We are looking for a dedicated NAC Security Engineer with deep hands-on expertise in identity-driven network access control and Zero Trust Network Access (ZTNA) architectures.

In this role, you will be responsible for the end-to-end design, implementation, and L3 operational support of enterprise NAC solutions using Aruba ClearPass or Cisco ISE. You will build granular policy frameworks, manage device profiling/posture assessment, automate certificate lifecycles, and enforce dynamic segmentation across wired, wireless, VPN, and IoT environments.

Key Responsibilities

  • NAC Architecture & Policy Engineering: Design and deploy enterprise-grade NAC frameworks across campus, branch, and data center environments. Build role-based access control models using Dynamic VLANs, Downloadable ACLs (dACLs), and Security Group Tags (SGT / Cisco TrustSec).
  • ClearPass / Cisco ISE Administration: Configure, tune, and maintain primary NAC platforms:
    • Aruba ClearPass: Policy Manager, OnGuard (posture), OnBoard (BYOD/PKI), Guest, and Insight.
    • Cisco ISE: Policy sets, profiling, posture assessment, TrustSec/SGT, pxGrid, and Adaptive Network Control (ANC).
  • AAA & Authentication Protocols: Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), TACACS+, and RADIUS frameworks.
  • Identity & PKI Integration: Integrate NAC policy engines with identity repositories (Active Directory, LDAP, Microsoft Entra ID / Azure AD) and enterprise Certificate Authorities (PKI) for seamless certificate-based authentication.
  • Endpoint Profiling & Posture Compliance: Create profiling policies for corporate, unmanaged, and IoT/OT devices; integrate posture checks with MDM/UEM (Intune, Jamf, Workspace ONE) and endpoint security agents.
  • Guest & BYOD Lifecycle Management: Manage self-service guest onboarding portals, sponsor approvals, and automated device enrollment workflows.
  • L3 Operations & Incident Escalation: Provide advanced L3 troubleshooting for RADIUS authentication dropouts, 802.1X mis-hits, posture evaluation failures, and certificate expiration issues.
  • Ecosystem Integrations: Connect NAC platforms with firewalls, SIEM/SOAR platforms (via pxGrid, Syslog, REST APIs), and network infrastructure (Cisco, Aruba, Juniper Mist) for closed-loop threat remediation.

Required Skills & Qualifications

Mandatory Requirements:

  • Experience: 3 to 6 years of network and security engineering experience with a dedicated focus on identity-based access and NAC deployments.
  • Core Platform Expertise: Deep, hands-on configuration experience with either Aruba ClearPass (Policy Manager, OnGuard, OnBoard) or Cisco ISE (Policy Sets, Profiling, Posture, pxGrid, TrustSec).
  • AAA & Protocols: Solid mastery of 802.1X, RADIUS, TACACS+, MAB, captive portal authentication, and EAP protocols (EAP-TLS, PEAP).
  • Role-Based Enforcement: Proven track record implementing dynamic VLAN assignment, downloadable ACLs (dACLs), and Security Group Tagging (SGT).
  • Identity Stores & PKI: Practical integration experience with Active Directory, Azure AD / Microsoft Entra ID, and PKI/CA infrastructures.
  • L3 Troubleshooting: Proven capability to diagnose and resolve complex authentication failures, certificate trust errors, and policy misconfigurations.
  • Networking Fundamentals: Strong foundational knowledge of TCP/IP, switching/routing, VLAN architectures, and Zero Trust security principles.
  • Education: Bachelor’s degree in Computer Science, Information Technology, Electronics, or a related field.

Preferred Qualifications:

  • Certifications: Aruba ACCP / ACMP / ACDP, Cisco CCNP Security (SISE 300-715), CCIE Security, or CISSP.
  • Experience with network automation and orchestration using Python, REST APIs, or Ansible.
  • Exposure to cloud-native/agentless NAC platforms (Arista Agni, Forescout, Portnox, or FortiNAC).

Work Arrangement & Location

  • Work Model: In-Office (5 Days a Week)
  • Location: Bengaluru, Karnataka, India
Job Category: Networking
Job Type: Fulltime
Job Location: Bengaluru - Karnataka

Apply for this position

Allowed Type(s): .pdf, .doc, .docx