Back to jobs
tags.new

Cloud & Infrastructure Engineer

Lehi, Utah, United States

MX is a fintech company on a mission to empower the world to be financially strong. We build technology that helps banks, credit unions, and fintechs deliver smarter, more intuitive financial experiences to millions of people.

Like many startups, we’ve navigated real growth challenges — and we’ve come out stronger on the other side. Today, MX is in a phase of renewed momentum and scale, with a solid foundation and a clear vision for what’s next. This is a place where thoughtful execution matters, innovation is encouraged, and individuals have real ownership over their work.

Our culture values curiosity, accountability, and impact. We give people the space to question assumptions, design better solutions, and help shape how the company grows. If you’re looking to do meaningful work, influence outcomes, and grow alongside a company that’s ready to move fast, you’ll feel at home at MX.

MX is seeking a Cloud & Infrastructure Engineer to join the new Enterprise Engineering team. Enterprise Engineering builds the paved road for how MX builds: self-serve tooling, shared standards, and guardrails that let any MXer go from an idea to a governed internal app, automation, or agent quickly and safely.

You'll own the foundation that road runs on: the Enterprise GCP Environment, the network and connectivity behind it, the identity and security controls that keep it safe, and the reliability practices that keep it running. You'll also partner with IT Operations to maintain inter-app integrations and MX's office networks. 

You'll partner closely with the team's Senior Enterprise Engineer, who builds the pipeline, registries, and integrations on top of your platform, and you'll work under Cloud Infrastructure's controls so the platform uses the same control spine as Engineering, scaled to risk.

Job Duties:

GCP Platform & Runtime

  • Build and operate the Enterprise GCP Environment with a predictable, automated CI/CD path to production, working under Cloud Infrastructure's controls and oversight (dotted line).
  • Own and maintain the curated GCP role catalog and org policy guardrails that make the compliant path the easy path.
  • Manage the platform as infrastructure-as-code (Terraform), including self-serve, disposable dev environments that builders can spin up safely.
  • Support the migration of the team's existing sharing and registry tools into the Enterprise GCP Environment as its first tenants, working alongside the Senior Enterprise Engineer.

Network & Connectivity

  • Design and operate the platform's network architecture: VPCs, network zones, private service connectivity, load balancing, DNS automation, and egress and data-exfiltration controls.
  • Partner with IT Operations to maintain MX's office networks, including firewalls, VPN or zero-trust network access, and secure connectivity between office networks and cloud environments, with Information Security on controls.
  • Partner with IT Operations to maintain inter-app integrations between MX's enterprise systems and the Enterprise GCP Environment, including the network, identity, and connectivity they depend on.
  • Maintain current network diagrams, standards, and change records, and lead network changes through MX's change management process.

Identity & Security Controls

  • Implement and maintain identity and auth patterns (Okta/IAP) for the platform's runtime and self-serve dev environments, including service account and workload identity hygiene and least-privilege access.
  • Integrate code and agent scanning (e.g., Snyk) into the CI/CD pipeline with the Senior Enterprise Engineer, and keep it current as threats and tooling evolve.
  • Partner with Security and Compliance on SOC 2 / PCI audit evidence for the platform's and network's controls.

Reliability, Operations & Cost

  • Establish and run reliability practices for the platform and the AI workloads on it: monitoring, alerting, runbooks, incident response, and post-incident reviews.
  • Coordinate escalation and after-hours coverage with Cloud Infrastructure for business-critical workloads.
  • Implement app support tiers and ownership metadata so tools that become business-critical can graduate to a real owner with a real SDLC.
  • Own cost attribution, tagging, and budget alerts for the platform, and support vendor and budget governance for cloud and AI/inference spend.

Cross-Functional Partnership

  • Partner closely with Cloud Infrastructure to operate under its controls and oversight rather than around them.
  • Partner with IT Operations on shared infrastructure, office networks, and inter-app integrations, with clear ownership and escalation between the teams.
  • Partner with the Senior Enterprise Engineer and system owners to make sure the platform's guardrails work for real builders, not just on paper.
  • Maintain architecture diagrams, runbooks, and documentation for the platform and network the team owns.

Basic Requirements

  • Education: Bachelor's degree in Computer Science, Information Technology, or related field, or equivalent practical experience.
  • Experience: 6-8+ years in cloud, network, or infrastructure engineering, with production experience on GCP (or AWS/Azure with strong GCP aptitude and willingness to ramp quickly).
  • Technical Proficiency:
    • Deep hands-on experience with GCP (IAM, VPC networking, org policy, Cloud Run, GKE, or equivalent compute), or an equivalent hyperscaler with fast GCP ramp-up.
    • Strong network engineering fundamentals: TCP/IP, routing, DNS, load balancing, firewalls, VPN or zero-trust network access, and hybrid cloud connectivity.
    • Infrastructure-as-code (Terraform strongly preferred) and CI/CD for infrastructure (GitLab CI, GitHub Actions, or similar).
    • Identity and auth implementation (Okta, IAP, SSO/SAML/OAuth/OIDC, workload identity).
    • Reliability practices: monitoring, alerting, incident response, and runbooks.
    • Scripting and automation (Python, Bash, or Go).
    • Security fundamentals: least-privilege access, data-exfiltration controls, code and dependency scanning; familiarity with SOC 2 Type II and PCI controls.
  • Soft Skills: Strong communication and collaboration skills; comfortable partnering directly with Cloud Infrastructure, Information Security, IT Operations, and builders across the business; documents systems clearly for a mixed-technical audience.

Advanced Requirements

  • Cloud or network certifications (e.g., Google Professional Cloud Architect or Professional Cloud Network Engineer) are a plus.
  • Experience running platforms for AI workloads (e.g., Vertex AI, inference endpoints, AI gateways) is a plus.
  • Please be prepared to walk through a network or platform design you built and the trade-offs you made, and a production incident you resolved.

MX is proudly committed to recruiting and retaining a diverse and inclusive workforce. As an Equal Opportunity Employer, we never discriminate based on race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, military or veteran status, status as an individual with a disability, or other applicable legally protected characteristics. We particularly welcome applications from veterans and military spouses. All your information will be kept confidential according to EEO guidelines. You may request reasonable accommodations by sending an email to hr@mx.com.

Create a Job Alert

Interested in building your career at MX Technologies, Inc.? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in MX Technologies, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...