Job Summary
|
Role title |
AOVPN Engineer / Consultant |
Function |
Connectivity / Network Services |
|
Experience |
5-8+ years |
Employment type |
Full-time |
|
Location |
Hybrid / Remote |
Support model |
Business hours with on-call support |
|
Reporting to |
Connectivity Service Lead / SDM |
Role level |
L2 / L3 Technical Specialist |
Role purpose
The AOVPN Engineer / Consultant is responsible for the engineering, operation, availability, security and continual improvement of Microsoft Always On VPN services. The role provides L2/L3 support across VPN gateways, Network Policy Server (NPS), Remote Access Service (RAS), Windows Network Load Balancing, certificates, VPN profiles and traffic-routing components, while coordinating closely with Intune, PKI, Wintel, network, firewall and service-management teams.
Key outcomes
- Stable and secure remote connectivity with proactive monitoring and timely incident restoration.
- Controlled AOVPN profile, certificate, policy and infrastructure changes with tested rollback plans.
- Current operational, recovery and configuration documentation that supports audit and disaster-recovery readiness.
Clear ownership, escalation and communication across internal teams, vendors and business stakeholder
Key Responsibilities
Key responsibilities
Service operations and support
- Monitor and administer VPN/RAS servers, NPS servers, Windows NLB clusters, Azure Traffic Manager endpoints and associated service health indicators.
- Troubleshoot user, device and site connectivity issues involving authentication, certificates, routing, DNS, split tunnelling, firewall flows and VPN profile behaviour.
- Own technical resolution of incidents, service requests, problems and changes, including accurate ticket updates, evidence, timelines and closure notes.
- Perform approved service restarts, server maintenance, patch coordination, endpoint enablement or disablement, and controlled traffic failover or switchback.
- Participate in an on-call or major-incident rota and provide technical leadership during priority incidents.
Engineering and lifecycle management
- Design, build, test and maintain AOVPN user and device tunnel configurations using ProfileXML and approved deployment methods.
- Configure and support RAS/VPN, NPS/RADIUS policies, IKEv2/SSTP settings, IP addressing, routes, DNS rules and traffic filters.
- Coordinate VPN profile deployment and removal through Microsoft Intune, ensuring pilot validation, sequencing, dependency checks and user-impact controls.
- Plan certificate enrolment, renewal and revocation activities with PKI teams for server, user, device and external-facing certificates.
- Support service transitions, platform upgrades, data-centre changes, tenant migrations, decommissioning and replacement of legacy VPN infrastructure.
- Engage Microsoft and other vendors for product defects, complex troubleshooting and technical escalation.
Availability, recovery and security
- Maintain disaster-recovery and blackout-recovery procedures covering backup, restore, rebuild, failover, rollback, validation, ownership and communication.
- Execute periodic recovery and traffic-switchover tests, capture evidence, record lessons learned and drive corrective actions.
- Validate configuration backups for VPN/NPS servers and AOVPN XML profiles, and confirm dependencies such as PKI, Intune, DNS, network, firewall and internet connectivity.
- Apply security hardening, least-privilege access, certificate controls, logging and vulnerability-remediation requirements in line with organisational standards.
- Assess service risks, document technical debt, maintain remediation plans and escalate material availability or security concerns.
Skill Requirements
Required technical skills
|
Capability |
Expected proficiency |
|
Core AOVPN |
Hands-on administration and troubleshooting of Microsoft Always On VPN, RAS/RRAS, NPS/RADIUS, user tunnel, device tunnel and ProfileXML. |
|
Windows platform |
Strong Windows Server and Windows 10/11 knowledge, including services, networking, event logs, PowerShell and Group Policy. |
|
Identity and certificates |
Practical knowledge of Active Directory, Microsoft Entra ID, enterprise PKI, certificate templates, auto-enrolment, CRL/OCSP and certificate-based authentication. |
|
Endpoint management |
Experience deploying and troubleshooting VPN profiles and certificates through Microsoft Intune or equivalent endpoint-management tooling. |
|
Network technologies |
Sound knowledge of TCP/IP, DNS, DHCP, routing, NAT, IPsec/IKEv2, SSTP, TLS, firewalls, proxies, load balancing and split/full-tunnel designs. |
|
Cloud and resilience |
Working knowledge of Azure Traffic Manager or equivalent traffic-routing services, high-availability patterns, backup/recovery and disaster-recovery testing. |
|
Service management |
Experience with ITIL-based incident, problem, change, request, knowledge and major-incident management processes. |
Qualifications and experience
- Bachelor's degree or equivalent practical experience in information technology, computer science, engineering or a related field.
- 5-8+ years of experience in enterprise network, remote-access or Windows infrastructure support, including substantial hands-on AOVPN experience.
- Proven experience supporting production services across multiple sites or regions and working within structured change and incident-management controls.
- Microsoft, networking, cloud, security or IT service-management certifications are desirable.
Behavioural competencies
- Strong analytical troubleshooting and root-cause thinking.
- Clear, concise stakeholder communication during incidents and planned changes.
- Ownership mindset with disciplined follow-through and attention to documentation.
- Ability to coordinate effectively across PKI, Intune, Wintel, network, security, vendor and service-management teams.
- Risk-aware decision-making and a continuous-improvement approach.
Other Requirements
Performance measures
- Service availability and reliability against agreed targets.
- Incident response and resolution performance, including reduction in repeat incidents.
- Change success rate and quality of implementation and rollback evidence.
- Certificate, profile and infrastructure lifecycle activities completed before expiry or obsolescence.
- Recovery-test success, closure of findings and currency of runbooks and configuration records.
- Stakeholder satisfaction, ticket hygiene and delivery of measurable automation or service improvements.