
Posted 1 month ago
Sr. Network Engineer & Connectivity Architect
AI Summary
Senior Network Engineer and Connectivity Architect responsible for designing and operating a cloud-aligned, identity-driven network that spans Azure, on-prem, Meraki, and SaaS, leveraging IaC, Zero Trust, and advanced identity mechanisms to ensure secure, resilient connectivity.
About this role
APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers.
Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve.
The Sr. Network Engineer & Connectivity Architect serves as the principal architect of the organization’s enterprise connectivity platform (“The Backbone”), with a primary focus on Microsoft Azure networking, Cisco Meraki infrastructure, and identity-driven access (Active Directory & Entra ID).
This role is responsible for designing and operating a secure, highly resilient, and cloud-aligned network architecture, where access decisions are governed by user identity, device posture, and real-time risk signals, rather than traditional network boundaries.
Leveraging Infrastructure as Code (IaC), AIOps, and Zero Trust principles, this position ensures seamless, secure connectivity across Azure, on-prem environments, branch networks (Meraki), and SaaS platforms such as Microsoft 365, while enabling a scalable, automated, and self-healing infrastructure.
Key Responsibilities
Identity-Driven Network Architecture (CORE)
Design and implement a network architecture where identity is the primary control plane. Integrate Active Directory (on-prem), Entra ID, and identity providers (Okta) with network enforcement points to enable real-time, identity-based access decisions.
Active Directory & Hybrid Identity Ownership
Architect and support enterprise-scale hybrid identity environments, including:
Entra ID & Conditional Access Engineering
Design, implement, and optimize Conditional Access policies, including:
Zero Trust & Identity Enforcement
Lead the implementation of a Zero Trust architecture by aligning:
Ensure consistent enforcement of least privilege access across all environments.
Microsoft 365 Identity & Access Optimization
Ensure secure, high-performance access to Microsoft 365 by:
Azure-Centric Network Architecture
Design and implement scalable Azure networking solutions, including:
Meraki Network Design & Operations
Lead the design, deployment, and optimization of Cisco Meraki environments, including:
Hybrid Connectivity & Interconnects
Architect and manage secure connectivity between environments using:
Ensure low latency, high availability, and seamless failover.
Infrastructure as Code (IaC) & Automation
Manage network and cloud configurations as code using:
Ensure all deployments are standardized, repeatable, and auditable.
AI Ops & Observability
Implement monitoring and telemetry across Azure and Meraki using:
Enable proactive detection, anomaly identification, and automated remediation.
Resiliency & Business Continuity Engineering (CRITICAL)
Design and maintain a highly resilient network architecture across Azure, Meraki, on-prem, and SaaS environments:
Governance & Policy Enforcement
Establish and enforce governance using:
Ensure compliance with security, regulatory, and enterprise standards.
Technical Expertise
|
Category |
Requirements |
|
Identity & Access (PRIMARY) |
Deep expertise in Active Directory (architecture, GPOs, replication), Entra ID, Conditional Access, MFA, federation (SAML, OAuth, OIDC), hybrid identity |
|
Zero Trust Architecture |
Experience implementing identity-driven access integrating network, endpoint, and SaaS |
|
Azure Networking (PRIMARY) |
VNets, ExpressRoute, VPN Gateway, Azure Firewall, Private Link, DNS, Hub-Spoke design |
|
Meraki (PRIMARY) |
MX (SD-WAN), MS (switching), MR (wireless), Auto VPN, Meraki Dashboard |
|
Automation & IaC |
Terraform, Bicep, ARM templates, CI/CD pipelines |
|
M365 Integration |
Identity and network dependency across Exchange, Teams, SharePoint |
|
Endpoint Integration |
Intune/device compliance integration with access policies |
|
Observability |
Azure Monitor, Log Analytics, Meraki Dashboard, Dynatrace, Splunk |
|
Scripting & DevOps |
PowerShell, Python, or similar scripting experience |
Education and Experience
Required Experience
Preferred Experience