Identity-Driven Network Architecture (CORE)
Design and implement a network architecture where identity is the primary control plane. Integrate Active Directory (on-prem), Entra ID, and identity providers (Okta) with network enforcement points to enable real-time, identity-based access decisions.
Active Directory & Hybrid Identity Ownership
•
Architect and support enterprise-scale hybrid identity environments, including:
•
Active Directory design (sites, replication, GPO strategy)
•
Entra Connect (Azure AD Connect) synchronization
•
Authentication protocols (Kerberos, NTLM, modern authentication)
•
Secure integration with cloud and network services
Entra ID & Conditional Access Engineering
•
Design, implement, and optimize Conditional Access policies, including:
•
MFA enforcement strategies
•
Device compliance (Intune integration)
•
Risk-based and session-based access controls
•
Location-aware and Zero Trust access models
Zero Trust & Identity Enforcement
•
Lead the implementation of a Zero Trust architecture by aligning:
•
Identity (Entra ID / Active Directory / Okta)
•
Endpoint (Intune / device posture)
•
Ensure consistent enforcement of least privilege access across all environments
Microsoft 365 Identity & Access Optimization
•
Ensure secure, high-performance access to Microsoft 365 by:
•
Aligning identity policies with network routing and access controls
•
Supporting modern authentication flows and token-based access
•
Optimizing Teams, Exchange, and SharePoint connectivity
Azure-Centric Network Architecture
•
Design and implement scalable Azure networking solutions, including:
•
Virtual Networks (VNet) and Hub-and-Spoke architectures
•
Private Endpoints and Private Link
•
Azure Firewall, NSGs, and routing strategies
•
DNS architecture and name resolution
Meraki Network Design & Operations
•
Lead the design, deployment, and optimization of Cisco Meraki environments, including:
•
MX (SD-WAN & security appliances)
•
Auto VPN and centralized cloud-based management
Hybrid Connectivity & Interconnects
•
Architect and manage secure connectivity between environments using:
•
Ensure low latency, high availability, and seamless failover.
Infrastructure as Code (IaC) & Automation
•
Manage network and cloud configurations as code using:
•
Terraform, Bicep, or ARM templates
•
CI/CD pipelines (Azure DevOps, GitHub Actions)
•
Ensure all deployments are standardized, repeatable, and auditable.
•
Implement monitoring and telemetry across Azure and Meraki using:
•
Azure Monitor & Log Analytics
•
Observability tools (Dynatrace, Splunk, etc.)
•
Enable proactive detection, anomaly identification, and automated remediation.
Resiliency & Buiness Continuity Engineering (CRITICAL)
•
Design and maintain a highly resilient network architecture across Azure, Meraki, on-prem, and SaaS environments:
•
Eliminate single points of failure
•
Implement redundancy across WAN, LAN, wireless, and cloud
•
Design for automated failover and rapid recovery
•
Ensure identity-dependent services remain available during outages
Governance & Policy Enforcement
•
Establish and enforce governance using:
•
Azure Policy and tagging standards
•
Policy-as-Code frameworks
•
Identity governance (access reviews, RBAC, least privilege)
•
Ensure compliance with security, regulatory, and enterprise standards.