Sr. Network Engineer & Connectivity Architect

APCO Holdings, LLC

Ponte Vedra Beach (FL)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

APCO Holdings, LLC seeks a Sr. Network Engineer & Connectivity Architect in Ponte Vedra Beach, FL to design and operate its enterprise connectivity platform. Responsibilities include creating identity-driven network architectures using Microsoft Azure and Cisco Meraki, and implementing Zero Trust principles. Candidates need extensive experience in Active Directory and Azure networking. Benefits include a collaborative environment focusing on innovative vehicle protection solutions.

Qualifications

  • 8-10+ years of enterprise networking experience required.
  • 5+ years of Active Directory experience at an enterprise scale.
  • 3+ years of experience with Azure networking and Cisco Meraki.

Responsibilities

  • Design and implement a network architecture where identity is the primary control plane.
  • Lead implementation of Zero Trust architecture supporting identity-driven policies.
  • Manage network and cloud configurations as code using IaC tools.

Skills

Active Directory
Zero Trust Architecture
Azure Networking
Cisco Meraki
Infrastructure as Code (IaC)
AIOps
Microsoft 365 optimization

Education

Bachelor’s degree in Computer Science or related field
Master’s degree in Information Systems Management

Tools

Terraform
Azure DevOps
Meraki Dashboard
Azure Monitor

Job description

APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers.

Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve.

The Sr. Network Engineer & Connectivity Architect serves as the principal architect of the organization’s enterprise connectivity platform (“The Backbone”), with a primary focus on Microsoft Azure networking, Cisco Meraki infrastructure, and identity-driven access (Active Directory & Entra ID).

This role is responsible for designing and operating a secure, highly resilient, and cloud-aligned network architecture, where access decisions are governed by user identity, device posture, and real-time risk signals, rather than traditional network boundaries.

Leveraging Infrastructure as Code (IaC), AIOps, and Zero Trust principles, this position ensures seamless, secure connectivity across Azure, on-prem environments, branch networks (Meraki), and SaaS platforms such as Microsoft 365, while enabling a scalable, automated, and self-healing infrastructure.

Key Responsibilities
Identity-Driven Network Architecture (CORE)

Design and implement a network architecture where identity is the primary control plane. Integrate Active Directory (on-prem), Entra ID, and identity providers (Okta) with network enforcement points to enable real-time, identity-based access decisions.

Active Directory & Hybrid Identity Ownership
Architect And Support Enterprise-scale Hybrid Identity Environments, Including
  • Active Directory design (sites, replication, GPO strategy)
  • Entra Connect (Azure AD Connect) synchronization
  • Authentication protocols (Kerberos, NTLM, modern authentication)
  • Secure integration with cloud and network services
Entra ID & Conditional Access Engineering
Design, Implement, And Optimize Conditional Access Policies, Including
  • MFA enforcement strategies
  • Device compliance (Intune integration)
  • Risk-based and session-based access controls
  • Location-aware and Zero Trust access models
Zero Trust & Identity Enforcement

Lead the implementation of a Zero Trust architecture by aligning:

  • Identity (Entra ID / Active Directory / Okta)
  • Network (Azure, Meraki)
  • Endpoint (Intune / device posture)

Ensure consistent enforcement of least privilege access across all environments.

Microsoft 365 Identity & Access Optimization
Ensure Secure, High-performance Access To Microsoft 365 By
  • Aligning identity policies with network routing and access controls
  • Supporting modern authentication flows and token-based access
  • Optimizing Teams, Exchange, and SharePoint connectivity
Azure-Centric Network Architecture
Design And Implement Scalable Azure Networking Solutions, Including
  • Virtual Networks (VNet) and Hub-and-Spoke architectures
  • Private Endpoints and Private Link
  • Azure Firewall, NSGs, and routing strategies
  • DNS architecture and name resolution
Meraki Network Design & Operations

Lead the design, deployment, and optimization of Cisco Meraki environments, including:

  • MX (SD-WAN & security appliances)
  • MS (switching)
  • MR (wireless)
  • Auto VPN and centralized cloud-based management
Hybrid Connectivity & Interconnects
Architect And Manage Secure Connectivity Between Environments Using
  • ExpressRoute
  • VPN Gateways
  • Meraki SD-WAN (Auto VPN)

Ensure low latency, high availability, and seamless failover.

Infrastructure as Code (IaC) & Automation
Manage Network And Cloud Configurations As Code Using
  • Terraform, Bicep, or ARM templates
  • CI/CD pipelines (Azure DevOps, GitHub Actions)

Ensure all deployments are standardized, repeatable, and auditable.

AI Ops & Observability
Implement Monitoring And Telemetry Across Azure And Meraki Using
  • Azure Monitor & Log Analytics
  • Meraki Dashboard
  • Observability tools (Dynatrace, Splunk, etc.)

Enable proactive detection, anomaly identification, and automated remediation.

Resiliency & Business Continuity Engineering (CRITICAL)

Design and maintain a highly resilient network architecture across Azure, Meraki, on-prem, and SaaS environments:

  • Eliminate single points of failure
  • Implement redundancy across WAN, LAN, wireless, and cloud
  • Design for automated failover and rapid recovery
  • Ensure identity-dependent services remain available during outages
Governance & Policy Enforcement
Establish And Enforce Governance Using
  • Azure Policy and tagging standards
  • Policy-as-Code frameworks
  • Identity governance (access reviews, RBAC, least privilege)

Ensure compliance with security, regulatory, and enterprise standards.

Technical Expertise
Requirements
Identity & Access (PRIMARY)

Deep expertise in Active Directory (architecture, GPOs, replication), Entra ID, Conditional Access, MFA, federation (SAML, OAuth, OIDC), hybrid identity.

Zero Trust Architecture
Azure Networking (PRIMARY)

Experience implementing identity-driven access integrating network, endpoint, and SaaS.

VNets, ExpressRoute, VPN Gateway, Azure Firewall, Private Link, DNS, Hub-Spoke design.

Meraki (PRIMARY)

MX (SD-WAN), MS (switching), MR (wireless), Auto VPN, Meraki Dashboard.

Automation & IaC

Terraform, Bicep, ARM templates, CI/CD pipelines.

M365 Integration

Identity and network dependency across Exchange, Teams, SharePoint.

Endpoint Integration

Intune/device compliance integration with access policies.

Observability

Azure Monitor, Log Analytics, Meraki Dashboard, Dynatrace, Splunk.

Scripting & DevOps

PowerShell, Python, Or Similar Scripting Experience.

Education and Experience
  • Bachelor’s degree in Computer Science, Information Technology, or a related technical field; Master’s degree in Information Systems Management preferred.
  • In lieu of a degree, 12+ years of enterprise-level infrastructure experience with a proven track record of delivering automation-first networking projects.
Required Experience
  • 8-10+ years of enterprise networking experience
  • 5+ years of Active Directory experience (enterprise scale)
  • 3+ years of Entra ID (Azure AD), Conditional Access, and MFA
  • 3+ years of Azure networking experience
  • 3+ years of Cisco Meraki experience (SD-WAN, switching, wireless)
  • Experience designing hybrid connectivity (ExpressRoute, VPN, SD-WAN)
  • Experience implementing IaC (Terraform, Bicep, ARM)
  • Experience integrating identity with network and Zero Trust frameworks
  • Proven experience leading a transition from legacy "box-by-box" management to a centralized, API-driven orchestration model.
Preferred Experience
  • Microsoft 365 performance and connectivity optimization.
Certifications (Preferred)
  • Microsoft Certified: Azure Network Engineer Associate (AZ-700)
  • Microsoft Certified: Identity and Access Administrator (SC-300)
  • Microsoft Certified: Azure Solutions Architect Expert
  • Cisco Meraki Solutions Specialist (CMSS)
  • Cisco Certified Internetwork Expert (CCIE) or CCNP Enterprise
  • Cisco Certified DevNet Professional
  • Hashi Corp Certified: Terraform Associate
  • Certified Kubernetes Administrator (CKA)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Network Engineer & Connectivity Architect
Sr. Network Engineer & Connectivity Architect

APCO Holdings • Norcross (GA)

On-site
USD 100,000 - 140,000
Azure Network Architect
Azure Network Architect

FTS, Inc. • Atlanta (GA)

On-site
USD 130,000 - 160,000
Lead Network Cloud EngineerSME
Lead Network Cloud EngineerSME

IQUASAR LLC • Washington

On-site
USD 120,000 - 150,000
401(k) matching
Dental insurance
Health insurance
+1
Senior Network Engineer – Azure (W2)
Senior Network Engineer – Azure (W2)

Snowrelic Inc • Washington

Hybrid
USD 120,000 - 150,000
Lead Network Engineer
Lead Network Engineer

Jobtailor • Madison (WI)

On-site
USD 120,000 - 160,000
Senior Network Engineer – Hybrid Cloud & Azure Security (W2)
Senior Network Engineer – Hybrid Cloud & Azure Security (W2)

Snowrelic Inc • United States

Hybrid
USD 100,000 - 130,000
Identity-Driven Network Architect (Azure & Meraki)
Identity-Driven Network Architect (Azure & Meraki)

APCO Holdings • Norcross (GA)

On-site
USD 100,000 - 140,000
Network Engineer/Architect
Network Engineer/Architect

PlanIT Group • Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Network Security Engineer
Senior Network Security Engineer

Liquid Environmental Solutions • Irving (TX)

On-site
USD 120,000 - 150,000
Sr. Network Architect
Sr. Network Architect

Piper Companies • Frederick (MD)

Hybrid
USD 128,000 - 170,000
PTO
Paid Holidays
Medical
+4