAN/NAS lifecycle, backup policy, immutable protection, capacity, replication and tested restore or failover.
Middleware and runtime
Application servers, web tiers, messaging, integration runtimes or comparable middleware; configuration, certificates, dependencies, patching, HA, logging and performance.
Networking and firewalls
IP/DNS/load-balancing dependencies, routing, segmentation, firewall policy, ports and protocols, network change validation, telemetry and rollback coordination.
Observability
Datadog, Nagios or comparable platforms; coverage, tagging, service checks, metrics/logs/traces, SLI/SLO, actionable alerts, dependency suppression, synthetic health and evidence retention.
Service management
ServiceNow CMDB/Discovery, CI identification and reconciliation, completeness/correctness/compliance, service mapping, catalog/workflow, change, incident, problem and knowledge integration.
Required Qualifications
Salary Range: $163,280 - $244,920
Actual compensation offered to a candidate may vary based on their unique qualifications and experience, internal equity, and market conditions. Final compensation decisions will be made in accordance with company policies and applicable laws.
#LI-Hybrid #LI-CW1
At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.
Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies.
Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work.
We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business.
#BI-Hybrid
Job Requisition: 546158
Address: USA-NC-Salisbury-2110 Executive Drive
Store Code: Infrastructure - Hosting (5118678)
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which includes five leading omnichannel grocery brands - Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Our associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.
Primary Purpose
The Principal Platform Engineer is an enterprise-level individual contributor within the Technology Infrastructure Hosting team. The role shapes hosting-platform vision, strategy, roadmaps, governance, priorities, investment recommendations, and delivery outcomes for complex, business-critical initiatives across multiple teams and systems. It develops reusable modules, golden paths, self-service capabilities, engineering standards, evaluation methods, and operational controls across Windows Server, Active Directory and identity integrations; AIX/POWER and Linux; VMware, Nutanix, Hyper-V and related compute; storage, backup, SAN and NAS; middleware; networking and firewalls; Datadog, Nagios and related observability; ServiceNow CMDB, ITSM and workflow integrations; and adjacent infrastructure services. The engineer remains hands-on with code and production systems and converts approved designs, domain standards, runbooks, lifecycle obligations, and recurring work into secure, scalable, reliable, cost-effective, and version-controlled capabilities using IaC, configuration management, CI/CD, deterministic orchestration, and governed AI where it adds value.
This role operates with broad decision-impacting opportunities over platform engineering priorities and outcomes without direct people-management responsibility. It aligns senior leaders and cross-functional stakeholders, establishes governance for consistent delivery, coaches senior technical leaders and engineers, resolves systemic cross-domain problems, and challenges unsupported completion claims with evidence. Engineering-whether manual, scripted, IaC-based, or AI-assisted-must improve scalability, developer and operator experience, reliability, security, lifecycle currency, recoverability, observability, auditability, service and financial outcomes.
Our flexible/hybrid work schedule includes 3 in-person days in our Salisbury, NC office and 2 remote days.
Applicants must be currently authorized to work in the United States on a full-time basis.
Core Responsibilities
- Platform strategy and roadmap. Define and execute the enterprise hosting-platform vision, multi-year roadmap, capability priorities, target outcomes, and investment sequencing. Use business analysis, demand, risk, lifecycle, service performance, experience, and cost data to recommend priorities and align senior stakeholders.
- Governance and portfolio leadership. Establish decision rights, engineering standards, intake and prioritization methods, delivery controls, scorecards, and review forums for consistent platform outcomes. Lead complex initiatives across internal teams and external partners using Lean-Agile and SAFe-aligned planning, user stories, estimation, dependency management, and incremental delivery.
- Cross-domain platform engineering. Translate approved designs into reusable implementation patterns, automation, and acceptance criteria spanning Windows/AD, AIX/Linux, VMware/Nutanix/Hyper-V, storage/backup/SAN/NAS, middleware, network/firewall, observability, and ServiceNow. Identify upstream and downstream dependencies, raise material design gaps to the accountable design authority, and verify implementation readiness.
- Platform product and experience management. Treat shared infrastructure capabilities as products with defined users, service levels, adoption targets, roadmaps, documentation, support models, and feedback loops. Enable self-service through service catalogs, APIs, golden paths, and internal developer portal capabilities that reduce friction without weakening controls.
- Infrastructure as Code and CI/CD. Implement approved designs with domain owners through secure IaC delivery pipelines using version control, peer review, automated validation, policy checks, plan/review/apply controls, secrets handling, artifact traceability, release gates, rollback, and drift detection. Work across Terraform or OpenTofu, Ansible, PowerShell, Python, ARM/Bicep, and applicable platform-native automation.
- Runbook-to-automation engineering. Identify high-volume, high-risk, and toil-heavy runbooks; decompose procedures into deterministic steps; define prerequisites, approvals, validations, error handling, rollback, evidence capture, and exception paths; then deliver production-ready orchestration.
- Generative and Agentic AI for operations. Design and implement governed AI-assisted workflows that can interpret approved runbooks, assemble execution plans, invoke tools, preserve state, request approvals, produce evidence, and stop safely when confidence, policy, or environmental conditions are not met.
- Prompt and context engineering. Create version-controlled system instructions, task prompts, tool descriptions, retrieval/context strategies, structured outputs, and prompt test suites. Manage prompt injection, data-boundary, hallucination, and tool-misuse risks through least privilege, allowlists, approvals, and validation.
- Agent harnesses and orchestration. Engineer the runtime scaffolding around agents, including tool interfaces, session state, memory, planning, bounded loops, approval policies, observability, error recovery, and human-in-the-loop handoffs. Separate model reasoning from deterministic control logic and privileged execution.
- Continuous agentic improvement. Establish bounded self-improvement loops in which production telemetry, failed cases, reviewer feedback, and test results propose changes to prompts, policies, tools, or workflows. Require evaluation, versioning, peer review, approval, and controlled rollout before promotion. Do not permit unreviewed self-modification in production.
- Evaluation and quality engineering. Build offline and pre-production evaluation harnesses for task success, tool choice, policy compliance, grounding, security, latency, cost, failure recovery, and reproducibility. Maintain representative test cases, regression suites, red-team scenarios, and release thresholds.
- Financial and capacity stewardship. Apply financial analysis and FinOps practices to platform planning and delivery, including demand and capacity forecasting, unit-cost and consumption visibility, cost allocation, vendor and licensing trade-offs, optimization opportunities, and benefit realization. Balance resilience, performance, technical debt, experience, and cost in recommendations.
- Security, risk, and compliance by design. Coordinate with Security and Governance to embed approved identity, secrets, least privilege, MFA, logging, audit evidence, encryption, policy-as-code, vulnerability controls, and exception-management requirements within automation and agent solutions. Align AI lifecycle controls to approved enterprise risk practices and NIST-aligned governance.
- Reliability and observability. Define SLIs, SLOs, telemetry, traces, dashboards, alerts, run histories, change evidence, and operational health measures for pipelines and agents. Lead troubleshooting and systemic correction for high-impact platform and automation failures.
- Platform lifecycle and resilience. Set and enforce lifecycle practices for provisioning, configuration, patching, upgrades, currency, backup, restore, high availability, disaster recovery, decommissioning, documentation, and operational reporting. Ensure lifecycle risk and recovery readiness are visible in roadmaps and governance decisions.
- Basis Engineering and Definition of Done. Translate domain specifications into pipelines, controls, scorecards, reference implementations, and acceptance criteria. A capability is not done until authoritative inventory and ownership are recorded; supported lifecycle and compatibility are verified; security and privileged-access controls pass; testing covers normal, failure, rollback, and recovery paths; monitoring, logging, SLI/SLO and alert routing are operational; ServiceNow CI, dependency, change and knowledge records are complete; runbooks and support handoffs are current; evidence is retained; and exceptions have accountable owners and expiry dates.
- Technical leadership and organizational capability. Set the technical bar, lead implementation and operational-readiness reviews, coach senior platform leaders and engineers, and strengthen capability across internal and supplier teams. Independently verify completion claims using artifacts, telemetry, CMDB records, test results, monitoring coverage, recovery evidence, financial outcomes, and change results; communicate material risks, trade-offs, and recommendations to senior leadership.
Domain
Principal-level evidence expected
Windows and identity
Windows Server lifecycle, Active Directory/GPO, DNS, privileged access, patching, configuration baselines, hybrid identity dependencies, PowerShell/DSC and recovery.
AIX and Linux
AIX/POWER, HMC/PowerVM/NIM, RHEL or equivalent Linux, package and kernel lifecycle, SSH/PAM/sudo, Ansible, filesystem and multipath dependencies, patching and recovery.
Compute and virtualization
VMware vSphere/vCenter/ESXi, Nutanix AOS/Prism, Hyper-V or comparable platforms; capacity, firmware/compatibility, cluster resilience, migration, lifecycle and automation.
Storage, backup and SAN
Block/file/storage services, Fibre Channel zoning and multipath, SAN/NAS lifecycle, backup policy, immutable protection, capacity, replication and tested restore or failover.
Middleware and runtime
Application servers, web tiers, messaging, integration runtimes or comparable middleware; configuration, certificates, dependencies, patching, HA, logging and performance.
Networking and firewalls
IP/DNS/load-balancing dependencies, routing, segmentation, firewall policy, ports and protocols, network change validation, telemetry and rollback coordination.
Observability
Datadog, Nagios or comparable platforms; coverage, tagging, service checks, metrics/logs/traces, SLI/SLO, actionable alerts, dependency suppression, synthetic health and evidence retention.
Service management
ServiceNow CMDB/Discovery, CI identification and reconciliation, completeness/correctness/compliance, service mapping, catalog/workflow, change, incident, problem and knowledge integration.
Required Qualifications
- 12+ years of progressive infrastructure, platform, site reliability, or infrastructure software engineering experience, including principal-level ownership of complex cross-platform outcomes in large enterprise production environments.
- Demonstrated production experience across at least four hosting-domain groups-Windows/AD; AIX/Linux; VMware/Nutanix/Hyper-V; storage/backup/SAN; middleware; networking/firewalls; observability; and ServiceNow-with deep hands-on expertise in at least two.
- Hands-on ability to design, code, test, deploy and operate production automation using Python and at least two of PowerShell, Ansible, Terraform/OpenTofu, ARM/Bicep, shell scripting or comparable technologies.
- Demonstrated experience applying Generative AI to engineering or operational workflows, including prompt engineering, context management, structured outputs, retrieval grounding, tool calling, and evaluation.
- Direct experience designing or operating agentic workflows or autonomous/semi-autonomous systems with tool integration, state/memory, human approvals, observability, bounded execution, and failure recovery.
- Experience creating evaluation harnesses, regression suites, test datasets, red-team cases, and measurable release gates for AI-enabled workflows.
- Expert ability to define platform strategy and roadmaps, establish governance, lead complex multi-team initiatives, and align senior business and technology stakeholders around priorities and measurable outcomes.
- Working mastery of Lean-Agile or SAFe principles, platform product management, business analysis, experience design, user stories, estimation, planning, dependency management, and incremental delivery.
- Demonstrated financial analysis and FinOps capability, including demand and capacity forecasting, unit-cost and consumption analysis, cost allocation, licensing and vendor trade-offs, optimization, and benefits realization.
- Strong knowledge of platform resource provisioning and configuration, CMDB and service mapping, patch and update management, incident/change/problem management, monitoring and logging, lifecycle and capacity management, documentation and reporting, security administration, backup, disaster recovery, high availability, runbook engineering, and production support.
- Ability to translate ambiguous operational problems and approved direction into reusable engineering products, measurable outcomes, implementation patterns, and clear technical standards.
- Proven ability to influence senior engineers, suppliers, technical stakeholders, and leaders and to challenge design assumptions through implementation evidence.
- Bachelor's degree in computer science, engineering, information systems, or a related field, or equivalent demonstrable experience.
- Able to work in the office a minimum of 3 days per week including every Tuesday, and Wednesday (excluding holidays & paid time off).
- Experience engineering and automating hybrid hosting estates spanning enterprise data centers, retail or edge compute, cloud, managed-service delivery, and multiple supplier boundaries.
- Experience with Microsoft Agent Framework, Azure AI/Foundry agent services, Semantic Kernel, LangGraph, or comparable orchestration frameworks.
- Experience integrating ServiceNow CMDB, Discovery, service mapping, catalog/workflow, change, incident and knowledge processes with source control, IaC, observability and operational automation.
- Experience with container platforms, Kubernetes, GitOps, golden paths, platform engineering, software supply-chain security, and artifact provenance.
- Familiarity with NIST AI RMF and the Generative AI Profile, CIS Benchmarks, NIST Cybersecurity Framework, zero trust, PCI-related controls, and regulated enterprise environments.
- Experience building self-service infrastructure products used by multiple engineering teams.
- Published technical writing, implementation guidance, open-source contributions, conference participation, or a sustained technical community presence.
- Relevant advanced certifications or directly equivalent demonstrated depth in Microsoft/Windows, Red Hat or IBM AIX, VMware, Nutanix, storage/SAN, networking/security, ServiceNow, observability, cloud, DevOps, Kubernetes or Terraform.
Salary Range: $163,280 - $244,920
Actual compensation offered to a candidate may vary based on their unique qualifications and experience, internal equity, and market conditions. Final compensation decisions will be made in accordance with company policies and applicable laws.
#LI-Hybrid #LI-CW1
At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.
Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies.
Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work.
We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business.
#BI-Hybrid
Ahold Delhaize USA Salisbury, North Carolina, USA Office
2110 Executive Dr, Salisbury, NC, United States, 28147
Similar Jobs at Ahold Delhaize USA
AdTech • eCommerce • Food • Marketing Tech • Retail
Supports digital analytics for grocery websites and apps by repurposing brand reports, learning GA4, Adobe Analytics, and Power BI, and ensuring reporting accuracy and quality. Provides data insights to stakeholders across departments and helps improve business KPIs. The co-op requires quantitative analysis skills, business understanding, attention to detail, and strong presentation or visual storytelling abilities.
Top Skills:
Adobe AnalyticsGa4Power BISQLTableau
AdTech • eCommerce • Food • Marketing Tech • Retail
Participate in a software engineering co-op focused on Master Data Management for retail product, vendor, and location domains. Learn MDM implementation, data quality, AI applications, Agile methodologies, and Product Owner practices within a Scrum team. Apply programming, database, SQL, documentation, troubleshooting, analytical, and software development lifecycle skills while delivering project work and an AI-focused MDM or data quality project.
Top Skills:
AgileAIDatabasesDatabricksMaster Data ManagementScrumSQL
AdTech • eCommerce • Food • Marketing Tech • Retail
Develop software for a next-generation loyalty platform supporting marketing, advertising, customer behavior analytics, targeted offers, coupons, and communications. The co-op will help build Azure-based cloud foundations using Databricks and Spring Boot microservices while collaborating with a team and learning modern technologies. The program includes mentorship, leadership development, community service, networking, and opportunities to present project work to company leaders.
Top Skills:
Amazon Web ServicesDatabricksDocument DatabasesJavaJavaScriptKotlinMicroservicesAzurePythonRelational DatabasesSpring Boot
What you need to know about the Charlotte Tech Scene
Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.
Key Facts About Charlotte Tech
- Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
- Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
- Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
- Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

