> Markdown version of [/jobs/ext/2298825-network-engineer-3-forescout-cisco-ise](https://www.wearedevelopers.com/jobs/ext/2298825-network-engineer-3-forescout-cisco-ise). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Engineer 3 - Forescout/Cisco ISE - **Company:** Federal Advisory Partners - **Location:** Suitland-Silver Hill, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** IEEE 802.1X, Active Directory, User Authentication, Profiling, Cyber Security, System Configuration, Network Security, Lightweight Directory Access Protocols (LDAP), Public Key Infrastructure, Zero Trust Network Access, Systems Integration, Wireless Access Point, Wireless Networks, Wireless LAN Controllers, Wireless Telecommunications, SSL Certificate Management, Identity Services Engine, System Availability, Firewalls (Computer Science), Forescout, Information Technology, TACACS+ Protocol, Cisco - **Published:** August 29, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18127064?backUrl=%2Fcareer%2F18127064%2FNetwork-Engineer-3-Forescout-Cisco-Ise-Maryland-Suitland ## About the Role * Senior Network Security Engineer responsible for designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform, including TACACS+/RADIUS services, device administration policies, and wired/wireless 802.1X authentication. * Experience working with Cisco ISE deployed on Cisco SNS3715 appliances, preferably in a twonode clustered, highavailability setup. * Understanding of ForeScout CounterACT, including legacy NAC/NAM policies, device classification, and access workflows, to support the migration to Cisco ISE. * Experience providing general wireless network support, including basic troubleshooting, controller interactions, and wireless access workflows. * Handson experience integrating Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, groupbased policy decisions, and directorybased authentication. * Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE with expertise in: * Authentication and authorization policies (RADIUS/TACACS+) * 1X/EAP methods for wireless and wired access * Device profiling, posture checks, and endpoint compliance * Certificatebased authentication (EAPTLS) and PKI integration * AAA integrations for switches, appliances, firewalls, and wireless controllers, * Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers, including guest/registration page redirection and wireless onboarding. * Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE while aligning with Zero Trust principles. * Four (4) years of experience supporting identitycentric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls. * Solid understanding of telecommunications, network security, and Zero Trust best practices. * Strong communication skills with the ability to explain Cisco ISE, NAC/NAM, and AAA concepts to both technical and nontechnical audiences. * Bachelor's degree in Information Technology, Cybersecurity, or a related field. * Preferred certifications: Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certifications., US Citizenship is a MUST given the nature of the work. Many of our roles require the hired candidate to go through public trust clearance. A minimum of 3 years of stay in the U.S. within the last 5 years is required to be eligible to qualify for public trust clearance sponsorship. ## Description This role also supports the agency's modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from ForeScout to Cisco ISE., * Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication. * Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS3715 appliances, ensuring high availability and consistent policy enforcement. * Support the agency's migration from ForeScout CounterACT to Cisco ISE, including reviewing legacy ForeScout policies, device groups, and access rules and mapping them into ISE policy sets. * Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams. * Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policydriven access control. * Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, groupbased authorization, and directorybased authentication workflows. * Deploy, configure, and maintain Cisco ISE components, including: * Policy Sets, Authorization Profiles, and Authentication Rules * TACACS+ device administration * 1X for wired and wireless networks * Profiling, posture, and compliance policies * Certificatebased authentication and PKI integrations * Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues. * Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience. * Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures. * Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Profiling Symfony & PHP apps with Blackfire](https://www.wearedevelopers.com/videos/265-profiling-symfony-php-apps-with-blackfire) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)