Sr. Network Engineer
$155k - $175kEmpire State Realty Trust
COMPANY SUMMARY Empire State Realty Trust, Inc. (NYSE: ESRT) is a NYC-focused REIT that owns and operates a portfolio of well-leased, top of tier, modernized, amenitized, and well-located office, retail, and multifamily assets. ESRT's flagship Empire State Building, the "World's Most Famous Building," features its iconic Observation Deck, ranked the #1 Top Attraction in New York City for the fifth consecutive year in Tripadvisor's 2026 Travelers' Choice Awards: Best of the Best Things to Do. The Company is a recognized leader in energy efficiency and indoor environmental quality. As of March 31, 2026, ESRT's portfolio is comprised of approximately 8.0 million rentable square feet of office space, 0.8 million rentable square feet of retail space and 743 residential units. More information about Empire State Realty Trust can be found at esrtreit.com and by following ESRT on Facebook, Instagram, TikTok, X and LinkedIn. The dedicated team at ESRT is a collection of diverse individuals with a shared passion for excellence and a keen eye toward future growth. Headquartered in New York City, we harness the energy of the city in everything we do. We care for one another, work hard, and have a lot of fun doing it! We are Certified™ as a Great Place to Work® by the global authority, Great Place to Work®, on workplace culture, employee experience, and leadership behaviors. We prioritize and invest in the health and wellness of employees to attract, develop, and retain top-tier talent. ESRT values continuous employee development and encourages colleagues to excel in their roles and adapt to emerging business needs. From our crown jewel, The Empire State Building, to incredible buildings modernized for the 21st century, to outstanding customer service, and our decade-long leadership position in sustainability and energy efficient portfolio that is 100% fully powered by renewable wind electricity, we take pride in our work. ESRT seeks an equally passionate colleague to join the team, understand the vision and help achieve that vision.
RESPONSIBILITIES TECHNICAL LEADERSHIP & ESCALATION:
NETWORK ARCHITECTURE & DESIGN:
NETWORK ENGINEERING & OPERATIONS:
SECURITY & COMPLIANCE:
PHYSICAL INFRASTRUCTURE & SYSTEMS:
MONITORING, DOCUMENTATION & GOVERNANCE:
PALO ALTO NGFWs & PANORAMA:
ARUBA WIRELESS & SWITCHING:
ZSCALER ZIA / ZPA:
OT / BMS / IoT / PROPTECH:
PHYSICAL INFRASTRUCTURE & DATA CENTER:
RESPONSIBILITIES TECHNICAL LEADERSHIP & ESCALATION:
- Serve as the primary escalation point for complex network incidents, outages, and performance issues owing problems through to resolution with clear communication to stakeholders >
- Provide expert guidance to internal engineers, MSP resources, and NOC personnel on architecture, troubleshooting methodology, and root cause analysis >
- Lead post-incident reviews, drive root cause identification, and implement lasting remediations to prevent recurrence >
- Evaluate complex vendor and MSP escalations; make technical decisions on design, tooling, and resolution approach >
NETWORK ARCHITECTURE & DESIGN:
- Work with the Director of Network & Infrastructure to architect scalable, resilient, and secure network solutions across LAN, WAN, wireless, cloud, and building infrastructure >
- Lead the design and evolution of network segmentation strategy including zero-trust principles, VRF separation, and secure OT/IT boundary enforcement >
- Develop and maintain network infrastructure standards, reference architectures, and design patterns for consistent deployment across properties >
- Evaluate emerging technologies and contribute to the long-term infrastructure roadmap, particularly around Palo Alto / Panorama, Aruba, and cloud connectivity platforms >
NETWORK ENGINEERING & OPERATIONS:
- Design, deploy, and manage enterprise network infrastructure across BMS, IoT, Wi-Fi, PropTech, AV, security systems, corporate offices, and the Observatory >
- Administer Palo Alto NGFWs via Panorama - policy management, threat prevention, VPN, NAT, and security profile lifecycle management >
- Manage and optimize Aruba switching and wireless infrastructure including configuration, upgrades, RF planning, and troubleshooting via Aruba Central >
- Own BGP, OSPF, VLANs, VPN, QoS, and DNS configurations across multi-site environments >
- Manage WAN and ISP connectivity including failover design and carrier-level troubleshooting >
- Support IoT and PropTech deployments in a secure manner with a focus on building systems, access control, and sustainability technology >
SECURITY & COMPLIANCE:
- Lead network security posture improvements including firewall policy lifecycle, ACL governance, and vulnerability remediation >
- Administer Zscaler ZIA and ZPA - URL filtering, SSL inspection, cloud firewall rules, and app connector management >
- Manage Proofpoint email security platform including anti-spam, anti-phishing, encryption, and threat response policies >
- Administer BitSight to track, triage, and coordinate remediation of external security posture findings >
- Maintain PCI-DSS and SOX compliance through adherence to and enforcement of network policies and procedures >
- Collaborate with the MSSP on security monitoring, threat analysis, and incident response >
- Ensure timely application of patches, hotfixes, and firmware upgrades across all network equipment >
- Administer Okta for SSO/SAML/OIDC, MFA enforcement, and user lifecycle management including SCIM provisioning and deprovisioning >
- Manage Conditional Access Policies and integrate identity platforms with Palo Alto User-ID, Zscaler IdP federation, and Azure AD >
- Design and manage Microsoft Azure cloud networking including hybrid connectivity, VNet architecture, NSGs, and Azure Firewall >
- Support Microsoft 365 and Exchange Online from a network and connectivity perspective including split tunneling and optimization >
- Support IAM and PAM platforms as they relate to network access control and privilege governance >
PHYSICAL INFRASTRUCTURE & SYSTEMS:
- Manage physical server infrastructure, rack equipment installation, and data center operations including cabling, power, and cooling >
- Administer building riser infrastructure and ensure secure integration of IT and OT devices on segregated network segments >
- Support VMware vSphere virtual networking environments and server resource management >
- Oversee SAN/NAS storage networking and business continuity / backup technologies >
MONITORING, DOCUMENTATION & GOVERNANCE:
- Drive network monitoring strategy and tooling to ensure proactive alerting and performance trending across the full infrastructure estate >
- Author and maintain high-quality documentation including topology diagrams, configuration baselines, SOPs, and runbooks >
- Contribute to business continuity and disaster recovery procedures; develop, test, and maintain failover runbooks >
- Adhere to change management and PMO best practices for all infrastructure changes; manage project milestones with clear stakeholder communication >
- Complex escalations are resolved decisively and thoroughly, with clear communication throughout the team and Director trust this person to own the hardest problems >
- Network architecture documentation, standards, and reference designs are developed and kept current, reducing reliance on tribal knowledge >
- Security posture improves measurably: firewall policies are rationalized, vulnerabilities remediated on time, and segmentation consistently enforced >
- Network stability and availability are maintained across all properties; incidents are detected proactively rather than reactively >
- New technologies and architectural improvements are identified and brought forward with well-reasoned business cases >
- Service Desk escalations are resolved efficiently with recurring patterns identified and addressed proactively >
- Communicates complex technical issues, architectural decisions, and incident status clearly to both engineering peers and executive leadership >
- Strong analytical and troubleshooting instincts works through ambiguous, high-pressure situations methodically and calmly >
- Collaborative mindset: works effectively with internal teams, MSP, MSSP, and vendors; shares knowledge freely and raises team capability >
- Self-directed and highly accountable that takes ownership without waiting to be asked and follows through to full resolution >
- Strong documentation discipline; leaves systems, configurations, and designs better documented than found >
- Proactively monitors industry developments and brings emerging technologies and best practices to the team's attention >
PALO ALTO NGFWs & PANORAMA:
- Expert-level policy management, troubleshooting, and architecture across a distributed multi-site environment >
- Panorama: centralized policy administration, device group management, log forwarding, and operational management at scale >
- Advanced firewall design: zone-based architecture, App-ID, User-ID, URL filtering, SSL decryption, threat prevention, and WildFire integration >
- GlobalProtect: VPN configuration, gateway management, and site-to-site connectivity >
- NAT policy design, security profile tuning, and firewall policy lifecycle management >
- PCNSE certification strongly preferred >
ARUBA WIRELESS & SWITCHING:
- Aruba CX / AOS-CX switching - configuration, troubleshooting, and lifecycle management across multi-site environments >
- Aruba Central management: RF planning, access point lifecycle, and performance optimization >
- Wireless security: 802.1X, RADIUS integration, guest network segmentation, and rogue AP detection >
- SD-WAN architecture awareness and WAN/ISP circuit failover design >
ZSCALER ZIA / ZPA:
- Zscaler Internet Access (ZIA) URL filtering, SSL inspection, cloud firewall, and policy configuration >
- Zscaler Private Access (ZPA) zero-trust application access, app connector management, and policy administration >
- Zscaler tenant administration, log streaming, and integration with SIEM and identity providers >
- Okta SSO/SAML/OIDC configuration, MFA enforcement, and user lifecycle management including SCIM provisioning >
- Okta integration with Palo Alto User-ID, Zscaler IdP federation, and Azure AD directory sync >
- PAM platform familiarity and IAM integration with network access controls and Conditional Access Policies >
- Windows DNS / Active Directory-integrated internal DNS, external authoritative DNS, and split-brain DNS architectures >
- DNSSEC implementation and DNS-based threat detection and filtering >
- Domain protection - monitoring for lookalike/spoofed domains and unauthorized SSL/TLS certificate issuance >
- SSL/TLS certificate lifecycle management across internal and external services >
- BitSight or equivalent EASM platform administration >
- Anti-spam, anti-phishing, email encryption, and threat response policy management >
- Platform administration including quarantine management, allow/block lists, and reporting >
- Coordination with the security team on phishing investigations and incident response >
- Experience with a comparable enterprise email security platform considered equivalent >
OT / BMS / IoT / PROPTECH:
- Hands-on experience with network design for building management systems (BMS), IoT devices, and PropTech deployments >
- Network segmentation for OT/IT boundaries including VRF separation and secure access control >
- Experience supporting access control, CCTV, AV systems, and sustainability technology in a commercial real estate or multi-family residential environment >
- Awareness of OT security principles and protocols relevant to building infrastructure >
PHYSICAL INFRASTRUCTURE & DATA CENTER:
- Physical server management, rack installation, and data center operations including cabling, power, and cooling >
- VMware vSphere, virtual networking and server resource management >
- Microsoft Windows Server 2019/2022/2025 and Linux administration >
- Microsoft Active Directory, DNS, and DHCP infrastructure management >
- SAN/NAS storage networking and business continuity / backup technologies >
- Working knowledge of PCI-DSS and SOX requirements for network segmentation, access control, and audit logging >
- Firewall ACL governance, policy review cycles, and evidence collection for compliance audits >
- Experience in a regulated industry (real estate, financial services, or similar) preferred >
- Microsoft Azure - VNet design, hybrid connectivity (ExpressRoute / VPN Gateway), NSGs, Azure Firewall, and Azure AD / Entra >
- Hybrid DNS resolution, cloud-to-on-premises connectivity patterns, and identity federation >
- Microsoft 365 and Exchange Online - network requirements, split tunneling, and connectivity optimization >
- 8-10 years of progressive, hands-on enterprise network engineering experience with demonstrated depth in complex, multi-site environments >
- At least 3 years in a senior or lead capacity managing complex, multi-site infrastructure >
- Proven experience serving as a technical escalation resource or informal architect on an infrastructure team >
- Experience in Real Estate, Financial Services, or a similarly regulated industry preferred >
- PCNSE (Palo Alto Networks Certified Network Security Engineer) strongly preferred; Panorama hands-on experience is a firm requirement >
- Aruba/HPE (ACSA/ACCP), Zscaler (ZCCA-IA/PA), Azure (AZ-104), or Okta Certified Administrator are a plus >
- CCNP Enterprise or equivalent routing/switching certification considered; demonstrated production depth matters most >
- Associate's or Bachelor's Degree in Computer Science, Information Technology, or related field preferred; equivalent professional experience considered >
- Prolonged periods of sitting at a desk and working on a computer
- Must be able to lift up to 15 pounds at times
- Adaptable - you are a self-starter who's able to quickly digest and execute new processes to work both collaboratively and independently
- Dynamic - you are solutions-oriented, aim to improve processes and implement efficiency, and offer insightful feedback to improve ESRT
- Dependable - you take a strong sense of ownership and accountability over your work
- Passionate - you keep up with industry trends and are excited about the potential to propel the industry forward with a "roll-up-your-sleeves" attitude
- Curious - you consistently look for new ways to work smarter, not just harder
- Ethical - you treat others with respect, act with integrity in how you perform your work, and embrace our collaborative culture
- Positive - you possess a service-oriented attitude with excellent follow through
- Competitive base salary and bonus
- Health/Dental/Vision insurance
- Company sponsored Life, AD&D, STD (with Salary Continuation), and LTD Insurance
- Voluntary Enhanced LTD Program
- Voluntary Hospital, Accident, and Cancer Programs
- 401(k) with 100% match up to 5%
- Paid parental leave
- Pre-tax transit accounts
- Employee Assistance Program for emotional, financial, and legal support
- Generous paid time off
- Flex remote work time
- Flex Summer Fridays
- Employee engagement programs
- Volunteer time off
- Continuing education
- Complimentary Empire State Building Observatory access
- Complimentary gym membership and other wellness benefits
- Employee Discount Programs
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Sr. Network Engineer in New York, NY vacancy
- ...Sr. Network Engineer Placement type (FTE/C/CTH) - Contract Duration - 6 Months + Location - 4 Days Per week Onsite, Mon-Thur. Will need to be able to travel to Rocklin, CA once a month for Engineering Team engagement and critical monthly staff meetings if located...SeniorContract work
- ...Sr. Network Engineer Location: Five boroughs of NYC (Hybrid) Duration: 12+ Months Hybrid schedule: 3 days per week on-site and 2 days per week remote. OTI will not be reimbursing for the travels which is expected to be confined to within five boroughs of City...SeniorRemote work2 days per week3 days per week
- ...Network Sme Engineer Senior Location: Alpharetta, GA or New York City, NY hybrid onsite - Need to come to office 3 days a week also we would prefer local associate from Alpharetta (Georgia) Network SME Engineer Senior in Network Engineering. More than 10+ years'...SeniorWork at officeLocal area3 days per week
- ...Senior Network Engineer | Hybrid in NYC Proper planning of upgrades and changes; perform code upgrades Update documentation, procedures, diagrams, circuit IDs, etc. Liaise with Network Services team and end-users on day-to-day issues React to Network Monitoring...SeniorRemote work
- ...Network Engineer We are seeking an experienced Network Engineer to support a large scale Juniper to Arista campus switching migration for a healthcare environment in New York City. The engagement will support deployment activities within an Arista Cloud managed campus...Senior
- ...Sr. Network Engineer III Location: Jersey City, NJ (Web Cam Interview) Duration: Long Term (W2) H1 Transfer/ GC/ Citizen Business Overview: CIB IT Production is a transversal function which provides all core technologies to all businesses of the bank in the Americas...SeniorWork experience placementLocal area
- ...Job Title: Job : Sr Network Engineer Duration: 6 months Location: Remote Responsibilities Design, implement, and manage scalable data center network architectures for Virtual Private Clouds (VPCs), hybrid/multi-cloud, and edge network...SeniorRemote work
- ...Job Description A leading hospital system in NYC is seeking a Network Engineer to join their team. Some of the daily responsibilities include: • Support and maintain enterprise and data center network environments (heavy operational focus) • Configure and troubleshoot...Senior
- ...Sr. Network Engineer - Modern Networks (CCNP or CCIE) * Remote role - based in the Northern NJ / NYC metro area * Full-time Perm role | working on Fortune 500 projects | High-impact role If you’re the type of engineer who loves solving big network challenges...SeniorPermanent employmentFull timeRemote work
$138.72k - $149.04k
...Job Description Company: AMD Design LLC, a wholly owned subsidiary of Advanced Micro Devices, Inc. Position Title: Sr. Network Engineer Work Location: 10 Enterprise Avenue N, Secaucus, NJ 07094 Wage: $138,717.30 - $149,040 per year Multiple Openings....SeniorFull time$150k - $165k
...Join to apply for the Sr. Network Engineer role at Piper Companies Join to apply for the Sr. Network Engineer role at Piper Companies Get AI-powered advice on this job and more exclusive features. Piper Companies is hiring a Senior Network Engineer to join a high-impact...SeniorFull timeLive inRemote work- ...Senior Network Engineer Client mission is to ensure staff and students have the technology knowledge, abilities and resources necessary for an excellent education while empowering collaboration across the organization to deliver technology for the next generation....SeniorRemote workNight shift
- ...SR. NETWORK ENGINEER Seeking a Sr. Network Engineer to join our team supporting the global network. You will be a member of our Enterprise I.T. Infrastructure Team responsible for ensuring a highly-available global network. This includes engineering, deploying...Senior
$128k
...Job Description We are seeking a highly skilled Senior Perimeter Network Engineer with deep expertise in Palo Alto Networks firewalls to design, implement, manage, and optimize our perimeter security infrastructure. This role will be responsible for securing enterprise...SeniorLocal areaNight shift$100k - $140k
...of content reflecting our world. Job Description Global Network and Distribution operations team is responsible for maintaining NBCU's corporate and broadcast network. We are looking for an engineer who has a broad spectrum of knowledge with all networking...SeniorWork at officeLocal area3 days per week$112.5k - $140k
...American Specialty Health Incorporated (ASH) is seeking a Sr Network Engineer I to join our Information Technology-Operations department. The Senior Network Engineer I is responsible for the design, implementation, security, and operational support of the enterprise network...SeniorFull timeLocal areaRemote workWork from home- Job Title Remote during pandemic Job Description This is NOT a deploy role looking for CCIE level, should have written CCIE, campus environment SME R/S Financial Industry background (low Latency) Mulitcast LAN/Wan expertise Configuration Expert-Design Required...SeniorRemote work
- ...Sr Systems Network Engineer Must live in a New England State or New York Fully remote except possible travel to the data centers in MA once a month Very senior - somebody who has been in the industry for 10 years and has virtualization Can hit the ground...SeniorLive inRemote work
- ...and unlocks productivity gains for modern enterprises by reducing costs and complexity. Role We are looking for a Sr. Network and Infrastructure Engineer to join our Cloud Ops - Network Engineering department in a fully remote capacity in the Netherlands, reporting to...SeniorWork at officeLocal areaRemote work
- ...Cisco Viptela SME Sr. Engineer, Architect level Engineer • General networking, working on a global SD-WAN. • SD-WAN certs would be nice to have • CCNP or higher caliber person for sure. • Expert in Cisco SD-WAN • Larger deployments, configuration expert architect level...Senior
- ...Core4ce Careers is looking for a Network Engineer SME specializing in Cisco ISE and Armis solutions. The role includes planning, deploying, and supporting critical network infrastructure in a dynamic environment. Candidates should have 8+ years of experience with Cisco...Senior
- ...A leading technology firm is seeking a Senior Network Engineer to support and implement network solutions across global platforms. The ideal candidate will have over 3 years of experience in configuring Next-Gen Firewalls and managing BGP and OSPF routing protocols. Responsibilities...Senior
$82.5k - $110k
...About The Role The Network Engineer is responsible for implementing, supporting, and maintaining enterprise networking solutions to meet business requirements. This role focuses on network operations, troubleshooting, and escalation support for LAN, WAN, wireless...SeniorPermanent employmentWork at officeLocal areaRemote work- ...A pioneering technology company in the United States is seeking a Software Engineer specializing in Networking to design and implement its networking stack. The ideal candidate will have over 5 years of systems software experience, with significant expertise in Rust or...SeniorRemote work
- ...Senior Data Center Network Engineer We are seeking a Senior Data Center Network Engineer with 10+ years of enterprise and data center networking experience to support the structured decommissioning of brownfield data center infrastructure. The right candidate has deep...Senior
- ...Senior Network Engineer (VoIP / SIP Network Support Engineer) Client: Financial Location: North America (on site Jersey City, NJ; Plano, TX; Columbus, OH) Work Hours: 8 AM – 5 PM EST Overview: We are seeking a highly skilled VoIP / SIP Network Support Engineer to...Senior
$140k - $150k
...Overview Our client is looking to hire a Senior Network Engineer to join the team. This is an add-to-staff position. They are going through acquisitions and need an extra set of hands. Remote, but travel may be required. Base pay range $140,000.00/yr - $150,000.00/yr...SeniorFull timeRemote work- ...Infrastructure services in all areas needed: LAN, WAN, cloud environments, network security and network monitoring, configuration and troubleshooting Working with our business and the engineering team to successfully implement secure LAN/WAN, wireless, and Data Center...Senior
- ...Title: Senior Network Engineer Location: Brooklyn, NY Duration: 12 Months Visa: USC, GC (orignal) Rate: $70/Hr AI C2C F2F interview is there Required Skills: ~8 years' experience in network administration and management...Senior
- ...Lead, Technical Recruiting @ CDW | ServiceNow, Network Engineering, Infrastructure, Security Network Engineer – ModernFabric & Enterprise Routing Remote Work – 6 month contract to start; overall project is 18 months 15-25% travel to troubleshoot issues when needed onsite...SeniorContract workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Network Engineer. Be the first to apply!
Related searches
- junior cisco network engineer New York, NY
- ip network engineer New York, NY
- enterprise network engineer New York, NY
- senior network engineer remote New York, NY
- network qa engineer New York, NY
- network implementation engineer New York, NY
- network services engineer New York, NY
- senior network engineer New York, NY
- ccna network engineer New York, NY
- work from home network engineer New York, NY

