Network EngineerEmpire State Realty Trust, Inc. is a NYC-focused REIT that owns and operates a portfolio of well-leased, top of tier, modernized, amenitized, and well-located office, retail, and multifamily assets. The Company is a recognized leader in energy efficiency and indoor environmental quality.
The dedicated team at ESRT is a collection of diverse individuals with a shared passion for excellence and a keen eye toward future growth. We prioritize and invest in the health and wellness of employees to attract, develop, and retain top-tier talent. ESRT values continuous employee development and encourages colleagues to excel in their roles and adapt to emerging business needs.
From our crown jewel, The Empire State Building, to incredible buildings modernized for the 21st century, to outstanding customer service, and our decade-long leadership position in sustainability and energy efficient portfolio that is 100% fully powered by renewable wind electricity, we take pride in our work. ESRT seeks an equally passionate colleague to join the team, understand the vision and help achieve that vision.ResponsibilitiesTechnical Leadership & Escalation:Serve as the primary escalation point for complex network incidents, outages, and performance issues owing problems through to resolution with clear communication to stakeholdersProvide expert guidance to internal engineers, MSP resources, and NOC personnel on architecture, troubleshooting methodology, and root cause analysisLead post-incident reviews, drive root cause identification, and implement lasting remediations to prevent recurrenceEvaluate complex vendor and MSP escalations; make technical decisions on design, tooling, and resolution approachNetwork Architecture & Design:Work with the Director of Network & Infrastructure to architect scalable, resilient, and secure network solutions across LAN, WAN, wireless, cloud, and building infrastructureLead the design and evolution of network segmentation strategy including zero-trust principles, VRF separation, and secure OT/IT boundary enforcementDevelop and maintain network infrastructure standards, reference architectures, and design patterns for consistent deployment across propertiesEvaluate emerging technologies and contribute to the long-term infrastructure roadmap, particularly around Palo Alto / Panorama, Aruba, and cloud connectivity platformsNetwork Engineering & Operations:Design, deploy, and manage enterprise network infrastructure across BMS, IoT, Wi-Fi, PropTech, AV, security systems, corporate offices, and the ObservatoryAdminister Palo Alto NGFWs via Panorama — policy management, threat prevention, VPN, NAT, and security profile lifecycle managementManage and optimize Aruba switching and wireless infrastructure including configuration, upgrades, RF planning, and troubleshooting via Aruba CentralOwn BGP, OSPF, VLANs, VPN, QoS, and DNS configurations across multi-site environmentsManage WAN and ISP connectivity including failover design and carrier-level troubleshootingSupport IoT and PropTech deployments in a secure manner with a focus on building systems, access control, and sustainability technologySecurity & Compliance:Lead network security posture improvements including firewall policy lifecycle, ACL governance, and vulnerability remediationAdminister Zscaler ZIA and ZPA — URL filtering, SSL inspection, cloud firewall rules, and app connector managementManage Proofpoint email security platform including anti-spam, anti-phishing, encryption, and threat response policiesAdminister BitSight to track, triage, and coordinate remediation of external security posture findingsMaintain PCI-DSS and SOX compliance through adherence to and enforcement of network policies and proceduresCollaborate with the MSSP on security monitoring, threat analysis, and incident responseEnsure timely application of patches, hotfixes, and firmware upgrades across all network equipmentIdentity, Access & Cloud:Administer Okta for SSO/SAML/OIDC, MFA enforcement, and user lifecycle management including SCIM provisioning and deprovisioningManage Conditional Access Policies and integrate identity platforms with Palo Alto User-ID, Zscaler IdP federation, and Azure ADDesign and manage Microsoft Azure cloud networking including hybrid connectivity, VNet architecture, NSGs, and Azure FirewallSupport Microsoft 365 and Exchange Online from a network and connectivity perspective including split tunneling and optimizationSupport IAM and PAM platforms as they relate to network access control and privilege governancePhysical Infrastructure & Systems:Manage physical server infrastructure, rack equipment installation, and data center operations including cabling, power, and coolingAdminister building riser infrastructure and ensure secure integration of IT and OT devices on segregated network segmentsSupport VMware vSphere virtual networking environments and server resource managementOversee SAN/NAS storage networking and business continuity / backup technologiesMonitoring, Documentation & Governance:Drive network monitoring strategy and tooling to ensure proactive alerting and performance trending across the full infrastructure estateAuthor and maintain high-quality documentation including topology diagrams, configuration baselines, SOPs, and runbooksContribute to business continuity and disaster recovery procedures; develop, test, and maintain failover runbooksAdhere to change management and PMO best practices for all infrastructure changes; manage project milestones with clear stakeholder communicationWhat Success Looks LikeComplex escalations are resolved decisively and thoroughly, with clear communication throughout the team and Director trust this person to own the hardest problemsNetwork architecture documentation, standards, and reference designs are developed and kept current, reducing reliance on tribal knowledgeSecurity posture improves measurably: firewall policies are rationalized, vulnerabilities remediated on time, and segmentation consistently enforcedNetwork stability and availability are maintained across all properties; incidents are detected proactively rather than reactivelyNew technologies and architectural improvements are identified and brought forward with well-reasoned business casesService Desk escalations are resolved efficiently with recurring patterns identified and addressed proactivelyRequired Technical Skills / AbilitiesInterpersonal Skills:Communicates complex technical issues, architectural decisions, and incident status clearly to both engineering peers and executive leadershipStrong analytical and troubleshooting instincts works through ambiguous, high-pressure situations methodically and calmlyCollaborative mindset: works effectively with internal teams, MSP, MSSP, and vendors; shares knowledge freely and raises team capabilitySelf-directed and highly accountable that takes ownership without waiting to be asked and follows through to full resolutionStrong documentation discipline; leaves systems, configurations, and designs better documented than foundProactively monitors industry developments and brings emerging technologies and best practices to the team's attentionPalo Alto NGFWs & Panorama:Expert-level policy management, troubleshooting, and architecture across a distributed multi-site environmentPanorama: centralized policy administration, device group management, log forwarding, and operational management at scaleAdvanced firewall design: zone-based architecture, App-ID, User-ID, URL filtering, SSL decryption, threat prevention, and WildFire integrationGlobalProtect: VPN configuration, gateway management, and site-to-site connectivityNAT policy design, security profile tuning, and firewall policy lifecycle managementPCNSE certification strongly preferredAruba Wireless & Switching:Aruba CX / AOS-CX switching — configuration, troubleshooting, and lifecycle management across multi-site environmentsAruba Central management: RF planning, access point lifecycle, and performance optimizationWireless security: 802.1X, RADIUS integration, guest network segmentation, and rogue AP detectionSD-WAN architecture awareness and WAN/ISP circuit failover designZscaler ZIA / ZPA:Zscaler Internet Access (ZIA) URL filtering, SSL inspection, cloud firewall, and policy configurationZscaler Private Access