> Markdown version of [/jobs/ext/2750828-network-access-control-nac-engineer](https://www.wearedevelopers.com/jobs/ext/2750828-network-access-control-nac-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Access Control (NAC) Engineer - **Company:** IS3 Solutions - **Location:** Hanover, NJ, United States - **Contract:** Permanent contract - **Skills:** IEEE 802.1X, Active Directory, Macintosh Computers, User Authentication, Profiling, Cyber Security, Intrusion Detection Systems, Python (Programming Language), Network Security, Network Segmentation, Public Key Infrastructure, Role-Based Access Control, Remote Access Technology, Ansible, Zero Trust Network Access, Security Information and Event Management, Virtual Local Area Networks, SSL Certificate Management, Scripting, Transport Layer Security, Network Access Control, QRadar, Firewalls (Computer Science), Forescout, Gitlab-ci, Fortinet, Restful APIs, Terraform, Splunk, Cisco, Servicenow - **Published:** September 6, 2026 - **Apply:** https://www.careerbuilder.com/job-details/network-access-control-nac-engineer-whippany-nj--dcf2bc35-aa22-4f9a-a71d-04cf6dbc1182 ## About the Role * Hands-on Forescout experience: deployment, endpoint/device discovery, agentless profiling, policy creation and enforcement, posture/compliance assessment, and unmanaged device identification * Hands-on Cisco Client experience: 802.1X, RADIUS, EAP-TLS, certificate-based authentication, profiling, posture, and policy design * Strong understanding of NAC architecture end-to-end from endpoint connection through discovery, authentication, profiling, posture/compliance, authorization, access decisioning, and continuous monitoring * Demonstrated experience handling non-802.1X devices via MAB, profiling, and restricted-access strategies (not simply MAC whitelisting) * Working knowledge of Zero Trust principles: identity-based access, continuous verification, least privilege, and segmentation * Understanding of how NAC and firewall platforms integrate to jointly enforce identity-, device-, and posture-based access control * Ability to speak to specific, personally-built or personally-modified NAC/Forescout policies * Experience working within formal change-management and incident-management processes Preferred Qualifications * Experience with Forescout and Cisco Client coexistence/integration in a production environment * PKI/certificate management and Active Directory integration experience * Experience with Security Group Tags (SGT), Cisco TrustSec, and pxGrid * Automation/scripting experience (Python, Ansible, REST APIs, Terraform, GitLab CI/CD) * Complementary firewall experience (Palo Alto, Fortinet, Check Point, Cisco) valuable as a secondary skill, not a substitute for NAC/Forescout depth * SIEM/security operations exposure (Splunk, QRadar) for alerting and incident correlation Tools and Technologies * Forescout Platform (device visibility, profiling, policy enforcement, compliance) * Cisco Client (802.1X, RADIUS, TrustSec, pxGrid) * Firewall platforms (Palo Alto, Fortinet, Check Point, Cisco) for NAC integration * Zero Trust / segmentation frameworks * Python, Ansible, GitLab CI/CD, REST APIs * ServiceNow / ITIL-based change and incident management Skills: 802.1, Access Authorization, Access Control, Ansible, Apple Macs, Authentication, Automation, Change Management, Cisco Network Systems, Customer Experience, Develop and Maintain Customers, Digital Certificates, Documentation, Financial Services, Firewalls, ITIL (IT Infrastructure Library), Identify Issues, Incident Management, Incident Response, Internet of Things, Intrusion Detection Systems, Intrusion Prevention Systems, Knowledge Transfer, Machine Tool, Maintain Compliance, Microsoft Active Directory, Network Access Control (NAC), Network Security, Operations Processes, Operations Security (OPSEC), Policy Development, Printers, Procedure Implementation, Production Systems, Public Key Infrastructure (PKI), Python Programming/Scripting Language, RADIUS (Remote Authentication Dial-In User Service), Remote Access, Root Cause Analysis, SSL-TLS (Secure Socket Layer - Transport Layer Security), Security Information and Event Management (SIEM), ServiceNow, Splunk, Standards Development, VLAN ## Description This role supports a major financial services customer's global network security organization as part of a broader modernization initiative covering NAC, firewalls, IDS/IPS, proxy, remote access, and Zero Trust segmentation. The engineer will work directly within the customer's existing Forescout and Cisco Client environment to mature how NAC is engineered and operationalized defining engineering standards, uplifting existing policy, closing known security gaps, and identifying automation opportunities. This is fundamentally a hands-on NAC engineering role: the person will need to understand endpoint access control at the mechanism and architecture level. Key Responsibilities * Engineer, deploy, and operationalize Forescout NAC across enterprise environments, including endpoint discovery, agentless device visibility, profiling, and policy enforcement * Configure and maintain Cisco Client for 802.1X authentication, RADIUS authorization, dynamic VLAN assignment, and downloadable ACLs * Design and support the coexistence and integration of Forescout and Cisco Client within a unified NAC architecture * Define and uplift NAC engineering standards, policies, and operational documentation * Handle non-802.1X-capable endpoints (printers, cameras, IoT, legacy equipment) using MAC Authentication Bypass (MAB), profiling-based classification, and restricted-access policy * Integrate NAC with firewall platforms to align identity/device context with network segmentation and access enforcement * Support Zero Trust initiatives, including continuous posture/compliance verification and least-privilege access design * Identify and implement automation opportunities for NAC policy management and operations, using Python, Ansible, and related tooling * Collaborate with engineering, architecture, operations, and security teams to deliver integrated infrastructure solutions * Participate in incident response, troubleshooting, and root cause analysis for NAC and access-control issues * Ensure adherence to change management, compliance, and operational governance processes * Develop deployment documentation, implementation procedures, operational runbooks, and knowledge-transfer materials ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)