| Location | Whippany, NJ |
This role supports a major financial services customer's global network security organization as part of a broader modernization initiative covering NAC, firewalls, IDS/IPS, proxy, remote access, and Zero Trust segmentation.
The engineer will work directly within the customer's existing Forescout and Cisco Client environment to mature how NAC is engineered and operationalized defining engineering standards, uplifting existing policy, closing known security gaps, and identifying automation opportunities. This is fundamentally a hands-on NAC engineering role: the person will need to understand endpoint access control at the mechanism and architecture level.
Key Responsibilities
Engineer, deploy, and operationalize Forescout NAC across enterprise environments, including endpoint discovery, agentless device visibility, profiling, and policy enforcement
Configure and maintain Cisco Client for 802.1X authentication, RADIUS authorization, dynamic VLAN assignment, and downloadable ACLs
Design and support the coexistence and integration of Forescout and Cisco Client within a unified NAC architecture
Define and uplift NAC engineering standards, policies, and operational documentation
Handle non-802.1X-capable endpoints (printers, cameras, IoT, legacy equipment) using MAC Authentication Bypass (MAB), profiling-based classification, and restricted-access policy
Integrate NAC with firewall platforms to align identity/device context with network segmentation and access enforcement
Support Zero Trust initiatives, including continuous posture/compliance verification and least-privilege access design
Identify and implement automation opportunities for NAC policy management and operations, using Python, Ansible, and related tooling
Collaborate with engineering, architecture, operations, and security teams to deliver integrated infrastructure solutions
Participate in incident response, troubleshooting, and root cause analysis for NAC and access-control issues
Ensure adherence to change management, compliance, and operational governance processes
Develop deployment documentation, implementation procedures, operational runbooks, and knowledge-transfer materials
Required Qualifications
Hands-on Forescout experience: deployment, endpoint/device discovery, agentless profiling, policy creation and enforcement, posture/compliance assessment, and unmanaged device identification
Hands-on Cisco Client experience: 802.1X, RADIUS, EAP-TLS, certificate-based authentication, profiling, posture, and policy design
Strong understanding of NAC architecture end-to-end from endpoint connection through discovery, authentication, profiling, posture/compliance, authorization, access decisioning, and continuous monitoring
Demonstrated experience handling non-802.1X devices via MAB, profiling, and restricted-access strategies (not simply MAC whitelisting)
Working knowledge of Zero Trust principles: identity-based access, continuous verification, least privilege, and segmentation
Understanding of how NAC and firewall platforms integrate to jointly enforce identity-, device-, and posture-based access control
Ability to speak to specific, personally-built or personally-modified NAC/Forescout policies
Experience working within formal change-management and incident-management processes
Preferred Qualifications
Experience with Forescout and Cisco Client coexistence/integration in a production environment
PKI/certificate management and Active Directory integration experience
Experience with Security Group Tags (SGT), Cisco TrustSec, and pxGrid
Automation/scripting experience (Python, Ansible, REST APIs, Terraform, GitLab CI/CD)
Complementary firewall experience (Palo Alto, Fortinet, Check Point, Cisco) valuable as a secondary skill, not a substitute for NAC/Forescout depth
SIEM/security operations exposure (Splunk, QRadar) for alerting and incident correlation
Tools and Technologies
Forescout Platform (device visibility, profiling, policy enforcement, compliance)
Cisco Client (802.1X, RADIUS, TrustSec, pxGrid)
Firewall platforms (Palo Alto, Fortinet, Check Point, Cisco) for NAC integration
Zero Trust / segmentation frameworks
Python, Ansible, GitLab CI/CD, REST APIs
ServiceNow / ITIL-based change and incident management