Manager, Network Infrastructure

WME GroupNew York, NY
$138,750 - $185,000

About The Position

The Manager, Network Infrastructure leads WME's global network and voice estate — the connectivity, wireless, security, and telephony that every office and every user depends on across eight sites. This is a hands-on technical manager: the role both leads a team of four network and voice engineers and serves as the senior technical authority for the estate, staying close enough to the technology to make architecture and troubleshooting calls, not just manage them. The role owns LAN / WAN and switching, Palo Alto firewall management — the platform WME routes and runs site-to-site connectivity from — enterprise wireless, network security and Zero Trust (802.1X and network access control), core network services (DNS / DHCP / IPAM), site-to-site connectivity and internet circuits, and voice / unified communications including Cisco Call Manager. It runs the network as a dependable service, works hand-in-hand with the cybersecurity function on security incident response and triage, and is the seat that finally puts management and backup coverage around a network and voice function that has carried single points of failure for too long. The role builds and operates within the enterprise network and security architecture standards set by the Principal Enterprise Architect, and partners with the cybersecurity governance function and the managed security services partner on Zero Trust and network security.

Requirements

  • 8+ years in network engineering with progressive responsibility, including team-lead or people-management experience.
  • Deep routing and switching — Cisco switching and campus / data-center networking, with routing and site-to-site VPN on Palo Alto firewalls.
  • Palo Alto NGFW management — security policy, threat prevention, URL filtering, and firewall-based routing / site-to-site VPN.
  • Core network services — DNS, DHCP, and IP address management (IPAM).
  • Enterprise wireless (WLAN) design and operations experience.
  • Network security expertise — Zero Trust network architecture, 802.1X, network access control (NAC), and segmentation.
  • Remote access VPN and secure connectivity — GlobalProtect, SASE / SSE, or equivalent.
  • Voice / unified communications — VoIP, Cisco Call Manager (CUCM), SIP trunking, PSTN, and E911.
  • Experience managing internet circuits and carrier / ISP relationships.
  • Hybrid cloud networking — Azure ExpressRoute / VPN and hybrid connectivity.
  • Load balancing / application delivery (F5 or equivalent), and network automation / scripting (Ansible, Python, or equivalent).
  • Experience partnering with security teams on incident response and triage.
  • Experience running distributed / global network operations across multiple sites and time zones.
  • People management — hiring, developing, and leading engineers, ideally distributed.
  • Strong written and verbal communication; demonstrated use of AI tooling in technical work.

Nice To Haves

  • CCNP or CCIE (Enterprise); wireless and security specializations a plus.
  • Palo Alto Networks certification (PCNSE).
  • Cisco ISE (NAC) and Zscaler / ZTNA experience.
  • SD-WAN design and operations experience.
  • Azure networking (AZ-700) or equivalent hybrid-cloud networking experience.
  • Cisco Unified Communications / Call Manager certification.
  • Experience in multi-region, high-availability, or media / entertainment environments.

Responsibilities

  • Lead, develop, and grow a team of four globally distributed network and voice engineers — hiring, coaching, performance, and career development.
  • Own on-call, escalation, and coverage models; build backup coverage that eliminates single points of failure in the network and telecom functions.
  • Set team priorities and workload across time zones and sites; own the WiFi Engineer contract resource and its month-9 decision.
  • Own LAN / WAN architecture and operations — Cisco switching and campus / data-center networking, with routing performed on the Palo Alto firewall platform.
  • Own site-to-site connectivity and inter-site VPN (terminated on the Palo Alto firewalls); own SD-WAN where deployed.
  • Manage internet circuits and carrier / ISP relationships — provisioning, performance, and lifecycle.
  • Own core network services — DNS, DHCP, and IP address management (IPAM).
  • Own hybrid cloud connectivity — the WAN / circuit side of Azure connectivity (ExpressRoute / VPN); the platform and server & cloud functions own the in-cloud network (VNets, NSGs).
  • Own load balancing and application delivery (F5 or equivalent) where deployed.
  • Own enterprise wireless (WLAN) architecture, performance, and operations across all sites.
  • Ensure a reliable, secure wireless experience for staff, executives, and guests.
  • Direct the WiFi Engineer contractor's RF design and remediation work.
  • Own Palo Alto NGFW management — security policy and rule lifecycle, threat prevention (IPS), and URL filtering. The firewalls are also the platform for perimeter / inter-site routing and site-to-site VPN.
  • Implement and operate Zero Trust network architecture, segmentation, 802.1X, and network access control (NAC) — within the enterprise standards set by architecture; partner with the IAM function on identity-driven network access.
  • Own remote access VPN (e.g., Palo Alto GlobalProtect) and SASE / SSE connectivity, in partnership with the managed security services partner.
  • Partner with the cybersecurity function on security incident response and triage — the network and firewall estate is a primary control point and telemetry source.
  • Own VoIP and unified communications across the estate, including Cisco Call Manager (CUCM) administration and operations.
  • Manage dial plans, SIP trunking, PSTN connectivity, and E911 / emergency-calling compliance across sites.
  • Own voice quality of service (QoS) end-to-end, including QoS across the network path.
  • Build backup coverage for the voice / telecom function to remove key-person risk.
  • Own network monitoring, observability, performance management, and capacity planning.
  • Own network resilience — redundancy, failover, and disaster-recovery posture for critical connectivity and voice.
  • Run change management for the network and voice estate; maintain topology and configuration documentation.
  • Own the physical network layer across sites — structured cabling, IDF / MDF, patching, and switch hardware lifecycle.
  • Drive network automation and infrastructure-as-code — Ansible, Python, and platform automation (e.g., Panorama) — to reduce manual change and configuration drift.
  • Manage network and voice vendors, hardware / circuit lifecycle, and renewals; apply AI / AIOps tooling to operations where it adds value.

Benefits

  • health care
  • retirement
  • vacation
  • other paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service