Network Security Engineer

Posted 2 Days Ago
Be an Early Applicant
Suitland, MD, USA
In-Office
100K-115K Annually
Senior level
Information Technology • Software • Cybersecurity • Defense
The Role
Designs, deploys, configures, monitors, and troubleshoots Cisco ISE for AAA, RADIUS/TACACS+, wired and wireless 802.1X, endpoint profiling, posture checks, and certificate-based authentication. Supports migration from ForeScout CounterACT, integrates ISE with Active Directory, LDAP, Cisco 9800 controllers, and PKI, and improves Zero Trust access controls. Performs health checks, upgrades, root-cause analysis, documentation, cross-team coordination, and mentoring while working onsite in Suitland, Maryland.
Summary Generated by Built In
About Agile Defense
 
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
 
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Requisition #: 1853
Job Title: Network Security Engineer
Location: Suitland, MD
Clearance Level: Public Trust
 

Job Description

    Agile Defense is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy ForeScout CounterACT NAC/NAM system and adopts Cisco Identity Services Engine (ISE) as the new access control platform. The engineer will help configure and manage Cisco ISE across the environment, handling AAA services, wired and wireless 802.1X authentication, device administration, and posture checks for users and devices.

    This role also supports the agency’s modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from ForeScout to Cisco ISE.

  • Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication.
  • Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS 3715 appliances, ensuring high availability and consistent policy enforcement.
  • Support the agency’s migration from ForeScout CounterACT to Cisco ISE, including reviewing legacy ForeScout policies, device groups, and access rules and mapping them into ISE policy sets.
  • Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams.
  • Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policy driven access control.
  • Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group based authorization, and directory based authentication workflows.
  • Deploy, configure, and maintain Cisco ISE components, including:
    o    Policy Sets, Authorization Profiles, and Authentication Rules
    o    TACACS+ device administration
    o    802.1X for wired and wireless networks
    o    Profiling, posture, and compliance policies
    o    Certificate based authentication and PKI integrations
  • Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues.
  • Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience.
  • Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures.
  • Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts.

Education and Background

  • Bachelor’s degree in Information Technology, Cybersecurity, or a related field.

Years of Experience

  • Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE.
  • Four (4) years of experience supporting identity centric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls.

Required Skills

    Senior Network Security Engineer responsible for designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform, including TACACS+/RADIUS services, device administration policies, and wired/wireless 802.1X authentication.
  • Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE with expertise in:
    o    Authentication and authorization policies (RADIUS/TACACS+)
    o    802.1X/EAP methods for wireless and wired access
    o    Device profiling, posture checks, and endpoint compliance
    o    Certificate based authentication (EAP TLS) and PKI integration
    o    AAA integrations for switches, appliances, firewalls, and wireless controllers
  • Experience working with Cisco ISE deployed on Cisco SNS 3715 appliances, preferably in a two node clustered, high availability setup.
  • Understanding of ForeScout CounterACT, including legacy NAC/NAM policies, device classification, and access workflows, to support the migration to Cisco ISE
  • Experience providing general wireless network support, including basic troubleshooting, controller interactions, and wireless access workflows.
  • Hands on experience integrating Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group based policy decisions, and directory based authentication.
  • Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers, including guest/registration page redirection and wireless onboarding.
  • Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE while aligning with Zero Trust principles.
  • Solid understanding of telecommunications, network security, and Zero Trust best practices.
  • Strong communication skills with the ability to explain Cisco ISE, NAC/NAM, and AAA concepts to both technical and non technical audiences.
  •  

Preferred Skills

  • Preferred certifications: Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certifications.

Working Conditions

  • On-site 5 days a week in Suitland, Maryland


In addition, Agile Defense invests in its employees beyond just compensation.  Agile’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections.

Our Core Values
 
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. 
 
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
 
  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
 
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

Skills Required

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field
  • Eight years of experience in a large government organization
  • Five years of technical leadership experience
  • Four years implementing and troubleshooting Cisco ISE
  • Four years supporting identity-centric or Zero Trust architectures
  • Experience with RADIUS, TACACS+, 802.1X, EAP methods, device profiling, posture checks, endpoint compliance, and PKI-integrated certificate authentication
  • Experience with Cisco ISE on Cisco SNS 3715 appliances, preferably in a two-node high-availability cluster
  • Understanding of ForeScout CounterACT legacy NAC/NAM policies and migration workflows
  • Experience providing wireless network support and troubleshooting
  • Hands-on experience integrating Cisco ISE with Active Directory and LDAP
  • Experience integrating Cisco ISE with Cisco 9800 Wireless LAN Controllers
  • Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE
  • Knowledge of telecommunications, network security, and Zero Trust best practices
  • Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certification
  • Ability to work onsite five days per week in Suitland, Maryland
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: McLean, VA
2,000 Employees
Year Founded: 1998

What We Do

Agile Defense is a technology services company that provides advanced digital transformation, data analytics, and cybersecurity solutions to support critical national security and civilian government missions. With a global presence, the company focuses on delivering outcome-driven, AI-powered capabilities to solve complex mission challenges for federal and defense customers.

Similar Jobs

Citizens Logo Citizens

Network Engineer

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees

Citizens Logo Citizens

Network Engineer

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees

Peraton Logo Peraton

Security Engineer

Aerospace • Information Technology • Security • Cybersecurity • Defense
In-Office
College Park, MD, USA
18000 Employees
146K-234K Annually

VOR Technology LLC Logo VOR Technology LLC

Systems Engineer

Information Technology • Professional Services • Cybersecurity • Defense
In-Office
Fort Meade, MD, USA
200 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account