Principal Analyst (Architect), Enterprise Networking & Telecom
1 day ago
Ohio Township
Job Description Our mission is to create the Experience of a Lifetime for our employees, so they can, in turn, create the Experience of a Lifetime for our guests. We own and operate the most renowned destination resorts in the world as well as regional and local ski areas outside major cities, and connect them all through one unrivaled network. We are looking for ambitious leaders, innovators and creators to join our talented team. If you’re ready to pursue your fullest potential, we want to get to know you! Candidates for year-round positions are reviewed on a rolling basis. Applications will be accepted up to 90 days after the posting date, or until the position is filled (whichever is first). Job Summary: The Principal Analyst, Enterprise Networking & Telecom, will act as the technical leader for enterprise networking and telecom, shaping architecture and strategy across hybrid datacenters, multi-cloud, and edge environments. This hire will oversee migrations, set standards, and mentor engineering teams on technologies such as Avaya telephony, CSaaS/CCaaS, SASE (Cato), Check Point firewalls, Cisco Nexus, Extreme Fabric, Azure, disaster recovery, and network automation. The Principal Analyst will lead the transition of contact centers to a cloud-native Genesys platform, managing the migration from legacy systems and integrating AI-driven features like intelligent routing, speech analytics, and automated quality assurance. This person will collaborate on compliance, data residency, and security, ensuring all regulatory requirements are met and teams are empowered to maximize new capabilities. In addition, they will guide international compliance for contact center voice, recording, data residency, and lawful intercept policies. Job Specifications: • Starting Wage: $104,000 - $156,000 + annual bonus, • Employment Type: Year Round, • Minimum Age: At least 18 years of age, • Housing Availability: No Job Responsibilities: Architecture & Strategy: • Set multi-year architectures for WAN/LAN/Voice/Cloud/SASE across Azure, AWS, and/or GCP; standardize hub-and-spoke/vWAN/Transit Gateway/Cloud WAN patterns and inter- cloud routing., • Define DR and business continuity patterns for network and voice (active/active DCs, cloud failover, SBC survivability, carrier diversity, ExpressRoute/Direct Connect failover)., • Create standards for addressing, segmentation, BGP/EVPN, QoS, SIP call flows, SBC/SIP trunks, Internet egress, cross-cloud connectivity, and data residency. Solution Design & Delivery: • Lead designs for: Cato SASE policy & topology; Check Point (policy as code, IPSec/SSL VPN, clustering); Cisco Nexus leaf-spine/EVPN-VXLAN; Extreme Fabric segmentation; Azure vWAN/Firewall/ER, AWS TGW/Cloud WAN, GCP NCC, Private Link/Endpoint services; DNS and L7/L4 LB across clouds; inter-cloud routing and failover., • Own call control architectures: Avaya CM/SM/SMGR/SBC, SIP trunking, global routing with regional breakouts, E911/NG911, survivability, and CSaaS/CCaaS integrations (QoS, WFM/QA/analytics)., • Drive strategy for seamless migration of on-premises Avaya voice systems to cloud AI- powered contact center platforms, ensuring robust planning, effective stakeholder alignment, and optimal utilization of modern AI-driven features for enhanced customer engagement and operational excellence., • Drive micro segmentation (host- and fabric-based) aligned to identity and zero trust., • International CC compliance: design call recording/redaction, storage, encryption, data residency controls, retention, DLP, and lawful disclosure workflows across regions; align to PCI-DSS, GDPR, UK DPA, LGPD, and local telecom rules; document country-specific constraints (e.g., call recording consent models, toll-free usage, CLI rules)., • Observability: global telemetry (NetFlow/IPFIX), synthetic testing, MOS/RTT analytics, SIP ladder traces, DEM—correlated across regions/clouds. Security, Reliability & Compliance: • Partner with Security on zero-trust zone models, least-privilege access, threat prevention, and incident response runbooks spanning on-prem and multi-cloud., • Architect HA/DR for network and voice: RTO/RPO targets, failover runbooks, scheduled game-days, and automated validation., • Ensure adherence to corporate/regulatory standards; produce DPIA/ROPA inputs for international contact center operations; maintain audit-ready artifacts. Automation & IaC: • Establish network/voice as code across clouds and platforms: Git, CI/CD, testing, drift detection, policy guardrails., • Build reusable modules and pipelines (Terraform/Ansible/Python) for Cato, Check Point, Azure/AWS/GCP networking, Extreme, and Nexus; integrate with ITSM/CMDB for request-to-deploy and inventory. Leadership & Enablement: • Act as domain authority and Tier-3 escalation for complex incidents., • Mentor engineers; run architecture councils; align Infra, Security, Cloud, Contact Center,, • Legal/Privacy, and regional stakeholders., • Vendor management: evaluate platforms, negotiate capabilities/roadmaps, and drive outcomes with carriers/SBCs/CSaaS providers globally. Required qualifications: • 10+ years in enterprise networking/voice; 3–5 years in an architecture/principal role delivering large-scale, multi-region designs., • Deep expertise in several and operational familiarity with the rest:, • Telecom/Voice: Avaya (CM/SM/SMGR), Genesys, SBCs/SIP trunks, E911/NG911, recording/compliance, CCaaS/CSaaS integrations., • SASE: Cato Networks (topology, policy, SWG/CASB/DLP), large-scale user/site onboarding., • Firewalls/Security: Check Point policy design, VPN, IPS, clustering, policy-as-code., • Datacenter: Cisco Nexus (EVPN/VXLAN), leaf-spine, vPC/MLAG, QoS, multicast (as needed)., • Campus/Fabric: Extreme Fabric Connect (SPB/IS-IS), macro/micro-seg., • Cloud Networking: Azure vWAN/Hub-Spoke/Firewall/ER, AWS TGW/Cloud WAN/Direct Connect, GCP NCC/VPC; Private Link/Endpoints; cross-cloud routing and inter-cloud resilience., • DR/BCP: Network and voice DR design (active/active, warm standby, SBC/carrier failover), RTO/RPO planning and validation., • Compliance (Contact Center): Experience aligning recording, storage, consent, retention, encryption, and access controls with PCI-DSS and international data protection laws (e.g., GDPR) and country telecom rules., • Certifications (nice to have): CCNP/CCIE (Enterprise/DC), Check Point CCSE/CCSM, Extreme ECS/ECSE, AWS Advanced Networking, GCP Network Engineer, Azure Network Engineer, Avaya ACSS/ACSA, ITIL., • Experience with global carriers, number management, and regional PSTN rules., • Exposure to DEM/observability (ThousandEyes/Catchpoint), call-quality analytics, and dataset design for QoE. The expected Total Compensation for this role is $104,000 - $156,000 + annual bonus. Individual compensation decisions are based on a variety of factors. Job Benefits • Ski/Mountain Perks! Free passes for employees, employee discounted lift tickets for friends and family AND free ski lessons, • MORE employee discounts on lodging, food, gear, and mountain shuttles, • 401(k) Retirement Plan, • Employee Assistance Program, • Health Insurance; Medical Insurance, Dental Insurance, and Vision Insurance plans (for eligible seasonal employees after working 500 hours), • Free ski passes for dependents, • Critical Illness and Accident plans Vail Resorts offers a ‘Hybrid’ work environment where employees living within 50 miles of the Broomfield office work on-site Tuesday, Wednesday, Thursday and have flexibility to work off-site on Mondays and Fridays. Employees living outside of a commutable distance can work remotely from British Columbia, Washington D.C., and the 16 U.S. states* in which we currently operate. This includes: California, Colorado, Indiana, Michigan, Minnesota, Missouri, New Hampshire, New York, Nevada, Ohio, Pennsylvania, Utah, Vermont, Washington State, Wisconsin, and Wyoming. Please note that the ability to work in person or off-site, and the particulars related to such work, are subject to change at any time; and, accordingly, the Company reserves the right to change its policies and/or require in-person/in-office work or off-site work at any time in its sole discretion. In completing this application, and when submitting related documentation, applicants may redact information that identifies their age, date of birth, and/or dates of attendance at or graduation from an educational institution. We follow all federal, state, and local laws including restrictions on child/minor labor. Minors hired into this position will not be asked or permitted to engage in any activities restricted to adult workers. Vail Resorts is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status or any other status protected by applicable law. Requisition ID 510998 Reference Date: 08/26/2025 Job Code Function: Applications