Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Dice.com

Senior Network Security Engineer

Career Insights for Cyber Security Engineer

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Maryland data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.

$118,693 / year median in Maryland

+0% projected growth

Explore Career

Job Description

Senior Network Security Engineer Skills
    NIST 800-53
    • FISMA
    • IT Management
    • Switches
    • Firewall
    • WLAN
    • Telecommunications
    • Network Security
    • Communication
    • NAC
    • Information Technology
    • Cyber Security
    • Cisco Certifications
    • RADIUS
    • High Availability
    • Mapping
    • Collaboration
    • Wireless Communication
    • Onboarding
    • Access Control
    • Active Directory
    • LDAP
    • Workflow
    • Cisco
    • Authorization
    • TACACS+
    IEEE 802.1X
    • Wireless Networking
    • PKI
    • ISE
    • Root Cause Analysis
    • Authentication
    • Management
    • User Experience
    • Migration
    • Regulatory Compliance
    • Mentorship
    • Knowledge Sharing
    • IMG
    • SAINT
    • Technical Direction
    NIST 800-53
    • FISMA
    • IT Management
    • Switches
    • Firewall
    • WLAN
    • Telecommunications
    • Network Security
    • Communication
    • NAC
    • Information Technology
    • Cyber Security
    • Cisco Certifications
    • RADIUS
    • High Availability
    • Mapping
    • Collaboration
    • Wireless Communication
    • Onboarding
    • Access Control
    • Active Directory
    • LDAP
    • Workflow
    • Cisco
    • Authorization
    • TACACS+
    IEEE 802.1X
    • Wireless Networking
    • PKI
    • ISE
    • Root Cause Analysis
    • Authentication
    • Management
    • User Experience
    • Migration
    • Regulatory Compliance
    • Mentorship
    • Knowledge Sharing
    • IMG
    • SAINT
    • Technical Direction
    • Summary
    • Role:
    • Sr Network Security Engineer
    • Location:
    • Suitland, MD
    • 100% onsite, 5 days/week Long Term Contract.
    • About the role
    • The agency is moving off its legacy ForeScout Counter
    ACT NAC/NAM
    platform and onto Cisco ISE as its new access-control system. This engineer will configure and manage Cisco ISE across the environment
    • AAA services, wired/wireless 802.1X authentication, device administration, and posture checks
    • and will support the ForeScout-to-ISE migration, troubleshoot access issues, and strengthen identity-based access controls as part of the agency's Zero Trust modernization work.
    • Must-Haves (candidates must meet ALL of these
    • please confirm before submitting)
    • ship (Public Trust position)
    • Public Trust eligible; active Public Trust is a plus
    • Willing and able to work 100% onsite in Suitland, MD, 5 days/week
    • 8+ years of total network/security experience
    • 4+ years of hands-on Cisco ISE experience
    • Bachelor's degree in IT, Cybersecurity, or a related field (or equivalent experience)
    • Strong Plus
    • Hands-on experience with ForeScout CounterACT (NAC/NAM policies, device classification, access workflows)
    • this is a major differentiator given the migration project
    • Cisco ISE deployed on
    SNS-3715
    appliances in a clustered, high-availability setup
    • Experience with Cisco 9800 Wireless LAN Controllers (guest/registration portals, wireless onboarding)
    • CCNP Security, CCIE Security, or Cisco ISE Specialist certification
    • Prior technical leadership in a large federal/government environment; familiarity with
    NIST 800-53, FISMA
    Tria Federal is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy ForeScout Counter
    ACT NAC/NAM
    system and adopts Cisco Identity Services Engine (ISE) as the new accesscontrol platform. The engineer will help configure and manage Cisco ISE across the environment, handling AAA services, wired and wireless 802.1X authentication, device administration, and posture checks for users and devices. This role also supports the agency's modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from ForeScout to Cisco ISE. Basic Requirements Senior Network Security Engineer responsible for designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform, including
    TACACS+/RADIUS
    services, device administration policies, and wired/wireless 802.1X authentication. Experience working with Cisco ISE deployed on Cisco SNS3715 appliances, preferably in a twonode clustered, highavailability setup. Understanding of ForeScout CounterACT, including legacy NAC/NAM policies, device classification, and access workflows, to support the migration to Cisco ISE. Experience providing general wireless network support, including basic troubleshooting, controller interactions, and wireless access workflows. Handson experience integrating Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, groupbased policy decisions, and directorybased authentication. Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE with expertise in: o Authentication and authorization policies (RADITACACS+) o 802.1X/EAP methods for wireless and wired access o Device profiling, posture checks, and endpoint compliance o Certificatebased authentication (EAPTLS) and PKI integration o AAA integrations for switches, appliances, firewalls, and wireless controllers Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers, including guest/registration page redirection and wireless onboarding. Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE while aligning with Zero Trust principles. Four (4) years of experience supporting identitycentric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls. Solid understanding of telecommunications, network security, and Zero Trust best practices. Strong communication skills with the ability to explain Cisco ISE, NAC/NAM, and AAA concepts to both technical and nontechnical audiences. Bachelor's degree in Information Technology, Cybersecurity, or a related field.
    Preferred certifications:
    Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certifications. Responsibilities Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication. Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS3715 appliances, ensuring high availability and consistent policy enforcement. Support the agency's migration from ForeScout CounterACT to Cisco ISE, including reviewing legacy ForeScout policies, device groups, and access rules and mapping them into ISE policy sets. Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams. Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policydriven access control. Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, groupbased authorization, and directorybased authentication workflows. Deploy, configure, and maintain Cisco ISE components, including: o Policy Sets, Authorization Profiles, and Authentication Rules o TACACS+ device administration o 802.1X for wired and wireless networks o Profiling, posture, and compliance policies o Certificatebased authentication and PKI integrations Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues. Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience. Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures. Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts. Sandip Kumar Sr.
    Tech Recruiter Email:
    Address:
    505 Knolle Court Saint Augustine, FL 32092
    Telephone:
    +1 Employers have access to artificial intelligence language tools ("AI") that help generate and enha... Visit the Employer site for more details