> Markdown version of [/jobs/ext/2256793-iam-security-engineer](https://www.wearedevelopers.com/jobs/ext/2256793-iam-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Security Engineer - **Company:** Cisco Systems, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Microsoft Access, IEEE 802.1X, User Authentication, Configuration Management, Software Design Documents, Push Technology, OAuth, OpenID, Performance Tuning, Azure Active Directory, Runbook, Security Assertion Markup Language (SAML), Systems Integration, Wireless Access Point, Wireless Networks, Identity Services Engine, Build Management, Cisco Switches, Cisco - **Published:** August 26, 2026 - **Apply:** https://www.dice.com/job-detail/77a506f1-d4ad-4dcd-88ce-f3f2621a2868 ## About the Role * 5+ years of experience in enterprise wireless network engineering (Cisco Meraki and/or Cisco Catalyst/Aironet platforms). * Hands-on experience with Cisco ISE (policy sets, authentication/authorization policies, NAC) * Demonstrated experience integrating network authentication with a cloud identity provider Microsoft Entra ID / Azure AD strongly preferred. * Working knowledge of SAML, OAuth 2.0/OIDC, and Conditional Access policy configuration. * Experience designing and deploying MFA-enforced authentication flows (push-based, e.g., Microsoft Authenticator). * Practical RF design experience site survey, AP placement, channel/power planning for greenfield deployments. * Comfortable working independently on-site for physical AP installation and cabling coordination with facilities/electricians as needed. * Strong documentation skills (HLD/LLD, runbooks). * Ability to work within compliance-driven timelines (audit-driven deadlines, defined go-live dates). Preferred Qualifications * Certifications: CCNP Enterprise/Security, Cisco ISE SISE, Meraki CMNA/CMNO, or Microsoft SC-300 (Identity and Access Administrator). * Prior experience supporting a defense/aerospace client environment (e.g., client supply chain compliance requirements). * Experience with a phased rollout methodology (Discovery ? Design ? Build ? Pilot ? Deploy ? Hypercare). * Familiarity with 802.1X, EAP-TLS/PEAP, and certificate-based authentication as a fallback design option. ## Description * Design and build the captive portal / splash page authentication flow, integrating with Microsoft Entra ID as the identity provider (SAML or OAuth/OIDC). * Configure Conditional Access policies in Entra ID to enforce MFA push notification on wireless sign-on. * Reconfigure existing wireless infrastructure at the Herndon, VA site (Cisco C9130AXI-B APs) to support the new authentication flow. * Plan and execute a greenfield wireless deployment at the Maryland site, including RF design and installation of 8 new access points. * Build and validate NAC policies (if ISE path is chosen), including device profiling, guest/BYOD carve-outs, and failover/fallback authentication scenarios. * Conduct pilot testing with a small user group prior to full rollout; troubleshoot edge cases (non-domain devices, personal phones, shared workstations). * Document high-level design (HLD), low-level design (LLD), and standard operating procedures for ongoing support. * Provide hypercare support post-deployment, including monitoring, tuning, and knowledge transfer to the client's internal IT/network team. * Coordinate site logistics and installation windows with client stakeholders and the project manager. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)