IAM Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
- Design and build the captive portal / splash page authentication flow, integrating with Microsoft Entra ID as the identity provider (SAML or OAuth/OIDC).
- Configure Conditional Access policies in Entra ID to enforce MFA push notification on wireless sign-on.
- Reconfigure existing wireless infrastructure at the Herndon, VA site (Cisco C9130AXI-B APs) to support the new authentication flow.
- Plan and execute a greenfield wireless deployment at the Maryland site, including RF design and installation of 8 new access points.
- Build and validate NAC policies (if ISE path is chosen), including device profiling, guest/BYOD carve-outs, and failover/fallback authentication scenarios.
- Conduct pilot testing with a small user group prior to full rollout; troubleshoot edge cases (non-domain devices, personal phones, shared workstations).
- Document high-level design (HLD), low-level design (LLD), and standard operating procedures for ongoing support.
- Provide hypercare support post-deployment, including monitoring, tuning, and knowledge transfer to the client’s internal IT/network team.
- Coordinate site logistics and installation windows with client stakeholders and the project manager.
Requirements
- 5+ years of experience in enterprise wireless network engineering (Cisco Meraki and/or Cisco Catalyst/Aironet platforms).
- Hands-on experience with Cisco ISE (policy sets, authentication/authorization policies, NAC)
- Demonstrated experience integrating network authentication with a cloud identity provider Microsoft Entra ID / Azure AD strongly preferred.
- Working knowledge of SAML, OAuth 2.0/OIDC, and Conditional Access policy configuration.
- Experience designing and deploying MFA-enforced authentication flows (push-based, e.g., Microsoft Authenticator).
- Practical RF design experience site survey, AP placement, channel/power planning for greenfield deployments.
- Comfortable working independently on-site for physical AP installation and cabling coordination with facilities/electricians as needed.
- Strong documentation skills (HLD/LLD, runbooks).
- Ability to work within compliance-driven timelines (audit-driven deadlines, defined go-live dates).
Preferred Qualifications
- Certifications: CCNP Enterprise/Security, Cisco ISE SISE, Meraki CMNA/CMNO, or Microsoft SC-300 (Identity and Access Administrator).
- Prior experience supporting a defense/aerospace client environment (e.g., client supply chain compliance requirements).
- Experience with a phased rollout methodology (Discovery ? Design ? Build ? Pilot ? Deploy ? Hypercare).
- Familiarity with 802.1X, EAP-TLS/PEAP, and certificate-based authentication as a fallback design option.
About the company
We are seeking a Wireless & Identity Security Engineer to design, build, and deploy a secure wireless onboarding solution that integrates enterprise Wi-Fi authentication with Microsoft Entra ID (Azure AD) and enforces multi-factor authentication (MFA) at the network edge. This role blends wireless infrastructure engineering Cisco Catalyst Center + ISE) with identity federation engineering (SAML/OAuth, Conditional Access policy design). The successful candidates will be equally comfortable configuring RF/AP hardware in the field and building identity provider integrations in a lab.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
The Overflow: Security and Privacy
Dev Digest 134 - Where pixels sing?