Requirements
Bachelor's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or a related discipline. Minimum 4 years of experience in network access control, network security, identity-based access, or enterprise network operations. Hands-on production experience with Cisco ISE, including 802.1X, RADIUS, policy configuration, and endpoint authentication. Strong understanding of AAA, certificates, PKI, RADIUS, TACACS+, switching, wireless integration, and VPN access control. Strong hands-on knowledge of Cisco ISE policy sets, authorization profiles, identity stores, profiling, posture, guest access, and BYOD workflows. Good understanding of 802.1X, MAB, EAP methods, certificate-based authentication, and endpoint onboarding. Professional certification such as CCNP Security, CCIE Security, Cisco ISE specialist certifications, or equivalent. Experience designing or supporting TrustSec / SGT segmentation in enterprise environments. Experience with TACACS+ device administration for network infrastructure access control.
Description
Design, deploy, administer, and optimize network access control services using Cisco Identity Services Engine (ISE) across wired, wireless, and VPN environments. The role is responsible for enforcing identity-based access policies, supporting Zero Trust segmentation, strengthening endpoint access controls, and ensuring secure and reliable user and device onboarding.Design, configure, and administer Cisco ISE services for wired, wireless, and VPN network access control.Implement and support 802.1X authentication, MAC Authentication Bypass (MAB), device profiling, posture assessment, guest access, and BYOD onboarding.Design, maintain, and enforce authorization policies based on user identity, device type, posture status, location, and business requirements.Configure and support TrustSec / Security Group Tag (SGT) policies to enable identity-based segmentation and Zero Trust access controls.Integrate Cisco ISE with Active Directory, PKI/certificate services, RADIUS, TACACS+, MDM platforms, wireless controllers, switches, and VPN services.Troubleshoot authentication, authorization, profiling, posture, certificate, and endpoint onboarding issues across wired, wireless, and remote-access environments.Maintain distributed Cisco ISE deployments, including Policy Administration Nodes (PAN), Monitoring and Troubleshooting Nodes (MnT), and Policy Service Nodes (PSN).Support high availability, backup and restore, patching, upgrades, certificate renewals, and platform health monitoring for Cisco ISE environments.Review access policies, logs, and reports to identify configuration issues, security gaps, and opportunities for improvement.Maintain technical documentation, network access control procedures, operational guides, policy matrices, diagrams, and support handover materials.Collaborate with network, security, infrastructure, endpoint, service desk, and application teams to support secure access and device onboarding.Participate in incident response, root-cause analysis, maintenance windows, audit support, and continuous improvement activities.RequirementsBachelor's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or a related discipline.Minimum 4 years of experience in network access control, network security, identity-based access, or enterprise network operations.Hands-on production experience with Cisco ISE, including 802.1X, RADIUS, policy configuration, and endpoint authentication.Strong understanding of AAA, certificates, PKI, RADIUS, TACACS+, switching, wireless integration, and VPN access control.Strong hands-on knowledge of Cisco ISE policy sets, authorization profiles, identity stores, profiling, posture, guest access, and BYOD workflows.Good understanding of 802.1X, MAB, EAP methods, certificate-based authentication, and endpoint onboarding.Professional certification such as CCNP Security, CCIE Security, Cisco ISE specialist certifications, or equivalent.Experience designing or supporting TrustSec / SGT segmentation in enterprise environments.Experience with TACACS+ device administration for network infrastructure access control.