Cloud Optimization Architect at APCO Holdings – Ponte Vedra, Florida
Explore Related Opportunities
About This Position
APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers.
Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve.
We are seeking a Cloud Optimization Architect to lead the financial and technical evolution of our Azure ecosystem. This is a senior-level technical role focused on the intersection of high-performance engineering and cloud financial accountability. You will be the primary architect responsible for ensuring our $1M+ annual Azure spend is optimized for maximum value through Infrastructure-as-Code (IaC), automated governance, and data-driven FinOps practices.
Cloud Financial Operations (FinOps) & Optimization
- Strategic Optimization: Lead the "Inform, Optimize, and Operate" phases of the FinOps lifecycle to maintain a lean cloud footprint.
- Commitment Management: Proactively manage the lifecycle of Azure Reservations and Savings Plans to maximize ROI and coverage.
- Data Visualization: Develop and maintain automated Power BI dashboards and "Showback/Chargeback" reports to provide stakeholders with granular visibility into spend.
- Governance & Guardrails: Implement and enforce Azure governance controls (Azure Policy, Tagging, Management Groups) to prevent cost leakage.
- Continuous Improvement: Lead monthly "Optimization Reviews" with application owners to identify and execute rightsizing opportunities for underutilized resources.
- Databricks Efficiency: Design and support Azure Databricks environments with a strict focus on cost-efficiency, implementing Auto-termination, Spot Instance policies, and Unity Catalog governance.
Infrastructure-as-Code (IaC) & Automation
- Architectural Standards: Build and maintain Azure reference architectures delivered exclusively via Terraform and/or Bicep.
- Shift-Left Costing: Integrate cost-estimation tools (e.g., Infracost) directly into CI/CD pipelines to provide visibility into the financial impact of code changes before deployment.
- Automated Remediation: Build automated workflows to detect and remediate "zombie" resources (unattached disks, idle Load Balancers, etc.).
- Scalable Networking: Architect secure, cost-optimized hybrid connectivity (VPN, ExpressRoute, VNet peering) and global DNS strategies.
Resiliency & Platform Support
- Cost-Effective DR: Design disaster recovery strategies (RTO/RPO) that balance business continuity with cost (e.g., Pilot Light vs. Multi-region Active/Active).
- Observability: Establish monitoring and logging standards using Azure Monitor and Log Analytics to track both performance and cost anomalies.
- 8+ years of experience in IT infrastructure or systems engineering.
- 5+ years of hands-on Azure architecture experience with a proven track record of managing spend at scale ($50k–$100k+/month).
- Expert-level proficiency in IaC: Extensive experience with Terraform (preferred) or Bicep in a production environment.
- Advanced Azure Billing Knowledge: Deep understanding of EA/MCA agreements, Azure Resource Graph (Kusto/KQL), and retail vs. negotiated rates.
- Data Platform Experience: Hands-on experience optimizing Azure Databricks, ADLS, and Entra ID integration.
Preferred certifications or equivalent hands-on experience across Azure DevOps, application development, networking, identity & access management, and hybrid infrastructure:
- FinOps Certified Practitioner (FOCP) – Highly Preferred
- AZ-305: Azure Solutions Architect Expert
- AZ-400: Azure DevOps Engineer Expert
- AZ-700: Azure Network Engineer Associate
- SC-300: Identity and Access Administrator Associate