Network Engineer 3 - Forescout/Cisco ISE

Posted 2 Days Ago
Be an Early Applicant
Suitland, MD, USA
In-Office
Senior level
Artificial Intelligence • Information Technology • Machine Learning • Software • Analytics • Consulting • Financial Services
The Role
Designs, configures, monitors, and troubleshoots Cisco ISE NAC/NAM services, including RADIUS, TACACS+, wired and wireless 802.1X, profiling, posture checks, PKI, and directory integrations. Supports migration from ForeScout CounterACT, maintains clustered SNS-3715 appliances, integrates Cisco 9800 WLCs, resolves authentication issues, and strengthens Zero Trust access controls. Documents procedures, performs upgrades and health checks, collaborates across teams, and mentors junior staff.
Summary Generated by Built In

 Who we are:

Tria Federal delivers digital services and technology solutions that support the health and safety of veterans, service members and civilians. For two decades, federal agencies have relied on Tria companies to advance their critical missions and modernize their systems, so that they can uphold their commitment to the American people. Today, we are pushing the boundaries of possibility through partnerships and investments in artificial intelligence and emerging technologies, developing solutions for the biggest challenges that government will face tomorrow.

We are proud to employ and support military veterans who bring mission-first mindset, technical expertise, and leadership qualities that strengthen our work. Veterans, transitioning service members, and military spouses are strongly encouraged to apply.



Senior Network Security Engineer

Tria Federal is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy ForeScout CounterACT NAC/NAM system and adopts Cisco Identity Services Engine (ISE) as the new access‑control platform. The engineer will help configure and manage Cisco ISE across the environment, handling AAA services, wired and wireless 802.1X authentication, device administration, and posture checks for users and devices.

This role also supports the agency’s modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from ForeScout to Cisco ISE.


Basic Requirements

  • Senior Network Security Engineer responsible for designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform, including TACACS+/RADIUS services, device administration policies, and wired/wireless 802.1X authentication.
  • Experience working with Cisco ISE deployed on Cisco SNS‑3715 appliances, preferably in a two‑node clustered, high‑availability setup.
  • Understanding of ForeScout CounterACT, including legacy NAC/NAM policies, device classification, and access workflows, to support the migration to Cisco ISE.
  • Experience providing general wireless network support, including basic troubleshooting, controller interactions, and wireless access workflows.
  • Hands‑on experience integrating Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group‑based policy decisions, and directory‑based authentication.
  • Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE with expertise in:
  • Authentication and authorization policies (RADIUS/TACACS+)
  • 1X/EAP methods for wireless and wired access
  • Device profiling, posture checks, and endpoint compliance
  • Certificate‑based authentication (EAP‑TLS) and PKI integration
  • AAA integrations for switches, appliances, firewalls, and wireless controllers
  • Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers, including guest/registration page redirection and wireless onboarding.
  • Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE while aligning with Zero Trust principles.
  • Four (4) years of experience supporting identity‑centric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls.
  • Solid understanding of telecommunications, network security, and Zero Trust best practices.
  • Strong communication skills with the ability to explain Cisco ISE, NAC/NAM, and AAA concepts to both technical and non‑technical audiences.
  • Bachelor’s degree in Information Technology, Cybersecurity, or a related field.
  • Preferred certifications: Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certifications.

Responsibilities                              

  • Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication.
  • Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS‑3715 appliances, ensuring high availability and consistent policy enforcement.
  • Support the agency’s migration from ForeScout CounterACT to Cisco ISE, including reviewing legacy ForeScout policies, device groups, and access rules and mapping them into ISE policy sets.
  • Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams.
  • Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policy‑driven access control.
  • Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group‑based authorization, and directory‑based authentication workflows.
  • Deploy, configure, and maintain Cisco ISE components, including:
  • Policy Sets, Authorization Profiles, and Authentication Rules
  • TACACS+ device administration
  • 1X for wired and wireless networks
  • Profiling, posture, and compliance policies
  • Certificate‑based authentication and PKI integrations
  • Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues.
  • Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience.
  • Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures.
  • Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts.

Benefits and Perks: 

  • Medical, dental, and vision insurance – Multiple plan options through Cigna and VSP Vision Care with employer contributions.  
  • 401(k) retirement plan – 5% employer match with immediate vesting.  
  • Paid time off (PTO) – Accrual-based PTO with 11 paid federal holidays and 1 floating holiday.  
  • Parental & maternity leave – 20 days paid parental leave and 12 weeks fully paid maternity leave.  Disability & life insurance – Company-paid short-term & long-term disability, basic life insurance, and AD&D.  
  • Tuition & certification reimbursement – Support for career growth with up to $5,250 per year for tuition and certification assistance.  
  • Commuter benefits – Pre-tax savings for public transit and rideshare expenses.  
  • Employee referral bonus – Reward program for successful candidate referrals. 

 

Public Trust Clearance: 

US Citizenship is a MUST given the nature of the work. Many of our roles require the hired candidate to go through public trust clearance. A minimum of 3 years of stay in the U.S. within the last 5 years is required to be eligible to qualify for public trust clearance sponsorship.  

Work Location: 

For this specifc role, it’s essential that candidates are able to work onsite. Start time for the day onsite has to be between 7 AM- 9 AM ET and it will be a standard 8 hour day.

Tria Federal, operates primarily in the Eastern Time Zone, with standard work hours from 9 AM – 5 PM ET and flexibility around start and end times based on team and customer needs. We have open-collaboration offices in Arlington, VA, and Baltimore, MD for those who prefer to work on-site. 

EEO Statement: 

Tria Federal is an affirmative action and equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. Tria is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, or to participate in the job application or interview process, contact the Talent Acquisition Team at [email protected]   

 

Know your rights poster: https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf  

Why Tria?
What defines the Tria brand is more than just our dedication to excellence in our craft; it’s our incredible team of dedicated, talented, and passionate people that make Tria so exceptional. As people powering possible, we are all partners in our team’s shared success.

As a company that cares about people, we seek to cultivate a culture in which all can thrive personally and professionally. We offer a top-tier benefits package to invest in your physical, mental, and financial health and wellness so that you can be your best self - at work and in life. At Tria, we are growth-minded, entrepreneurial in spirit, and committed to fostering a culture of inclusion and opportunity for all. Whatever your background, your role, your department, or stage in your professional journey, here you will have opportunities to learn new skills, seize new challenges, and advance your career as we grow. 


California Consumer Privacy Act (CCPA)

We are committed to protecting your privacy. As part of our compliance with the California Consumer Privacy Act (CCPA), we want to inform you about how we collect, use, and protect your personal information during the job application process. For more details, please review https://www.oag.ca.gov/privacy/ccpa.

Skills Required

  • Eight years of experience in a large government organization
  • Five years of technical leadership experience
  • Four years implementing and troubleshooting Cisco ISE
  • Experience designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform
  • Experience with TACACS+, RADIUS, device administration policies, and wired/wireless 802.1X authentication
  • Experience with Cisco ISE on SNS-3715 appliances, preferably in a two-node high-availability cluster
  • Understanding of ForeScout CounterACT legacy NAC/NAM policies, device classification, and access workflows
  • General wireless network support experience, including controller interactions and troubleshooting
  • Experience integrating Cisco ISE with Active Directory and LDAP
  • Experience with authentication and authorization policies, device profiling, posture checks, endpoint compliance, EAP-TLS, PKI, and AAA integrations
  • Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers
  • Experience migrating legacy NAC, RADIUS, or device authentication systems to Cisco ISE
  • Four years supporting identity-centric or Zero Trust architectures
  • Knowledge of telecommunications, network security, segmentation, certificate management, endpoint posture controls, and Zero Trust best practices
  • Strong communication skills for explaining technical concepts to technical and non-technical audiences
  • Bachelor's degree in Information Technology, Cybersecurity, or a related field
  • Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certification
  • U.S. citizenship
  • Ability to work onsite during an eight-hour day with a start time between 7 AM and 9 AM Eastern Time
  • At least three years of U.S. residence within the last five years to qualify for Public Trust clearance sponsorship

Tria Federal Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Tria Federal and has not been reviewed or approved by Tria Federal.

  • Retirement Support The package includes a 401(k) with an employer match and immediate vesting, characterized as generous and automatic. The retirement plan is repeatedly described as a standout element within the overall offering.
  • Healthcare Strength Core medical, dental, vision, life, and disability coverage are provided, with materials describing minimal out-of-pocket costs. Health insurance is often characterized as good overall, particularly for individual coverage.
  • Leave & Time Off Breadth PTO is described as generous with accrual that increases with tenure and includes 12 paid holidays, alongside paid parental leave. These components indicate a broad time-off offering.

Tria Federal Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Arlington, VA
1,372 Employees
Year Founded: 2022

What We Do

Tria Federal (Tria) delivers digital services and technology solutions that support the health and safety of veterans, service members and civilians. For two decades, federal agencies have relied on Tria companies to help them complete their critical missions and modernize their systems, so that they can uphold their commitment to the American people. Today, our technology innovation group Tria Labs is pushing the boundaries of what is possible through partnerships and investments in artificial intelligence and emerging technologies, developing solutions for the biggest challenges that will face government tomorrow.

Similar Jobs

Wells Fargo Logo Wells Fargo

Sr Premier Banker - Bay Forest

Fintech • Financial Services
Hybrid
Annapolis, MD, USA
205000 Employees
34K-60K Hourly
Hybrid
California, MD, USA
205000 Employees
27K-41K Hourly

Boeing Logo Boeing

Mid-Level Appian Developer

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Annapolis Junction, MD, USA
170000 Employees
122K-152K Annually

Boeing Logo Boeing

Capture Manager

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Annapolis Junction, MD, USA
170000 Employees
190K-240K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account