Network Security Engineer
Listed on 2026-09-28
-
IT/Tech
Cybersecurity, Systems Engineer
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #: 1853
Job Title: Network Security Engineer
Location: Suitland, MD
Clearance Level: Public Trust
Job DescriptionAgile Defense is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy Fore Scout CounterACT NAC/NAM system and adopts Cisco Identity Services Engine (ISE) as the new access control platform. The engineer will help configure and manage Cisco ISE across the environment, handling AAA services, wired and wireless 802.1X authentication, device administration, and posture checks for users and devices.
This role also supports the agency’s modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from Fore Scout to Cisco ISE.
- Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication.
- Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS 3715 appliances, ensuring high availability and consistent policy enforcement.
- Support the agency’s migration from Fore Scout CounterACT to Cisco ISE, including reviewing legacy Fore Scout policies, device groups, and access rules and mapping them into ISE policy sets.
- Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams.
- Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policy driven access control.
- Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group based authorization, and directory based authentication workflows.
- Deploy, configure, and maintain Cisco ISE components, including:
o Policy Sets, Authorization Profiles, and Authentication Rules
o TACACS+ device administration
o 802.1X for wired and wireless networks
o Profiling, posture, and compliance policies
o Certificate based authentication and PKI integrations - Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues.
- Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience.
- Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures.
- Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts.
- Bachelor’s degree in Information Technology, Cybersecurity, or a related field.
- Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE.
- Four (4) years of experience supporting identity centric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).