HamburgerMenu
hirist

NAC Security Engineer - Entra ID/VLAN

Laksh Consultants
3 - 6 Years
Bangalore

Posted on: 26/08/2026

Job Description

Position : NAC Security Engineer

Overall/Total Experience : 3-6 years only

Location : Bengaluru

Working Days : 5 Days Working from Office

Notice Period Requirement : 30 Days (Maximum)

Client's Company Size : Mid-Sized

Key Responsibilities :

- Design and implement scalable, highly available NAC solutions across campus, branch, data center, and remote-access environments.

- Develop NAC architecture standards, policy frameworks, HLD/LLD design documents, and deployment runbooks.

- Define authentication, authorization, and enforcement models for wired (802.1X/MAB), wireless, and VPN access.

- Deep hands-on expertise in at least one platform:

1. Aruba ClearPass Policy Manager, OnGuard (posture), OnBoard (BYOD / certificate provisioning), Guest, and Insight.

2. Cisco ISE policy sets, profiling, posture, TrustSec/SGT, pxGrid, and Adaptive Network Control (ANC).

- Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), and web/captive-portal authentication.

- Configure and operate RADIUS and TACACS+ for network access and device administration (AAA).

- Design role-based access using dynamic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role).

- Integrate with identity stores: Active Directory, LDAP, Azure AD / Entra ID, and certificate authorities (PKI).

- Implement device profiling and fingerprinting to classify managed, unmanaged, and IoT/OT endpoints.

- Integrate with MDM/UEM (Intune, Jamf, Workspace ONE) and EDR/AV for compliance signals.

- Implement BYOD onboarding and certificate-based provisioning (EAP-TLS).

Candidate Requirements :

- Must have 3+ years in network/security engineering, with a strong focus on NAC and identity-based access.

- Must have L3 support experience troubleshooting RADIUS/802.1X failures, certificate issues, and policy mis-hits, plus health checks, capacity planning, and performance tuning of NAC infrastructure.

- Must have deep hands-on expertise with at least one leading NAC platform Aruba ClearPass (Policy Manager, OnGuard, OnBoard, Guest, Insight) or Cisco ISE (policy sets, profiling, posture, TrustSec/SGT, pxGrid, ANC).

- Must have strong working knowledge of 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAB, web/captive-portal authentication, RADIUS, and TACACS+ (AAA).

- Must have experience designing role-based access using dynamic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role).

- Must have experience integrating with identity stores Active Directory, LDAP, Azure AD / Entra ID and PKI / certificate-based authentication (EAP-TLS).

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...