Posted on: 26/08/2026
Role Title : NAC Security Engineer
Working Days : 5 Days
Max NP : 30 days
Job Location : Bengaluru
Experience : 36 years
Total CTC : Confidential, ?915 L
Working Model : In-Office
Positions Open : 14
Core Platforms : NAC platforms Aruba ClearPass (Policy Manager, OnGuard, OnBoard, Guest, Insight) / Cisco ISE (policy sets, profiling, posture, TrustSec/SGT, pxGrid, ANC)
Key Responsibilities :
- Design and implement scalable, highly available NAC solutions across campus, branch, data centre, and remote-access environments.
- Develop NAC architecture standards, policy frameworks, HLD/LLD design documents, and deployment runbooks.
- Lead identity-driven access and dynamic segmentation initiatives aligned with Zero Trust Network Access (ZTNA) principles.
- Define authentication, authorization, and enforcement models for wired (802.1X/MAB), wireless, and VPN access.
ClearPass / ISE Expertise :
- Deep hands-on expertise in at least one platform : Aruba ClearPass or Cisco ISE.
- Build and tune service/policy logic, enforcement profiles, and role-mapping for complex multi-site environments.
- Manage platform upgrades, clustering/redundancy, certificate lifecycle, and licensing.
Authentication, Authorization & Policy :
- Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), and web/captive-portal authentication.
- Configure and operate RADIUS and TACACS+ for network access and device administration (AAA).
- Design role-based access using dynamic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role).
- Integrate with identity stores : Active Directory, LDAP, Azure AD / Entra ID, and certificate authorities (PKI).
Profiling, Posture & Endpoint Compliance :
- Implement device profiling and fingerprinting to classify managed, unmanaged, and IoT/OT endpoints.
- Configure posture/compliance assessment and remediation workflows for endpoint health.
- Integrate with MDM/UEM (Intune, Jamf, Workspace ONE) and EDR/AV for compliance signals.
Operations & Support :
- Provide L3 support for complex NAC authentication, policy, and connectivity issues.
- Troubleshoot RADIUS/802.1X failures, certificate issues, and policy mis-hits across environments.
- Perform health checks, capacity planning, and performance tuning of NAC infrastructure.
Mandatory Requirements :
- Strong NAC / Identity-Based Access Specialist Profile with deep ClearPass or Cisco ISE expertise.
- 3+ years in network/security engineering, with a strong focus on NAC and identity-based access.
- Bachelor's degree in Computer Science, IT, or a related field.
- Preferred Certifications : Aruba ACCP / ACMP / ACDP, Cisco CCNP Security / SISE / CCIE Security, CISSP.
- Preferred Automation : Scripting and APIs (Python, REST) for NAC automation.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Networking & Wireless
Job Code
1666170