Sr. Network Engineer

Esrtreit

New York (NY)

Hybrid

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, Dental, Vision insurance
401(k) with match
Flexible remote work time
Paid parental leave
Generous PTO

Job summary

ESRT seeks a senior network engineering leader to architect, deploy, and secure enterprise networks across multi‑site properties. You will design LAN/WAN, manage Palo Alto, Aruba, Zscaler, and Azure components, and drive incident response, root-cause analysis, and remediation with cross‑functional teams.

You will mentor engineers, collaborate with MSP/MSSP partners, and ensure PCI‑DSS/SOX compliance while delivering resilient connectivity and robust security posture.

Qualifications

  • 8–10 years of progressive, hands-on enterprise network engineering experience in complex, multi-site environments.
  • At least 3 years in a senior or lead capacity managing complex, multi-site infrastructure.
  • Proven experience serving as a technical escalation resource or informal architect on an infrastructure team.
  • Experience in Real Estate, Financial Services, or a similarly regulated industry preferred.
  • PCNSE strongly preferred; Panorama hands-on experience is a firm requirement.
  • Aruba/HPE, Zscaler, Azure, or Okta certifications are a plus.
  • CCNP Enterprise or equivalent routing/switching certification considered; depth matters.
  • Degree in CS/IT or related field preferred; relevant experience considered.

Responsibilities

  • Serve as primary escalation point for complex network incidents, outages, and performance issues, driving resolution with clear communication to stakeholders.
  • Provide expert guidance to internal engineers, MSP resources, and NOC personnel on architecture, troubleshooting methodology, and root cause analysis.
  • Lead post‑incident reviews, drive root cause identification, and implement lasting remediations to prevent recurrence.
  • Evaluate complex vendor and MSP escalations; make technical decisions on design, tooling, and resolution approach.
  • Design, deploy, and manage enterprise network infrastructure across BMS, IoT, Wi‑Fi, PropTech, AV, security systems, corporate offices, and the Observatory.
  • Administer Palo Alto NGFWs via Panorama – policy management, threat prevention, VPN, NAT, and security profile lifecycle management.
  • Manage and optimize Aruba switching and wireless infrastructure – configuration, upgrades, RF planning, and troubleshooting via Aruba Central.
  • Own BGP, OSPF, VLANs, VPN, QoS, and DNS configurations across multi‑site environments.
  • Manage WAN and ISP connectivity including failover design and carrier‑level troubleshooting.
  • Support IoT and PropTech deployments in a secure manner focusing on building systems, access control, and sustainability technology.
  • Lead network security posture improvements including firewall policy lifecycle, ACL governance, and vulnerability remediation.
  • Administer Zscaler ZIA and ZPA – URL filtering, SSL inspection, cloud firewall rules, and app connector management.
  • Manage Proofpoint email security platform – anti‑spam, anti‑phishing, encryption, and threat response policies.
  • Administer BitSight to track, triage, and coordinate remediation of external security posture findings.
  • Maintain PCI‑DSS and SOX compliance via enforcement of network policies and procedures.
  • Collaborate with the MSSP on security monitoring, threat analysis, and incident response.
  • Ensure timely application of patches, hotfixes, and firmware upgrades across all network equipment.
  • Administer Okta for SSO/SAML/OIDC, MFA enforcement, and user lifecycle management including SCIM provisioning and deprovisioning.
  • Manage Conditional Access Policies and integrate identity platforms with Palo Alto User‑ID, Zscaler IdP federation, and Azure AD.
  • Design and manage Microsoft Azure cloud networking – hybrid connectivity, VNet architecture, NSGs, and Azure Firewall.
  • Support Microsoft 365 and Exchange Online from a network and connectivity perspective – split tunneling and optimization.
  • Support IAM and PAM platforms as they relate to network access control and privilege governance.
  • Monitor and maintain building infrastructure, data center operations, and secure integration of IT/OT devices.
  • Maintain documentation, runbooks, and architectural diagrams.

Skills

8–10 years enterprise network eng
Senior/lead capacity
Technical escalation resource
Regulated industry experience
Documentation discipline

Education

Associate's or Bachelor's in CS/IT

Tools

Palo Alto Panorama
Aruba/HPE
Zscaler ZIA/ZPA
Azure networking
Okta Admin

Job description

Responsibilities
Technical Leadership & Escalation
  • Serve as primary escalation point for complex network incidents, outages, and performance issues, driving resolution with clear communication to stakeholders.
  • Provide expert guidance to internal engineers, MSP resources, and NOC personnel on architecture, troubleshooting methodology, and root cause analysis.
  • Lead post‑incident reviews, drive root cause identification, and implement lasting remediations to prevent recurrence.
  • Evaluate complex vendor and MSP escalations; make technical decisions on design, tooling, and resolution approach.
Network Architecture & Design
  • Work with the Director of Network & Infrastructure to architect scalable, resilient, and secure network solutions across LAN, WAN, wireless, cloud, and building infrastructure.
  • Lead design and evolution of network segmentation strategy including zero‑trust principles, VRF separation, and secure OT/IT boundary enforcement.
  • Develop and maintain network infrastructure standards, reference architectures, and design patterns for consistent deployment across properties.
  • Evaluate emerging technologies and contribute to the long‑term infrastructure roadmap, especially around Palo Alto Panorama, Aruba, and cloud connectivity platforms.
Network Engineering & Operations
  • Design, deploy, and manage enterprise network infrastructure across BMS, IoT, Wi‑Fi, PropTech, AV, security systems, corporate offices, and the Observatory.
  • Administer Palo Alto NGFWs via Panorama – policy management, threat prevention, VPN, NAT, and security profile lifecycle management.
  • Manage and optimize Aruba switching and wireless infrastructure – configuration, upgrades, RF planning, and troubleshooting via Aruba Central.
  • Own BGP, OSPF, VLANs, VPN, QoS, and DNS configurations across multi‑site environments.
  • Manage WAN and ISP connectivity including failover design and carrier‑level troubleshooting.
  • Support IoT and PropTech deployments in a secure manner focusing on building systems, access control, and sustainability technology.
Security & Compliance
  • Lead network security posture improvements including firewall policy lifecycle, ACL governance, and vulnerability remediation.
  • Administer Zscaler ZIA and ZPA – URL filtering, SSL inspection, cloud firewall rules, and app connector management.
  • Manage Proofpoint email security platform – anti‑spam, anti‑phishing, encryption, and threat response policies.
  • Administer BitSight to track, triage, and coordinate remediation of external security posture findings.
  • Maintain PCI‑DSS and SOX compliance via enforcement of network policies and procedures.
  • Collaborate with the MSSP on security monitoring, threat analysis, and incident response.
  • Ensure timely application of patches, hotfixes, and firmware upgrades across all network equipment.
Identity, Access & Cloud
  • Administer Okta for SSO/SAML/OIDC, MFA enforcement, and user lifecycle management including SCIM provisioning and deprovisioning.
  • Manage Conditional Access Policies and integrate identity platforms with Palo Alto User‑ID, Zscaler IdP federation, and Azure AD.
  • Design and manage Microsoft Azure cloud networking – hybrid connectivity, VNet architecture, NSGs, and Azure Firewall.
  • Support Microsoft 365 and Exchange Online from a network and connectivity perspective – split tunneling and optimization.
  • Support IAM and PAM platforms as they relate to network access control and privilege governance.
Physical Infrastructure & Systems
  • Manage physical server infrastructure, rack installation, and data center operations – cabling, power, and cooling.
  • Administer building riser infrastructure and ensure secure integration of IT and OT devices on segregated network segments.
  • Support VMware vSphere virtual networking and server resource management.
  • Oversee SAN/NAS storage networking and business continuity/backup technologies.
Monitoring, Documentation & Governance
  • Drive network monitoring strategy and tooling to ensure proactive alerting and performance trending.
  • Author and maintain high‑quality documentation – topology diagrams, configuration baselines, SOPs, runbooks.
  • Contribute to business continuity and disaster recovery procedures; develop, test, and maintain failover runbooks.
  • Adhere to change management and PMO best practices for all infrastructure changes; manage project milestones with clear stakeholder communication.
  • Resolve complex escalations decisively and thoroughly, with clear communication throughout.
  • Keep architecture documentation, standards, and reference designs current.
  • Improve security posture measurably – rationalize firewall policies, remediate vulnerabilities on time, enforce segmentation.
  • Maintain network stability and availability across all properties; detect incidents proactively.
  • Identify and bring forward new technologies and architectural improvements with solid business cases.
  • Address repetitive Service Desk escalations proactively.
Interpersonal Skills
  • Communicate complex technical issues, architectural decisions, and incident status clearly to peers and executive leadership.
  • Strong analytical and troubleshooting instincts; methodically address ambiguous, high‑pressure situations.
  • Collaborative mindset – work with internal teams, MSP, MSSP, vendors; share knowledge and elevate team capability.
  • Self‑directed and highly accountable – take ownership and follow through to resolution.
  • Strong documentation discipline – leave systems, configurations, designs better documented.
  • Proactively monitor industry developments and bring emerging technologies and best practices to the team.
Qualifications
  • 8–10 years of progressive, hands‑on enterprise network engineering experience in complex, multi‑site environments.
  • At least 3 years in a senior or lead capacity managing complex, multi‑site infrastructure.
  • Proven experience serving as a technical escalation resource or informal architect on an infrastructure team.
  • Experience in Real Estate, Financial Services, or a similarly regulated industry preferred.
  • PCNSE (Palo Alto Networks Certified Network Security Engineer) strongly preferred; Panorama hands‑on experience is a firm requirement.
  • Aruba/HPE (ACSA/ACCP), Zscaler (ZCCA‑IA/PA), Azure (AZ‑104), or Okta Certified Administrator are a plus.
  • CCNP Enterprise or equivalent routing/switching certification considered; demonstrated production depth matters most.
  • Associate's or Bachelor's Degree in Computer Science, Information Technology, or related field preferred; equivalent professional experience considered.
Benefits
  • Competitive base salary and bonus.
  • Health, Dental, Vision insurance.
  • Company‑sponsored Life, AD&D, STD (with Salary Continuation), and LTD Insurance.
  • Voluntary Enhanced LTD Program.
  • Voluntary Hospital, Accident, and Cancer Programs.
  • 401(k) with 100% match up to 5%.
  • Paid parental leave.
  • Pre‑tax transit accounts.
  • Employee Assistance Program for emotional, financial, and legal support.
  • Generous paid time off.
  • Flexible remote work time.
  • Flexible Summer Fridays.
  • Employee engagement programs.
  • Volunteer time off.
  • Continuing education.
  • Complimentary Empire State Building Observatory access.
  • Complimentary gym membership and other wellness benefits.
  • Employee Discount Programs.
EEO Statement

ESRT is an equal opportunity employer and is committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because they drive curiosity, innovation, and the success of our business. We do not discriminate based on race, religion, color, creed, national origin, sex, sexual orientation, gender identity or expression, reproductive choices, age, marital status, veteran status, disability status, pregnancy, parental status, caregiver status, genetic information, political affiliation, or any other status protected by the laws or regulations in the locations where we operate. This policy applies to all aspects of employment, including hiring, promotion, demotion, compensation, training, working conditions, transfer, job assignments, benefits, layoff, and termination. Reasonable accommodations that do not create an undue hardship for the Company are available for applicants and employees with disabilities or sincerely held religious beliefs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Socket.dev • California (MO)

On-site
USD 154,000 - 250,000
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Palo Alto Networks • Santa Clara (CA)

On-site
USD 154,000 - 250,000
Staff Technical Support Engineer, Focused Services, NGFW
Staff Technical Support Engineer, Focused Services, NGFW

Palo Alto Networks • Santa Clara (CA)

On-site
USD 117,000 - 190,000
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 154,000 - 250,000
Staff Technical Support Engineer, Focused Services, NGFW
Staff Technical Support Engineer, Focused Services, NGFW

Palo Alto Networks, Inc. • Plano (TX)

On-site
USD 117,000 - 190,000
Staff Network Security Engineer (Information Security) - US Citizen
Staff Network Security Engineer (Information Security) - US Citizen

Palo Alto Networks • Boston (MA)

On-site
USD 128,000 - 207,000
Staff Network Security Engineer (Information Security)
Staff Network Security Engineer (Information Security)

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 127,000 - 207,000
Employee benefits
Restricted stock units
Principal Cloud Infrastructure Engineer (Advanced Threat Protection)
Principal Cloud Infrastructure Engineer (Advanced Threat Protection)

Palo Alto Networks • United States

On-site
USD 150,000 - 230,000
Manager, Technical Customer Support, Focused Services
Manager, Technical Customer Support, Focused Services

Palo Alto Networks, Inc. • Plano (TX)

On-site
Senior Manager, Technical Support - Focused Services
Senior Manager, Technical Support - Focused Services

Palo Alto Networks, Inc. • Plano (TX)

On-site