Network Access Control (NAC) Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+19 more
Job description
This role supports a major financial services customer’s global network security organization as part of a broader modernization initiative covering NAC, firewalls, IDS/IPS, proxy, remote access, and Zero Trust segmentation.
The engineer will work directly within the customer’s existing Forescout and Cisco Client environment to mature how NAC is engineered and operationalized defining engineering standards, uplifting existing policy, closing known security gaps, and identifying automation opportunities. This is fundamentally a hands-on NAC engineering role: the person will need to understand endpoint access control at the mechanism and architecture level.
Key Responsibilities
-
Engineer, deploy, and operationalize Forescout NAC across enterprise environments, including endpoint discovery, agentless device visibility, profiling, and policy enforcement
-
Configure and maintain Cisco Client for 802.1X authentication, RADIUS authorization, dynamic VLAN assignment, and downloadable ACLs
-
Design and support the coexistence and integration of Forescout and Cisco Client within a unified NAC architecture
-
Define and uplift NAC engineering standards, policies, and operational documentation
-
Handle non-802.1X-capable endpoints (printers, cameras, IoT, legacy equipment) using MAC Authentication Bypass (MAB), profiling-based classification, and restricted-access policy
-
Integrate NAC with firewall platforms to align identity/device context with network segmentation and access enforcement
-
Support Zero Trust initiatives, including continuous posture/compliance verification and least-privilege access design
-
Identify and implement automation opportunities for NAC policy management and operations, using Python, Ansible, and related tooling
-
Collaborate with engineering, architecture, operations, and security teams to deliver integrated infrastructure solutions
-
Participate in incident response, troubleshooting, and root cause analysis for NAC and access-control issues
-
Ensure adherence to change management, compliance, and operational governance processes
-
Develop deployment documentation, implementation procedures, operational runbooks, and knowledge-transfer materials
Requirements
-
Hands-on Forescout experience: deployment, endpoint/device discovery, agentless profiling, policy creation and enforcement, posture/compliance assessment, and unmanaged device identification
-
Hands-on Cisco Client experience: 802.1X, RADIUS, EAP-TLS, certificate-based authentication, profiling, posture, and policy design
-
Strong understanding of NAC architecture end-to-end from endpoint connection through discovery, authentication, profiling, posture/compliance, authorization, access decisioning, and continuous monitoring
-
Demonstrated experience handling non-802.1X devices via MAB, profiling, and restricted-access strategies (not simply MAC whitelisting)
-
Working knowledge of Zero Trust principles: identity-based access, continuous verification, least privilege, and segmentation
-
Understanding of how NAC and firewall platforms integrate to jointly enforce identity-, device-, and posture-based access control
-
Ability to speak to specific, personally-built or personally-modified NAC/Forescout policies
-
Experience working within formal change-management and incident-management processes
Preferred Qualifications
-
Experience with Forescout and Cisco Client coexistence/integration in a production environment
-
PKI/certificate management and Active Directory integration experience
-
Experience with Security Group Tags (SGT), Cisco TrustSec, and pxGrid
-
Automation/scripting experience (Python, Ansible, REST APIs, Terraform, GitLab CI/CD)
-
Complementary firewall experience (Palo Alto, Fortinet, Check Point, Cisco) valuable as a secondary skill, not a substitute for NAC/Forescout depth
-
SIEM/security operations exposure (Splunk, QRadar) for alerting and incident correlation
Tools and Technologies
-
Forescout Platform (device visibility, profiling, policy enforcement, compliance)
-
Cisco Client (802.1X, RADIUS, TrustSec, pxGrid)
-
Firewall platforms (Palo Alto, Fortinet, Check Point, Cisco) for NAC integration
-
Zero Trust / segmentation frameworks
-
Python, Ansible, GitLab CI/CD, REST APIs
-
ServiceNow / ITIL-based change and incident management
Skills: 802.1, Access Authorization, Access Control, Ansible, Apple Macs, Authentication, Automation, Change Management, Cisco Network Systems, Customer Experience, Develop and Maintain Customers, Digital Certificates, Documentation, Financial Services, Firewalls, ITIL (IT Infrastructure Library), Identify Issues, Incident Management, Incident Response, Internet of Things, Intrusion Detection Systems, Intrusion Prevention Systems, Knowledge Transfer, Machine Tool, Maintain Compliance, Microsoft Active Directory, Network Access Control (NAC), Network Security, Operations Processes, Operations Security (OPSEC), Policy Development, Printers, Procedure Implementation, Production Systems, Public Key Infrastructure (PKI), Python Programming/Scripting Language, RADIUS (Remote Authentication Dial-In User Service), Remote Access, Root Cause Analysis, SSL-TLS (Secure Socket Layer - Transport Layer Security), Security Information and Event Management (SIEM), ServiceNow, Splunk, Standards Development, VLAN
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The Overflow: Security and Privacy
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks