Padmi
Empire State Realty Trust logo
Empire State Realty Trust

commercial real estate investment trust · office properties

Sr. Network Engineer

New York · Hybrid$155k–$175k/yrPosted 2 months ago
InfrastructureSeniorFull Time
Apply at Empire State Realty Trust

Opens the source posting on jobs.lever.co

Source description

About the role

View original

​ ​ ​ INTERPERSONAL SKILLS:

​ Communicates complex technical issues, architectural decisions, and incident status clearly to both engineering peers and executive leadership

​ Strong analytical and troubleshooting instincts works through ambiguous, high-pressure situations methodically and calmly

​ Collaborative mindset: works effectively with internal teams, MSP, MSSP, and vendors; shares knowledge freely and raises team capability

​ Self-directed and highly accountable that takes ownership without waiting to be asked and follows through to full resolution

​ Strong documentation discipline; leaves systems, configurations, and designs better documented than found

​ Proactively monitors industry developments and brings emerging technologies and best practices to the team's attention

​ PALO ALTO NGFWs & PANORAMA:

​ Expert-level policy management, troubleshooting, and architecture across a distributed multi-site environment

​ Panorama: centralized policy administration, device group management, log forwarding, and operational management at scale

​ Advanced firewall design: zone-based architecture, App-ID, User-ID, URL filtering, SSL decryption, threat prevention, and WildFire integration

​ GlobalProtect: VPN configuration, gateway management, and site-to-site connectivity

​ NAT policy design, security profile tuning, and firewall policy lifecycle management

​ PCNSE certification strongly preferred

​ ARUBA WIRELESS & SWITCHING:

​ Aruba CX / AOS-CX switching — configuration, troubleshooting, and lifecycle management across multi-site environments

​ Aruba Central management: RF planning, access point lifecycle, and performance optimization

​ Wireless security: 802.1X, RADIUS integration, guest network segmentation, and rogue AP detection

​ SD-WAN architecture awareness and WAN/ISP circuit failover design

​ ZSCALER ZIA / ZPA:

​ Zscaler Internet Access (ZIA) URL filtering, SSL inspection, cloud firewall, and policy configuration

​ Zscaler Private Access (ZPA) zero-trust application access, app connector management, and policy administration

​ Zscaler tenant administration, log streaming, and integration with SIEM and identity providers

​ OKTA / IAM & PAM:

​ Okta SSO/SAML/OIDC configuration, MFA enforcement, and user lifecycle management including SCIM provisioning

​ Okta integration with Palo Alto User-ID, Zscaler IdP federation, and Azure AD directory sync

​ PAM platform familiarity and IAM integration with network access controls and Conditional Access Policies

​ DNS & DOMAIN SECURITY:

​ Windows DNS / Active Directory-integrated internal DNS, external authoritative DNS, and split-brain DNS architectures

​ DNSSEC implementation and DNS-based threat detection and filtering

​ Domain protection — monitoring for lookalike/spoofed domains and unauthorized SSL/TLS certificate issuance

​ SSL/TLS certificate lifecycle management across internal and external services

​ BitSight or equivalent EASM platform administration

​ PROOFPOINT EMAIL SECURITY:

​ Anti-spam, anti-phishing, email encryption, and threat response policy management

​ Platform administration including quarantine management, allow/block lists, and reporting

​ Coordination with the security team on phishing investigations and incident response

​ Experience with a comparable enterprise email security platform considered equivalent

​ OT / BMS / IoT / PROPTECH:

​ Hands-on experience with network design for building management systems (BMS), IoT devices, and PropTech deployments

​ Network segmentation for OT/IT boundaries including VRF separation and secure access control

​ Experience supporting access control, CCTV, AV systems, and sustainability technology in a commercial real estate or multi-family residential environment

​ Awareness of OT security principles and protocols relevant to building infrastructure

​ PHYSICAL INFRASTRUCTURE & DATA CENTER:

​ Physical server management, rack installation, and data center operations including cabling, power, and cooling

​ VMware vSphere, virtual networking and server resource management

​ Microsoft Windows Server 2019/2022/2025 and Linux administration

​ Microsoft Active Directory, DNS, and DHCP infrastructure management

​ SAN/NAS storage networking and business continuity / backup technologies

​ PCI-DSS & SOX COMPLIANCE:

​ Working knowledge of PCI-DSS and SOX requirements for network segmentation, access control, and audit logging

​ Firewall ACL governance, policy review cycles, and evidence collection for compliance audits

​ Experience in a regulated industry (real estate, financial services, or similar) preferred

​ CLOUD & HYBRID NETWORKING:

​ Microsoft Azure — VNet design, hybrid connectivity (ExpressRoute / VPN Gateway), NSGs, Azure Firewall, and Azure AD / Entra

​ Hybrid DNS resolution, cloud-to-on-premises connectivity patterns, and identity federation

​ Microsoft 365 and Exchange Online — network requirements, split tunneling, and connectivity optimization