Sr. Network Engineer & Connectivity Architect
Listed on 2026-05-25
-
IT/Tech
Systems Engineer, Cybersecurity, Network Engineer, Network Security
Overview
APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers. Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve.
The Sr. Network Engineer & Connectivity Architect serves as the principal architect of the organization’s enterprise connectivity platform (The Backbone), with a primary focus on Microsoft Azure networking, Cisco Meraki infrastructure, and identity-driven access (Active Directory & Entra ).
This role is responsible for designing and operating a secure, highly resilient, and cloud-aligned network architecture, where access decisions are governed by user identity, device posture, and real-time risk signals, rather than traditional network boundaries. Leveraging Infrastructure as Code (IaC), AIOps, and Zero Trust principles, this position ensures seamless, secure connectivity across Azure, on-prem environments, branch networks (Meraki), and SaaS platforms such as Microsoft 365, while enabling a scalable, automated, and self-healing infrastructure.
Key Responsibilities- Identity-Driven Network Architecture (CORE)
Design and implement a network architecture where identity is the primary control plane. Integrate Active Directory (on-prem), Entra , and identity providers (Okta) with network enforcement points to enable real-time, identity-based access decisions. - Active Directory & Hybrid Identity Ownership
Architect and support enterprise-scale hybrid identity environments, including: - Active Directory design (sites, replication, GPO strategy)
- Entra Connect (Azure AD Connect) synchronization
- Authentication protocols (Kerberos, NTLM, modern authentication)
- Secure integration with cloud and network services
- Entra & Conditional Access Engineering
Design, implement, and optimize Conditional Access policies, including: - MFA enforcement strategies
- Device compliance (Intune integration)
- Risk-based and session-based access controls
- Location-aware and Zero Trust access models
- Zero Trust & Identity Enforcement
Lead the implementation of a Zero Trust architecture by aligning: - Identity (Entra / Active Directory / Okta)
- Network (Azure, Meraki)
- Endpoint (Intune / device posture)
- Ensure consistent enforcement of least privilege access across all environments.
- Microsoft 365 Identity & Access Optimization
Ensure secure, high-performance access to Microsoft 365 by: - Aligning identity policies with network routing and access controls
- Supporting modern authentication flows and token-based access
- Optimizing Teams, Exchange, and SharePoint connectivity
- Azure-Centric Network Architecture
Design and implement scalable Azure networking solutions, including: - Virtual Networks (VNet) and Hub-and-Spoke architectures
- Private Endpoints and Private Link
- Azure Firewall, NSGs, and routing strategies
- DNS architecture and name resolution
- Meraki Network Design & Operations
Lead the design, deployment, and optimization of Cisco Meraki environments, including: - MX (SD-WAN & security appliances)
- MS (switching)
- MR (wireless)
- Auto VPN and centralized cloud-based management
- Hybrid Connectivity & Interconnects
Architect and manage secure connectivity between environments using: - Express Route
- VPN Gateways
- Meraki SD-WAN (Auto VPN)
- Ensure low latency, high availability, and seamless failover.
- Infrastructure as Code (IaC) & Automation
Manage network and cloud configurations as code using: - Terraform, Bicep, or ARM templates
- CI/CD pipelines (Azure Dev Ops, Git Hub Actions)
- Ensure all deployments are standardized, repeatable, and auditable.
- AI Ops & Observability
Implement monitoring and telemetry across Azure and Meraki using: - Azure Monitor & Log Analytics
- Meraki Dashboard
- Observability tools (Dynatrace, Splunk, etc.)
- Enable proactive detection, anomaly…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).