HamburgerMenu
hirist

Job Description

Role Title : NAC Security Engineer

Working Days : 5 Days

Max NP : 30 days

Job Location : Bengaluru

Experience : 36 years

Total CTC : Confidential, ?915 L

Working Model : In-Office

Positions Open : 14

Core Platforms : NAC platforms Aruba ClearPass (Policy Manager, OnGuard, OnBoard, Guest, Insight) / Cisco ISE (policy sets, profiling, posture, TrustSec/SGT, pxGrid, ANC)

Key Responsibilities :

- Design and implement scalable, highly available NAC solutions across campus, branch, data centre, and remote-access environments.

- Develop NAC architecture standards, policy frameworks, HLD/LLD design documents, and deployment runbooks.

- Lead identity-driven access and dynamic segmentation initiatives aligned with Zero Trust Network Access (ZTNA) principles.

- Define authentication, authorization, and enforcement models for wired (802.1X/MAB), wireless, and VPN access.

ClearPass / ISE Expertise :

- Deep hands-on expertise in at least one platform : Aruba ClearPass or Cisco ISE.

- Build and tune service/policy logic, enforcement profiles, and role-mapping for complex multi-site environments.

- Manage platform upgrades, clustering/redundancy, certificate lifecycle, and licensing.

Authentication, Authorization & Policy :

- Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), and web/captive-portal authentication.

- Configure and operate RADIUS and TACACS+ for network access and device administration (AAA).

- Design role-based access using dynamic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role).

- Integrate with identity stores : Active Directory, LDAP, Azure AD / Entra ID, and certificate authorities (PKI).

Profiling, Posture & Endpoint Compliance :

- Implement device profiling and fingerprinting to classify managed, unmanaged, and IoT/OT endpoints.

- Configure posture/compliance assessment and remediation workflows for endpoint health.

- Integrate with MDM/UEM (Intune, Jamf, Workspace ONE) and EDR/AV for compliance signals.

Operations & Support :

- Provide L3 support for complex NAC authentication, policy, and connectivity issues.

- Troubleshoot RADIUS/802.1X failures, certificate issues, and policy mis-hits across environments.

- Perform health checks, capacity planning, and performance tuning of NAC infrastructure.

Mandatory Requirements :

- Strong NAC / Identity-Based Access Specialist Profile with deep ClearPass or Cisco ISE expertise.

- 3+ years in network/security engineering, with a strong focus on NAC and identity-based access.

- Bachelor's degree in Computer Science, IT, or a related field.

- Preferred Certifications : Aruba ACCP / ACMP / ACDP, Cisco CCNP Security / SISE / CCIE Security, CISSP.

- Preferred Automation : Scripting and APIs (Python, REST) for NAC automation.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...