Network Access Control (NAC) Engineer

IS3 Solutions

  • Whippany, NJ
  • 5 days ago

    Highlights

    Position Overview This role supports a major financial services customer's global network security organization as part of a broader modernization initiative covering NAC, firewalls, IDS/IPS, proxy, remote access, and Zero Trust segmentation. Handle non-802.1X-capable endpoints (printers, cameras, IoT, legacy equipment) using MAC Authentication Bypass (MAB), profiling-based classification, and restricted-access policy.

    Numbers & Facts

    LocationWhippany, NJ

    Description

    Position Overview

    This role supports a major financial services customer's global network security organization as part of a broader modernization initiative covering NAC, firewalls, IDS/IPS, proxy, remote access, and Zero Trust segmentation.

    The engineer will work directly within the customer's existing Forescout and Cisco Client environment to mature how NAC is engineered and operationalized defining engineering standards, uplifting existing policy, closing known security gaps, and identifying automation opportunities. This is fundamentally a hands-on NAC engineering role: the person will need to understand endpoint access control at the mechanism and architecture level.

    Key Responsibilities

    • Engineer, deploy, and operationalize Forescout NAC across enterprise environments, including endpoint discovery, agentless device visibility, profiling, and policy enforcement

    • Configure and maintain Cisco Client for 802.1X authentication, RADIUS authorization, dynamic VLAN assignment, and downloadable ACLs

    • Design and support the coexistence and integration of Forescout and Cisco Client within a unified NAC architecture

    • Define and uplift NAC engineering standards, policies, and operational documentation

    • Handle non-802.1X-capable endpoints (printers, cameras, IoT, legacy equipment) using MAC Authentication Bypass (MAB), profiling-based classification, and restricted-access policy

    • Integrate NAC with firewall platforms to align identity/device context with network segmentation and access enforcement

    • Support Zero Trust initiatives, including continuous posture/compliance verification and least-privilege access design

    • Identify and implement automation opportunities for NAC policy management and operations, using Python, Ansible, and related tooling

    • Collaborate with engineering, architecture, operations, and security teams to deliver integrated infrastructure solutions

    • Participate in incident response, troubleshooting, and root cause analysis for NAC and access-control issues

    • Ensure adherence to change management, compliance, and operational governance processes

    • Develop deployment documentation, implementation procedures, operational runbooks, and knowledge-transfer materials

    Required Qualifications

    • Hands-on Forescout experience: deployment, endpoint/device discovery, agentless profiling, policy creation and enforcement, posture/compliance assessment, and unmanaged device identification

    • Hands-on Cisco Client experience: 802.1X, RADIUS, EAP-TLS, certificate-based authentication, profiling, posture, and policy design

    • Strong understanding of NAC architecture end-to-end from endpoint connection through discovery, authentication, profiling, posture/compliance, authorization, access decisioning, and continuous monitoring

    • Demonstrated experience handling non-802.1X devices via MAB, profiling, and restricted-access strategies (not simply MAC whitelisting)

    • Working knowledge of Zero Trust principles: identity-based access, continuous verification, least privilege, and segmentation

    • Understanding of how NAC and firewall platforms integrate to jointly enforce identity-, device-, and posture-based access control

    • Ability to speak to specific, personally-built or personally-modified NAC/Forescout policies

    • Experience working within formal change-management and incident-management processes

    Preferred Qualifications

    • Experience with Forescout and Cisco Client coexistence/integration in a production environment

    • PKI/certificate management and Active Directory integration experience

    • Experience with Security Group Tags (SGT), Cisco TrustSec, and pxGrid

    • Automation/scripting experience (Python, Ansible, REST APIs, Terraform, GitLab CI/CD)

    • Complementary firewall experience (Palo Alto, Fortinet, Check Point, Cisco) valuable as a secondary skill, not a substitute for NAC/Forescout depth

    • SIEM/security operations exposure (Splunk, QRadar) for alerting and incident correlation

    Tools and Technologies

    • Forescout Platform (device visibility, profiling, policy enforcement, compliance)

    • Cisco Client (802.1X, RADIUS, TrustSec, pxGrid)

    • Firewall platforms (Palo Alto, Fortinet, Check Point, Cisco) for NAC integration

    • Zero Trust / segmentation frameworks

    • Python, Ansible, GitLab CI/CD, REST APIs

    • ServiceNow / ITIL-based change and incident management

    Similar Jobs

    See more jobs