About the Role
IMCO offers a stimulating and rewarding environment for career growth and organizational transformation. Our culture emphasizes collaboration and passion, with a commitment to delivering lasting value to clients. Our vision is to be the partner of choice for Ontario’s public sector funds, building a high-performing, value-driven asset management firm. This role offers the opportunity to do impactful work and broaden expertise by driving strategic outcomes.
Responsibilities
- Lead the technical design and implementation of Azure network architecture, including hub-and-spoke topology, connectivity to partners, regional redundancy, and cross-region connectivity, aligning with the broader cloud roadmap defined with the Cloud Architect Lead.
- Define and enforce network engineering standards, routing strategies, UDRs, route tables, NSGs, and hybrid connectivity frameworks to ensure consistent, secure, and audit-ready infrastructure provisioning.
- Design, deploy, and maintain Azure Front Door and related global traffic management solutions, including Web Application Firewall (WAF) policies, SSL/TLS termination, DDoS protection, and performance optimization, ensuring secure, highly available, and globally optimized access to IMCO’s cloud-native applications.
- Collaborate with and oversee managed service providers on Azure, Palo Alto/PRISMA and Meraki network operations, site-to-site VPNs, BGP peering, route optimizations, and security control implementations, ensuring technical alignment, service quality, and successful project execution while developing long-term operational readiness models.
- Drive end-to-end network initiatives from requirements gathering and architecture design through vendor coordination, build-out, testing, rollout, and operationalization.
- Evaluate existing network architecture through performance analysis, routing reviews, and connectivity assessments, identifying bottlenecks or vulnerabilities and proposing modernization strategies that improve cost, performance, and reliability.
- Produce and maintain comprehensive documentation, including network topology diagrams, routing specifications, operational procedures, and transition planning artifacts, to ensure clarity and maintainability of systems for current and future teams.
- Monitor industry trends, emerging networking technologies, and evolving regulatory requirements to ensure cloud network solutions remain compliant, secure, and aligned with IMCO’s long-term infrastructure goals.
Requirements
- A degree in Computer Science, Engineering, Network Technology, or a related technical field; equivalent combination of education and field experience will also be considered.
- Minimum of 7 years’ hands-on experience designing and implementing enterprise-scale Azure networking and hybrid connectivity solutions, with a proven track record of delivering secure, scalable, and compliant network architectures in highly regulated environments such as financial services.
- Extensive expertise in Azure Virtual Networks, hub-and-spoke topology, UDRs, route tables, regional peering, and cross-region redundancy, including the ability to design, implement, and optimize complex routing and security policies.
- Practical experience with Azure Front Door, WAF, global traffic routing, and cloud-native application delivery networks, with the ability to configure, monitor, and optimize these services for security, performance, and high availability across multi-region environments.
- Strong background in hybrid connectivity frameworks, site-to-site IPsec VPNs, BGP peering, and secure remote access architectures, with experience evaluating and planning infrastructure transitions or cloud-native modernization initiatives.
- Strong background in access layer switch management and enterprise switching architecture, including hands-on experience designing, deploying, and maintaining switch stacks across office and DR sites.
- Demonstrated ability to oversee managed service providers and vendor teams, ensuring technical alignment, service quality, and successful project execution while developing long-term operational readiness and transition pathways.
- Proficient with Azure Network Watcher, NSGs, private endpoints, and cloud-native monitoring and alerting, with the skills to leverage these tools for performance analysis, troubleshooting, and capacity modeling.
- Strong grasp of network security hardening, compliance remediation, and structured change management processes, with experience integrating security controls and monitoring into every stage of the network lifecycle.
- Proficient in producing and maintaining detailed technical documentation, including network topology diagrams, routing specifications, operational procedures, and comprehensive technical designs that support cross-functional teams and maintain clarity for future stakeholders.
- Proven experience collaborating with business and technical architects, fostering a culture of knowledge sharing, technical excellence, and adherence to best practices in cloud networking, security, and operational governance.
- Strong analytical and communication skills, with the ability to translate complex business and connectivity requirements into practical technical solutions and to influence both technical and non-technical audiences.
- Hands-on knowledge of cloud-native networking services, automation frameworks, and infrastructure-as-code methodologies, with the ability to integrate these tools to streamline network provisioning, validation, and operational support.
- Commitment to ongoing professional development, demonstrated by relevant certifications and a proactive approach to monitoring emerging networking technologies, industry trends, and evolving regulatory standards to ensure network solutions remain innovative and compliant.
- Candidates being considered for this position will be required to undergo background screening.
Skills
- Azure cloud networking
- Azure hybrid connectivity
- Azure resource configuration
- Azure network architecture
- Hub-and-spoke topology
- Azure Front Door
- Web Application Firewall (WAF)
- DDoS protection
- Palo Alto/PRISMA
- Meraki network operations
- Site-to-site VPNs
- BGP peering
- Access layer switch management
- Enterprise switching architecture
- VLANs
- STP/RSTP
- Link aggregation
- QoS
- Network segmentation
- Azure Network Watcher
- NSGs
- Private endpoints
- Network security hardening
- Cloud-native networking services
- Automation frameworks
- Infrastructure-as-code methodologies
Location
- Downtown Toronto
Work Type
- Hybrid
Experience Level
- Senior
- 7 years’ hands-on experience
Education Level
- Degree in Computer Science, Engineering, Network Technology, or a related technical field
- Equivalent combination of education and field experience
- Microsoft Certified: Azure Network Engineer Associate (AZ-700)
- Palo Alto PCNSE/PCNSA
- Relevant cloud and networking certifications
Salary/Compensations
- CAD $105,000.00 - $138,000.00
Benefits
- Annual incentive plan
- Comprehensive benefits package
- Defined benefit pension plan
About the Company
- IMCO is Ontario’s professional asset manager, investing on behalf of public sector clients to care for beneficiaries and secure retirement futures.
- With approximately $90.7 billion in assets under management, IMCO is one of the largest institutional investment managers in Canada and globally.
- IMCO's mandate is to provide broader public sector clients with exceptional investment management services, including best-in-class advice around portfolio construction, efficient access to a diverse range of asset classes and superior reporting on risks and returns.
- IMCO's vision is to rank among the world’s leading public-sector asset managers by focusing on creating client value and delivering the returns required for clients to meet their long-term financial obligations.
Equal Opportunity
- IMCO is committed to providing accommodation for people with disabilities throughout the recruitment process. If you require support, please let us know and we will work with you to meet your needs.
