We are looking for a dedicated NAC Security Engineer with deep hands-on expertise in identity-driven network access control and Zero Trust Network Access (ZTNA) architectures.
In this role, you will be responsible for the end-to-end design, implementation, and L3 operational support of enterprise NAC solutions using Aruba ClearPass or Cisco ISE. You will build granular policy frameworks, manage device profiling/posture assessment, automate certificate lifecycles, and enforce dynamic segmentation across wired, wireless, VPN, and IoT environments.
Key Responsibilities
- NAC Architecture & Policy Engineering: Design and deploy enterprise-grade NAC frameworks across campus, branch, and data center environments. Build role-based access control models using Dynamic VLANs, Downloadable ACLs (dACLs), and Security Group Tags (SGT / Cisco TrustSec).
- ClearPass / Cisco ISE Administration: Configure, tune, and maintain primary NAC platforms:
- Aruba ClearPass: Policy Manager, OnGuard (posture), OnBoard (BYOD/PKI), Guest, and Insight.
- Cisco ISE: Policy sets, profiling, posture assessment, TrustSec/SGT, pxGrid, and Adaptive Network Control (ANC).
- AAA & Authentication Protocols: Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), TACACS+, and RADIUS frameworks.
- Identity & PKI Integration: Integrate NAC policy engines with identity repositories (Active Directory, LDAP, Microsoft Entra ID / Azure AD) and enterprise Certificate Authorities (PKI) for seamless certificate-based authentication.
- Endpoint Profiling & Posture Compliance: Create profiling policies for corporate, unmanaged, and IoT/OT devices; integrate posture checks with MDM/UEM (Intune, Jamf, Workspace ONE) and endpoint security agents.
- Guest & BYOD Lifecycle Management: Manage self-service guest onboarding portals, sponsor approvals, and automated device enrollment workflows.
- L3 Operations & Incident Escalation: Provide advanced L3 troubleshooting for RADIUS authentication dropouts, 802.1X mis-hits, posture evaluation failures, and certificate expiration issues.
- Ecosystem Integrations: Connect NAC platforms with firewalls, SIEM/SOAR platforms (via pxGrid, Syslog, REST APIs), and network infrastructure (Cisco, Aruba, Juniper Mist) for closed-loop threat remediation.
Required Skills & Qualifications
Mandatory Requirements:
- Experience: 3 to 6 years of network and security engineering experience with a dedicated focus on identity-based access and NAC deployments.
- Core Platform Expertise: Deep, hands-on configuration experience with either Aruba ClearPass (Policy Manager, OnGuard, OnBoard) or Cisco ISE (Policy Sets, Profiling, Posture, pxGrid, TrustSec).
- AAA & Protocols: Solid mastery of 802.1X, RADIUS, TACACS+, MAB, captive portal authentication, and EAP protocols (EAP-TLS, PEAP).
- Role-Based Enforcement: Proven track record implementing dynamic VLAN assignment, downloadable ACLs (dACLs), and Security Group Tagging (SGT).
- Identity Stores & PKI: Practical integration experience with Active Directory, Azure AD / Microsoft Entra ID, and PKI/CA infrastructures.
- L3 Troubleshooting: Proven capability to diagnose and resolve complex authentication failures, certificate trust errors, and policy misconfigurations.
- Networking Fundamentals: Strong foundational knowledge of TCP/IP, switching/routing, VLAN architectures, and Zero Trust security principles.
- Education: Bachelor’s degree in Computer Science, Information Technology, Electronics, or a related field.
Preferred Qualifications:
- Certifications: Aruba ACCP / ACMP / ACDP, Cisco CCNP Security (SISE 300-715), CCIE Security, or CISSP.
- Experience with network automation and orchestration using Python, REST APIs, or Ansible.
- Exposure to cloud-native/agentless NAC platforms (Arista Agni, Forescout, Portnox, or FortiNAC).
Work Arrangement & Location
- Work Model: In-Office (5 Days a Week)
- Location: Bengaluru, Karnataka, India
Job Category: Networking
Job Type: Fulltime
Job Location: Bengaluru - Karnataka