Posted on: 26/08/2026
Position : NAC Security Engineer
Overall/Total Experience : 3-6 years only
Location : Bengaluru
Working Days : 5 Days Working from Office
Notice Period Requirement : 30 Days (Maximum)
Client's Company Size : Mid-Sized
Key Responsibilities :
- Design and implement scalable, highly available NAC solutions across campus, branch, data center, and remote-access environments.
- Develop NAC architecture standards, policy frameworks, HLD/LLD design documents, and deployment runbooks.
- Define authentication, authorization, and enforcement models for wired (802.1X/MAB), wireless, and VPN access.
- Deep hands-on expertise in at least one platform:
1. Aruba ClearPass Policy Manager, OnGuard (posture), OnBoard (BYOD / certificate provisioning), Guest, and Insight.
2. Cisco ISE policy sets, profiling, posture, TrustSec/SGT, pxGrid, and Adaptive Network Control (ANC).
- Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), and web/captive-portal authentication.
- Configure and operate RADIUS and TACACS+ for network access and device administration (AAA).
- Design role-based access using dynamic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role).
- Integrate with identity stores: Active Directory, LDAP, Azure AD / Entra ID, and certificate authorities (PKI).
- Implement device profiling and fingerprinting to classify managed, unmanaged, and IoT/OT endpoints.
- Integrate with MDM/UEM (Intune, Jamf, Workspace ONE) and EDR/AV for compliance signals.
- Implement BYOD onboarding and certificate-based provisioning (EAP-TLS).
Candidate Requirements :
- Must have 3+ years in network/security engineering, with a strong focus on NAC and identity-based access.
- Must have L3 support experience troubleshooting RADIUS/802.1X failures, certificate issues, and policy mis-hits, plus health checks, capacity planning, and performance tuning of NAC infrastructure.
- Must have deep hands-on expertise with at least one leading NAC platform Aruba ClearPass (Policy Manager, OnGuard, OnBoard, Guest, Insight) or Cisco ISE (policy sets, profiling, posture, TrustSec/SGT, pxGrid, ANC).
- Must have strong working knowledge of 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAB, web/captive-portal authentication, RADIUS, and TACACS+ (AAA).
- Must have experience designing role-based access using dynamic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role).
- Must have experience integrating with identity stores Active Directory, LDAP, Azure AD / Entra ID and PKI / certificate-based authentication (EAP-TLS).
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1666308