Description
AlterG Resources
Job Description
Platform Engineer
Department:
Data and Technology
Location:
Anywhere in the United States; on site one week a month (Salt Lake City, Philadelphia, or project sites).
Relocation support offered for those who prefer to be on site more often.
Reports To:
SVP, Data Science and Optimization
Employment Type:
Full-time - Exempt
Team:
Data and Technology
“Powering the future with endless potential.”
AlterG Resources is developing next-generation geothermal to deliver reliable, carbon-free baseload power.
Our mission is to unlock geothermal resources at scale through innovative drilling, reservoir engineering, and power generation technologies.
As a rapidly growing company, we are building a world-class team dedicated to transforming the future of clean energy.
About the Role
The Data and Technology team builds the data, the models, and the tools every part of the business runs on — much of it with no precedent in geothermal.
As one of the team’s first engineering hires, you will own the platform everything ships on: identity, deploys, infrastructure, and cost.
You embed with two forward-deployed engineers who work directly with geoscience, reservoir, operations, land, and finance, and you own the deploy, secure, and operate path that turns their work into running product.
This is a senior, hands-on engineering role.
Today the platform is owned by the SVP alongside everything else the function does; this role makes it someone’s actual job.
You decide what good looks like on that platform and build it.
You work in the room with the team, and your job is to engineer routine administration out of everyone’s week, including your own, so the team spends its time building.
You will report to our SVP, Data Science and Optimization, a hands-on petroleum engineer who has led teams across reservoir, geology, drilling, completions, and production, and who worked as a deployment engineer at an enterprise software company.
The SVP also works as a forward-deployed engineer on this team.
Because this role carries broad access to the systems behind the investment decisions, reserves, and investor reporting, AlterG runs reference and background checks, and the SVP reviews access changes so that no one, including the platform owner, is the only reviewer of their own permissions.
Key Responsibilities
Identity, Access, and the Control Plane
●Design and own service principal and OIDC federated identity: the trust relationships, scopes, and token flows between Azure, GitHub Actions, and Databricks.
●Define role-based access control across Unity Catalog, storage, applications, and repositories, as version-controlled code rather than portal configuration.
●Own secret and token lifecycle, including scheduled rotation and the automation that keeps an expiring credential from becoming an outage.
●Own the MCP server’s authorization model, including its Azure AD on-behalf-of token exchange, so every tool call runs with the calling user’s own Unity Catalog and SharePoint permissions.
This is the most consequential thing you own: if its scope or token handling is wrong, one user can see another user’s data with no error to notice.
●Run access governance as a standing practice: periodic review, least-privilege enforcement, and a documented joiner, mover, and leaver process.
Deploys and Infrastructure
●Own production deploys for Databricks Asset Bundles, Azure App Services, and the MCP server.
●Build infrastructure as code (Terraform or Bicep) for everything inside AlterG’s boundary, including configuration of provider-provisioned resources.
●Administer the GitHub organization: branch protection, required checks, code owners, Actions policy, runners, and org-level secrets.
●Design the CI/CD pipeline and the engineering standards built on it.
The Paved Road
●Build self-service environments and deploy paths so engineers can ship without waiting on the platform owner.
●Deliver fast, trustworthy feedback: preview environments, meaningful checks, and short build times.
●Design guardrails as defaults rather than gates, so the safe path is also the easy one.
●Own monitoring, alerting, and application instrumentation.
●Own cloud cost visibility and control, including Databricks compute cost and cluster policy.
●Build runbooks and incident response so operational knowledge lives in systems, not individuals.
Scope
You own the access control plane and platform for the engineering estate: Databricks and Unity Catalog, the GitHub organization, our applications, and the MCP server.
You do not own the Microsoft tenant, Entra directory, corporate credentials, licensing, end-user support, or the VM estate behind our directory, geospatial, and BI servers, which our managed service provider runs with our input.
The Platform Today
The platform on Databricks and Azure: a two-layer lakehouse (raw to curated), production web applications on Azure App Service, and a remote MCP server, also an App Service, which is how most people at AlterG reach the platform, primarily through Claude.
The estate is small in headcount, but broad in surface area, spanning multiple repositories, CI/CD workflows, ingestion pipelines, and production applications.
Databricks is declaratively managed through Asset Bundles and validated in CI.
Early work includes standardizing secret handling, bringing Azure under code, and extending instrumentation across all applications.
Together these are the largest net-new build in the role, and you choose the tools.
What you build must hold as field and sensor data and operations-critical workloads come onto the platform.
Working With Our Provider
Our managed service provider provisions Azure resources and administers the Microsoft account, and that arrangement is not changing.
What has been missing is an engineering owner at the boundary who understands both sides well enough to negotiate changes rather than route around them.
This is not a ticket-relay job.
If your week goes into passing requests between our engineers and the provider, the role has been scoped wrong.
The job is to engineer the boundary until it needs you less: establish in writing what our team can safely self-serve, automate provisioning within our boundary, and make the few requests that genuinely require the provider fast and precise.
Over time, shipping a change should require fewer handoffs, not more.
Qualifications
We assess experience by what you have built and operated, not by title or years.
Mistakes in identity, secrets, and production deploys are hard to recover from, and the judgment that prevents them usually comes from having lived through them.
Required:
●Experience building infrastructure as code from scratch and living with it afterward.
●Experience designing federated identity and token flows: service principals, scopes, delegated authorization (e.g., OAuth on-behalf-of), and scheduled secret rotation.
Azure preferred; depth from AWS or GCP transfers.
●Experience designing a CI/CD system, not just maintaining one.
●Experience governing a data platform’s access model, in Unity Catalog or a comparable system.
●Sound judgment about what to codify first rather than taking everything on at once.
●Experience building with coding agents, with rigor about what is accept from them.
●A track record of holding a technical line with fast-moving engineers by making the safer option the easier one.
●Experience working productively across a managed service provider or shared platform boundary.
Preferred:
●Azure: App Service, Key Vault, VNet and private endpoints, and Entra ID.
●Databricks platform administration and Asset Bundles.
●GitHub organization administration at scale, beyond repository-level work.
●Small-company or early-platform experience setting standards rather than inheriting them.
●Cost management on a growing cloud footprint.
●Security or compliance work in a regulated or investor-facing environment.
●Developer experience or internal platform work with named internal users.
Logistics
This role is remote based anywhere in the United States, with a required on-site week each month.
The team collocates at our Salt Lake City or Philadelphia office or at an active project site for scoping, problem breakdown, and paired builds.
Travel may run heavier during onboarding or a major build phase and is company-paid.
As field offices come online, the people working from them will depend on this platform, and you will spend time where they are.
Relocation support is available if you would like to be on site more often, but it is not required.
There is no on-call rotation today.
Pipelines are scheduled batch jobs and applications are internal tools used during business hours, so failures outside those hours are picked up the next working morning; Azure and tenant incidents follow our provider’s escalation path.
For a short list of dates, such as investor presentations, board meetings and regulatory deadlines, someone is on point by prior arrangement.
As the platform grows, you will design the on-call model it needs.
Interested in joining our team? Send resumes and questions to careers@altergresources.com.
To Third-Party Recruiters and Staffing Agencies: AlterG Resources LLC has an internal talent acquisition team and does not accept unsolicited candidate submissions from recruitment agencies, search firms, or staffing companies.
Any resume or candidate profile submitted to AlterG Resources or its employees without a prior written agreement executed by an authorized AlterG Resources representative will be considered unsolicited and the property of AlterG Resources.
AlterG Resources will not pay any placement fee in connection with such submissions.
Agencies are asked not to contact AlterG Resources hiring managers or employees directly.
Recruiting agency relationships are managed exclusively through AlterG’s Human Resources/Talent Acquisition department.