Cisco Network Security Engineer/ Senior Consultant

Deloitte T.T.L.
Los Angeles, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 208K

Job location

Los Angeles, United States of America

Tech stack

Microsoft Access
IEEE 802.1X
API
Amazon Web Services (AWS)
Azure
Profiling
CompTIA Security+
Computer Security
System Configuration
Data Centers
DNS
Intrusion Detection and Prevention
Information Systems Security Architecture Professional
Python
Network Security
Microsoft Security Essentials
Ansible
Zero Trust Network Access
SAP Sales and Distribution
Security Information and Event Management
Systems Integration
Transport Layer Security
Identity Services Engine
Google Cloud Platform
Network Access Control
Cloud Platform System
System Availability
Malware
Firewalls (Computer Science)
Information Technology
Patch Management
Firepower
REST
Terraform
Cisco Switches
Cisco networks

Job description

As a Senior Consultant, Strategy, Growth, and Transformation on the Cyber team, you will be responsible for...

  • Designing, deploying, and managing Cisco Firepower Threat Defense (FTD) and Firepower Management Center (FMC) solutions across enterprise environments, including physical, virtual, and cloud-delivered deployments
  • Implementing and supporting Cisco Identity Services Engine (ISE) capabilities, including 802.1X network access control, device profiling, guest lifecycle management, TrustSec segmentation, and integration with enterprise identity stores
  • Configuring and tuning advanced Cisco security features, including intrusion prevention system (IPS), malware protection, URL filtering, Domain Name System (DNS)-based security, Security Intelligence, and Secure Sockets Layer/Transport Layer Security (SSL/TLS) decryption policies
  • Deploying and integrating Cisco Secure Firewall solutions in cloud environments, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), while supporting centralized policy management and secure connectivity across hybrid infrastructures
  • Developing client-facing security architectures, integrating Cisco platforms with security information and event management (SIEM) tools and automation solutions, and delivering recommendations that align technical requirements, compliance needs, and business objectives

Requirements

  • Ability to design, assess, and troubleshoot enterprise network security environments using Cisco security technologies
  • Ability to implement and manage Cisco Firepower Threat Defense (FTD), Firepower Management Center (FMC), and Identity Services Engine (ISE) solutions
  • Ability to support 802.1X network access control, profiling, guest access, TrustSec segmentation, and policy enforcement requirements
  • Ability to analyze and tune firewall, intrusion prevention system (IPS), Secure Sockets Layer/Transport Layer Security (SSL/TLS) decryption, and threat prevention controls
  • Ability to support secure network and firewall deployments across on-premises, campus, data center, and cloud environments
  • Ability to produce technical assessments, target-state architectures, implementation roadmaps, and executive-ready deliverables
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Ability to provide clear guidance to others

The team, * BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent work experience)

  • CCNP Security or CCIE Security certification required
  • 5+ years of experience in network security engineering with Cisco security technologies
  • 5+ years of experience designing, deploying, and managing Cisco Firepower Threat Defense (FTD) and Firepower Management Center (FMC) in enterprise environments, including physical appliances, virtual instances, and cloud-delivered Firewall Management Center (cdFMC)
  • 5+ years of experience designing and implementing Cisco Identity Services Engine (ISE), including distributed node architectures, high availability configurations, patch management, and upgrade planning
  • 3+ years of experience with Cisco Identity Services Engine (ISE) 802.1X Network Access Control (NAC), guest lifecycle management, profiling policies, TrustSec segmentation, and Cisco Firepower capabilities including intrusion prevention system (IPS), malware protection, Uniform Resource Locator (URL) filtering, Domain Name System (DNS)-based security, Secure Sockets Layer/Transport Layer Security (SSL/TLS) decryption, and cloud firewall deployments in Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP)
  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available., * Additional cybersecurity certifications such as Certified Information Systems Security Professional (CISSP), GIAC Security Essentials (GSEC), or GIAC Certified Enterprise Defender (GCED)
  • Experience with Cisco Secure Access, Cisco Umbrella, Cisco Secure Client, or Duo Security in Zero Trust architectures
  • Experience with Cisco Extended Detection and Response (XDR), Cisco SecureX, or integration of Firepower and Identity Services Engine (ISE) telemetry for threat detection, investigation, and response
  • Experience using Representational State Transfer application programming interfaces (REST APIs), Ansible, Terraform, or Python for policy provisioning, compliance checks, configuration drift detection, or network security automation
  • Experience with Cisco Catalyst Center and Cisco Identity Services Engine (ISE) integration for Software-Defined Access (SD-Access) deployments and segmentation policy enforcement
  • Experience delivering network security, network access control, segmentation, or Zero Trust engagements in consulting environments

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

About the company

Deloitte's Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative approach. We collaborate with teams from across our organization in order to bring the full breadth of Deloitte, its commercial and public sector expertise, to best support our clients. Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Apply for this position