Source description
About the role
INTERPERSONAL SKILLS:
Communicates complex technical issues, architectural decisions, and incident status clearly to both engineering peers and executive leadership
Strong analytical and troubleshooting instincts works through ambiguous, high-pressure situations methodically and calmly
Collaborative mindset: works effectively with internal teams, MSP, MSSP, and vendors; shares knowledge freely and raises team capability
Self-directed and highly accountable that takes ownership without waiting to be asked and follows through to full resolution
Strong documentation discipline; leaves systems, configurations, and designs better documented than found
Proactively monitors industry developments and brings emerging technologies and best practices to the team's attention
PALO ALTO NGFWs & PANORAMA:
Expert-level policy management, troubleshooting, and architecture across a distributed multi-site environment
Panorama: centralized policy administration, device group management, log forwarding, and operational management at scale
Advanced firewall design: zone-based architecture, App-ID, User-ID, URL filtering, SSL decryption, threat prevention, and WildFire integration
GlobalProtect: VPN configuration, gateway management, and site-to-site connectivity
NAT policy design, security profile tuning, and firewall policy lifecycle management
PCNSE certification strongly preferred
ARUBA WIRELESS & SWITCHING:
Aruba CX / AOS-CX switching — configuration, troubleshooting, and lifecycle management across multi-site environments
Aruba Central management: RF planning, access point lifecycle, and performance optimization
Wireless security: 802.1X, RADIUS integration, guest network segmentation, and rogue AP detection
SD-WAN architecture awareness and WAN/ISP circuit failover design
ZSCALER ZIA / ZPA:
Zscaler Internet Access (ZIA) URL filtering, SSL inspection, cloud firewall, and policy configuration
Zscaler Private Access (ZPA) zero-trust application access, app connector management, and policy administration
Zscaler tenant administration, log streaming, and integration with SIEM and identity providers
OKTA / IAM & PAM:
Okta SSO/SAML/OIDC configuration, MFA enforcement, and user lifecycle management including SCIM provisioning
Okta integration with Palo Alto User-ID, Zscaler IdP federation, and Azure AD directory sync
PAM platform familiarity and IAM integration with network access controls and Conditional Access Policies
DNS & DOMAIN SECURITY:
Windows DNS / Active Directory-integrated internal DNS, external authoritative DNS, and split-brain DNS architectures
DNSSEC implementation and DNS-based threat detection and filtering
Domain protection — monitoring for lookalike/spoofed domains and unauthorized SSL/TLS certificate issuance
SSL/TLS certificate lifecycle management across internal and external services
BitSight or equivalent EASM platform administration
PROOFPOINT EMAIL SECURITY:
Anti-spam, anti-phishing, email encryption, and threat response policy management
Platform administration including quarantine management, allow/block lists, and reporting
Coordination with the security team on phishing investigations and incident response
Experience with a comparable enterprise email security platform considered equivalent
OT / BMS / IoT / PROPTECH:
Hands-on experience with network design for building management systems (BMS), IoT devices, and PropTech deployments
Network segmentation for OT/IT boundaries including VRF separation and secure access control
Experience supporting access control, CCTV, AV systems, and sustainability technology in a commercial real estate or multi-family residential environment
Awareness of OT security principles and protocols relevant to building infrastructure
PHYSICAL INFRASTRUCTURE & DATA CENTER:
Physical server management, rack installation, and data center operations including cabling, power, and cooling
VMware vSphere, virtual networking and server resource management
Microsoft Windows Server 2019/2022/2025 and Linux administration
Microsoft Active Directory, DNS, and DHCP infrastructure management
SAN/NAS storage networking and business continuity / backup technologies
PCI-DSS & SOX COMPLIANCE:
Working knowledge of PCI-DSS and SOX requirements for network segmentation, access control, and audit logging
Firewall ACL governance, policy review cycles, and evidence collection for compliance audits
Experience in a regulated industry (real estate, financial services, or similar) preferred
CLOUD & HYBRID NETWORKING:
Microsoft Azure — VNet design, hybrid connectivity (ExpressRoute / VPN Gateway), NSGs, Azure Firewall, and Azure AD / Entra
Hybrid DNS resolution, cloud-to-on-premises connectivity patterns, and identity federation
Microsoft 365 and Exchange Online — network requirements, split tunneling, and connectivity optimization
