Cisco Identity Services Engine (ISE) Engineer

Brenham Ready Mix Inc
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$110,000.0 - $132,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access IEEE 802.1X Access Network Active Directory User Authentication Authentication Protocols Profiling Cyber Security Identity and Access Management Network Security Lightweight Directory Access Protocols (LDAP) Public Key Infrastructure
+7 more
Azure Active Directory Systems Integration Identity Services Engine Network Access Control Information Technology 3-tier Architectures TACACS+ Protocol

Job description

BRMi is seeking a Cisco Identity Services Engine (ISE) Engineer to support the design, implementation, administration, and optimization of our enterprise Network Access Control (NAC) environment. This role will be responsible for managing secure network authentication services, troubleshooting complex access issues, and ensuring reliable identity-based access across wired and wireless enterprise networks. The ideal candidate has hands-on experience with Cisco ISE, strong knowledge of authentication protocols and identity integrations, and thrives in a highly regulated enterprise environment with formal change management processes., * Administer, configure, and support Cisco Identity Services Engine (ISE) 2.x and 3.x environments.

  • Design, implement, and maintain Network Access Control (NAC) solutions using Cisco ISE.
  • Configure and maintain authentication and authorization Policy Sets, Conditions, Profiles, and Rules.
  • Support wired and wireless 802.1X authentication deployments.
  • Configure and troubleshoot MAC Authentication Bypass (MAB) for non-802.1X capable devices.
  • Implement and maintain endpoint profiling and posture assessment policies.
  • Support Guest and Bring Your Own Device (BYOD) onboarding solutions.
  • Integrate Cisco ISE with enterprise identity providers including Active Directory, LDAP, and Azure Active Directory.
  • Configure and support authentication protocols including RADIUS, TACACS+, PEAP, EAP-TLS, and EAP-FAST.
  • Perform troubleshooting and root cause analysis for network authentication and access-related issues.
  • Provide Tier 2 and Tier 3 operational support for Cisco ISE and NAC-related incidents.
  • Participate in scheduled on-call support rotations as required.
  • Create and maintain runbooks, standard operating procedures (SOPs), technical documentation, and architecture diagrams.
  • Collaborate with network, infrastructure, security, and identity management teams to implement secure access solutions.
  • Participate in system upgrades, maintenance activities, and infrastructure improvement initiatives.
  • Ensure all work is performed in accordance with established change management and enterprise operational procedures.
  • Manage multiple operational priorities while supporting concurrent projects and initiatives.
  • Perform other duties as assigned

Requirements

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related discipline, or equivalent combination of education and professional experience.
  • 3-5 years of hands-on experience administering Cisco Identity Services Engine (ISE) version 2.x and/or 3.x.
  • Experience implementing and supporting Network Access Control (NAC) solutions using Cisco ISE.
  • Strong understanding of:
  • Authentication and Authorization Policy Sets
  • Policy Conditions, Profiles, and Rules
  • Endpoint Profiling
  • Posture Assessment
  • 802.1X authentication (wired and wireless)
  • MAC Authentication Bypass (MAB)
  • Guest Access and BYOD onboarding
  • Experience integrating Cisco ISE with:
  • Microsoft Active Directory
  • LDAP
  • Azure Active Directory
  • Knowledge of Public Key Infrastructure (PKI) and certificate-based authentication.
  • Experience with EAP authentication methods including PEAP, EAP-TLS, and EAP-FAST.
  • Strong understanding of RADIUS and TACACS+ authentication services.
  • Experience troubleshooting complex authentication and network access issues.
  • Experience working within enterprise environments utilizing formal incident, problem, and change management processes.
  • Strong documentation, analytical, and communication skills.
  • Ability to manage multiple priorities while maintaining high-quality customer support.

Benefits & conditions

4.44.4 out of 5 stars Virginia Remote $110,000 - $132,000 a year - Full-time, Pulled from the full job description

  • Tuition reimbursement
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance
  • Paid holidays, * Comprehensive Medical, Dental, and Vision Insurance
  • Employer-Paid Life Insurance
  • Employer-Paid Short-Term and Long-Term Disability Insurance
  • 401(k)
  • Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays
  • Educational Assistance

Salary: $110K-$132K Can be 100% remote in TX, VA, MD, DC, WV or FL

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

9:33 min

Limiting script execution permissions in Node and package managers

Chris Heilmann +2 · LIVE

47 sec

Profiling native execution calls with async-profiler

Gonzalo Ortiz Jaureguizar Gonzalo Ortiz Jaureguizar · WWC Europe 2026

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

2:17 min

Comparing code profiling with surface level monitoring

Jérôme Vieilledent · LIVE

5:25 min

Identifying candidate profiles for intent engineering role transitions

Videos

See all

Related articles

See all