{"id":1356660,"url":"https://alion.io/job/wme-manager-network-infrastructure","title":"Manager, Network Infrastructure","company":{"id":1780327,"name":"WME","domain":"wmeagency.com","url":"https://alion.io/company/wmeagency","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":6,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-29T05:45:00Z"}},"role":"Leadership","role_family":"Leadership","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Beverly Hills, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":138750,"max":null,"currency":"USD","period":"year","gross":null,"usd_annual":138750},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AIOps","optional":false},{"name":"Ansible","optional":false},{"name":"Azure","optional":false},{"name":"DHCP","optional":false},{"name":"DNS","optional":false},{"name":"IAM","optional":false},{"name":"Palo Alto NGFW","optional":false},{"name":"Python","optional":false},{"name":"VPN","optional":false},{"name":"Wi-Fi","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":true}],"status":"live","first_seen_at":"2026-08-12T00:00:00Z","employer_posted_date":"2026-08-12","last_verified_at":"2026-09-29T09:14:50Z","board_verified":true,"closed_at":null,"days_open":49,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":49},"description":"The Manager, Network Infrastructure leads WME's global network and voice estate - the connectivity, wireless, security, and telephony that every office and every user depends on across eight sites. This is a hands-on technical manager: the role both leads a team of four network and voice engineers and serves as the senior technical authority for the estate, staying close enough to the technology to make architecture and troubleshooting calls, not just manage them.\nThe role owns LAN / WAN and switching, Palo Alto firewall management - the platform WME routes and runs site-to-site connectivity from - enterprise wireless, network security and Zero Trust (802.1X and network access control), core network services (DNS / DHCP / IPAM), site-to-site connectivity and internet circuits, and voice / unified communications including Cisco Call Manager. It runs the network as a dependable service, works hand-in-hand with the cybersecurity function on security incident response and triage, and is the seat that finally puts management and backup coverage around a network and voice function that has carried single points of failure for too long.\nThe role builds and operates within the enterprise network and security architecture standards set by the Principal Enterprise Architect, and partners with the cybersecurity governance function and the managed security services partner on Zero Trust and network security.\nScope & Boundaries\n In scope: people leadership of the global network and voice team; LAN / WAN, switching, Palo Alto firewall management (perimeter, routing, and site-to-site), enterprise wireless, network security (Zero Trust, 802.1X, NAC), segmentation, core network services (DNS / DHCP / IPAM), internet circuits and carrier management, and voice / UC including VoIP and Cisco Call Manager.\nTeam & single-point-of-failure mandate: leads four globally distributed network and voice engineers, and owns the backup-coverage plan that eliminates the documented single points of failure in the network and telecom functions - building bench depth rather than letting coverage default upward.\n Owns the wireless contract resource: the WiFi Engineer (12-month contract) reports to this role, including the month-9 renew / convert / absorb decision.\n Relationship to the Principal Enterprise Architect (#55): builds and operates within the enterprise network, Zero Trust, and security architecture standards #55 sets; owns the engineering and operation, not the enterprise standards.\n Cloud connectivity boundary: this role owns the WAN / circuit side of hybrid cloud connectivity (e.g., Azure ExpressRoute / VPN); the Senior Platform Engineer (#61) and server & cloud function own the in-cloud network (VNets, NSGs, in-cloud routing).\n Partnerships: the cybersecurity function on security incident response and triage; the Sr Manager, GRC (#53) on network security governance and audit; the Senior IAM Engineer (#62) on 802.1X / NAC identity integration; the managed security services partner on Zero Trust connectivity.\nHow This Team Works\nEnterprise IT runs on one idea: operational excellence - infrastructure that just works, problems fixed at the root, and an engineering bar that keeps climbing. The network and voice estate is where users feel that most directly, and this role sets the standard for the team. Six operating foundations describe how the function works, and a Manager here models all six and builds them into the team.\nService management, done right. Runs network and voice as dependable services with clear ownership, SLAs, and root-cause fixes.\nContinual improvement. Uses monitoring, incidents, and performance data to keep raising network reliability and experience.\nAI fluency. Uses AI and AIOps tooling fluently in network operations, and builds that fluency into the team.\nOwnership and documentation. Owns the estate end to end and leaves runbooks, topology documentation, and decision records that reduce key-person risk.\nSecurity and risk by default. Designs Zero Trust, segmentation, and strong access control into the network by default.\n Clarity and influence. Leads a distributed team well, and partners credibly with architecture, security, and the business.\nKey Responsibilities\nResponsibilities group into six pillars across leadership and the network and voice estate.\n1. Team Leadership & People Management\nLead, develop, and grow a team of four globally distributed network and voice engineers - hiring, coaching, performance, and career development.\nOwn on-call, escalation, and coverage models; build backup coverage that eliminates single points of failure in the network and telecom functions.\nSet team priorities and workload across time zones and sites; own the WiFi Engineer contract resource and its month-9 decision.\n2. Network Infrastructure - LAN / WAN & Connectivity\nOwn LAN / WAN architecture and operations - Cisco switching and campus / data-center networking, with routing performed on the Palo Alto firewall platform.\nOwn site-to-site connectivity and inter-site VPN (terminated on the Palo Alto firewalls); own SD-WAN where deployed.\nManage internet circuits and carrier / ISP relationships - provisioning, performance, and lifecycle.\nOwn core network services - DNS, DHCP, and IP address management (IPAM).\nOwn hybrid cloud connectivity - the WAN / circuit side of Azure connectivity (ExpressRoute / VPN); the platform and server & cloud functions own the in-cloud network (VNets, NSGs).\nOwn load balancing and application delivery (F5 or equivalent) where deployed.\n3. Enterprise Wireless\nOwn enterprise wireless (WLAN) architecture, performance, and operations across all sites.\nEnsure a reliable, secure wireless experience for staff, executives, and guests.\nDirect the WiFi Engineer contractor's RF design and remediation work.\n4. Firewall, Network Security & Zero Trust\nOwn Palo Alto NGFW management - security policy and rule lifecycle, threat prevention (IPS), and URL filtering. The firewalls are also the platform for perimeter / inter-site routing and site-to-site VPN.\nImplement and operate Zero Trust network architecture, segmentation, 802.1X, and network access control (NAC) - within the enterprise standards set by architecture; partner with the IAM function on identity-driven network access.\nOwn remote access VPN (e.g., Palo Alto GlobalProtect) and SASE / SSE connectivity, in partnership with the managed security services partner.\nPartner with the cybersecurity function on security incident response and triage - the network and firewall estate is a primary control point and telemetry source.\n5. Voice & Unified Communications\nOwn VoIP and unified communications across the estate, including Cisco Call Manager (CUCM) administration and operations.\nManage dial plans, SIP trunking, PSTN connectivity, and E911 / emergency-calling compliance across sites.\nOwn voice quality of service (QoS) end-to-end, including QoS across the network path.\nBuild backup coverage for the voice / telecom function to remove key-person risk.\n6. Network Management, Operations & Vendor Lifecycle\nOwn network monitoring, observability, performance management, and capacity planning.\nOwn network resilience - redundancy, failover, and disaster-recovery posture for critical connectivity and voice.\nRun change management for the network and voice estate; maintain topology and configuration documentation.\nOwn the physical network layer across sites - structured cabling, IDF / MDF, patching, and switch hardware lifecycle.\nDrive network automation and infrastructure-as-code - Ansible, Python, and platform automation (e.g., Panorama) - to reduce manual change and configuration drift.\nManage network and voice vendors, hardware / circuit lifecycle, and renewals; apply AI / AIOps tooling to operations where it adds value.\nRequired Qualifications\n8+ years in network engineering with progressive responsibility, including team-lead or people-management experience.\nDeep routing and switching - Cisco switching and campus / data-center networking, with routing and site-to-site VPN on Palo Alto firewalls.\nPalo Alto NGFW management - security policy, threat prevention, URL filtering, and firewall-based routing / site-to-site VPN.\nCore network services - DNS, DHCP, and IP address management (IPAM).\nEnterprise wireless (WLAN) design and operations experience.\nNetwork security expertise - Zero Trust network architecture, 802.1X, network access control (NAC), and segmentation.\nRemote access VPN and secure connectivity - GlobalProtect, SASE / SSE, or equivalent.\nVoice / unified communications - VoIP, Cisco Call Manager (CUCM), SIP trunking, PSTN, and E911.\nExperience managing internet circuits and carrier / ISP relationships.\nHybrid cloud networking - Azure ExpressRoute / VPN and hybrid connectivity.\nLoad balancing / application delivery (F5 or equivalent), and network automation / scripting (Ansible, Python, or equivalent).\nExperience partnering with security teams on incident response and triage.\nExperience running distributed / global network operations across multiple sites and time zones.\nPeople management - hiring, developing, and leading engineers, ideally distributed.\nStrong written and verbal communication; demonstrated use of AI tooling in technical work.\nPreferred Qualifications\nCCNP or CCIE (Enterprise); wireless and security specializations a plus.\nPalo Alto Networks certification (PCNSE).\nCisco ISE (NAC) and Zscaler / ZTNA experience.\nSD-WAN design and operations experience.\nAzure networking (AZ-700) or equivalent hybrid-cloud networking experience.\nCisco Unified Communications / Call Manager certification.\nExperience in multi-region, high-availability, or media / entertainment environments.\nPer local requirements and in the interest of transparency, the rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.\nHiring Rate Minimum:\n$138,750 annually (minimum will not fall below the applicable state/local minimum salary thresholds)Hiring Rate Maximum:\n$185,000 annuallyWME is an equal opportunity employer and encourages applications from qualified and eligible candidates regardless of sex, race, disability, age, sexual orientation, or religion or belief.","description_format":"text","description_chars":10668,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Media & Entertainment","Network Security","Content Creation","Digital Media"],"lifecycle":[{"event":"open","at":"2026-09-27T22:39:24Z"}],"liveness":{"score":40,"band":"fade","label":"Fading","p_open":1,"p_active":0.729,"p_room":0.55,"age_days":48,"expected_fill_days":40,"reasons":["conf:2","velocity","win:tail"],"computed_at":"2026-09-29T05:45:00Z"},"pay":{"stated_usd_annual":138750,"is_top_pay":false},"html_url":"https://alion.io/job/wme-manager-network-infrastructure","json_url":"https://alion.io/job/wme-manager-network-infrastructure.json","meta":{"generated_at":"2026-09-30T01:21:45Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":900,"day_limit":5000,"remaining_today":4100,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}