Actively recruiting / 6 applicants
We’re here to help you
Jane Cervantes is in direct contact with the company and can answer any questions you may have. Email
Jane Cervantes, RecruiterSummary
Onyx Graphics is seeking a hands-on, security-minded Cloud Infrastructure and Integration Engineer to build and operate the cloud foundation that connects our product portfolio. The primary responsibility of this role is implementing the cloud infrastructure, system integrations, data pipelines, and licensing connectivity that Onyx products and business systems depend on — built secure and user-centric by default. The role stands up cloud environments as version-controlled infrastructure code across our cloud estates, connects internal systems and external partner connection points, builds validated data pipelines, implements identity and access for the portfolio’s users and workloads, and serves as a named member of the first responder team for infrastructure and connectivity incidents. It works closely with the Director of Product & Engineering, the Enterprise Architect and senior engineers, the Engineering Systems Manager and QA, the IT Systems Engineer, and the revenue organization on partner connectivity.
- Build and maintain the portfolio’s cloud environments as version-controlled infrastructure code — networking, compute, storage, DNS, and environment separation across development, staging, and production — with security controls (encryption, logging, access baselines) built into the modules rather than applied afterward.
- Build the networking foundations the portfolio’s systems and connections run on: private networking, TLS, controlled ingress and egress, and cross-cloud connectivity.
- Build and operate the secure connections between internal systems — commerce, accounting, payments, support tooling, and product services — using authenticated service identities, encrypted transport, and managed secrets stores.
- Implement partner-facing connection points — authentication, rate limiting, payload validation, and logging — delivering working integrations in coordination with the revenue organization, which owns all external partner relationships.
- Implement and operate licensing connectivity across the portfolio: activation, entitlement, renewal, and revocation flows, including offline and grace-period behavior for environments with unreliable connectivity, built against the licensing architecture defined by the Enterprise Architect — including entitlement gating and usage metering for AI-backed product capabilities.
- Own the engineering work of operating across the mainland China network boundary: measure real cross-border performance and failure behavior, then implement resilient, degradation-tolerant connectivity for licensing and product traffic.
- Build and operate data pipelines between products, business systems, and reporting destinations, with validation as a pipeline stage — schema enforcement at boundaries, reconciliation against source-of-truth systems, and quarantine paths that surface failed records — and traceable lineage for licensing and financial data.
- Implement identity and access for users and workloads: OIDC/OAuth 2.0 flows, SSO integration, service credentials, token lifecycle, and least-privilege roles and permissions mapped to the portfolio’s customers, resellers, OEM partners, and internal teams, realizing the authorization model defined at the architecture level.
- Secure the AI surface of the portfolio and the engineering organization: manage credentials, access scopes, network egress, and logging for AI service connections — including chatbot and model-backed product features and AI-assisted development tooling (MCP servers, .claudeignore coverage) — and enforce data-boundary controls governing what information reaches external AI services, holding every AI connection to the same authenticated, least-privilege, observable standard as any other integration.
- Publish secure infrastructure patterns as reusable modules and templates so engineering teams inherit secure defaults, and weigh security decisions against user experience — documenting the trade-off rather than defaulting silently to either extreme.
- Ensure everything built is observable — emitting the logs, metrics, and alerts needed to diagnose failures — and covered by automated tests, consistent with Onyx’s test-first development standard.
- Partner with the Director, the Enterprise Architect, and senior engineers on design realization; with the Engineering Systems Manager and QA on CI quality gates and release evidence; and with the IT Systems Engineer on shared infrastructure-as-code practices.