NAC Security Engineer
TalentXO · India
FULL TIME
Job Description
Hiring for a Client - Airowire
Key Responsibilities
- Design and implement scalable NAC solutions across campus, branch, data centre and remote-access environments.
- Develop NAC architecture standards, policy frameworks, HLD/LLD documents and deployment runbooks.
- Drive identity-based access, dynamic segmentation and Zero Trust access initiatives.
- Design authentication and enforcement models for wired 802.1X/MAB , wireless and VPN environments.
- Provide deep hands-on expertise in Aruba ClearPass or Cisco ISE , including policy, profiling, posture, guest/BYOD and platform administration.
- Build and optimize policy logic, enforcement profiles, role mapping, clustering, upgrades, certificates and licensing.
- Implement EAP-TLS, PEAP, EAP-TTLS, MAB, RADIUS and TACACS+ authentication.
- Design role-based access using dynamic VLANs, dACLs and SGT/role-based enforcement .
- Integrate NAC with AD, LDAP, Entra ID/Azure AD, PKI, MDM/UEM, EDR/AV and security ecosystems.
- Implement endpoint profiling, posture assessment, compliance and segmentation for managed, unmanaged and IoT/OT devices.
- Design and manage guest access, BYOD onboarding, captive portals and certificate-based provisioning.
- Integrate NAC with firewalls, SIEM/SOAR, ITSM and threat-intelligence platforms using APIs, pxGrid and syslog.
- Provide L3 support for RADIUS/802.1X failures, certificate issues and policy mis-hits.
- Perform NAC health checks, capacity planning, performance tuning and troubleshooting.
- Maintain NAC architecture, policy matrices, configurations, SOPs and audit documentation.
- Exposure to Forescout, FortiNAC, Portnox or Arista Agni is an added advantage.
Ideal Candidate
Mandatory
- 3+ years of network/security engineering experience with strong NAC and identity-based access expertise.
- Deep hands-on expertise in Aruba ClearPass or Cisco ISE .
- Strong L3 troubleshooting experience covering RADIUS, 802.1X, certificates and NAC policy issues .
- Experience with policy design, enforcement profiles, role mapping, clustering, upgrades, certificates and licensing.
- Strong knowledge of 802.1X, EAP-TLS/PEAP/EAP-TTLS, MAB, RADIUS and TACACS+ .
- Experience with dynamic VLANs, dACLs, SGT/role-based access and dynamic segmentation .
- Hands-on experience integrating AD, LDAP, Entra ID/Azure AD and PKI .
- Experience with device profiling, posture assessment and IoT/OT endpoint segmentation .
- Strong networking fundamentals across TCP/IP, VLANs, wired/wireless networks and Zero Trust principles .
- Bachelor's degree in Computer Science, IT or a related field .
Preferred
- Aruba ACCP / ACMP / ACDP
- Cisco CCNP Security / SISE / CCIE Security
- CISSP
- Python/REST API scripting for NAC automation
- Exposure to cloud-native/agentless NAC platforms such as Forescout, Portnox, FortiNAC or Arista Agni
