Network Access Control; NAC) Engineer
Listed on 2026-09-07
-
Security
Cybersecurity, Network Security
Location: Whippany
Network Access Control Engineer
This role supports a major financial services customer's global network security organization as part of a broader modernization initiative covering NAC, firewalls, IDS/IPS, proxy, remote access, and Zero Trust segmentation.
The engineer will work directly within the customer's existing Forescout and Cisco Client environment to mature how NAC is engineered and operationalized — defining engineering standards, uplifting existing policy, closing known security gaps, and identifying automation opportunities. This is fundamentally a hands-on NAC engineering role: the person will need to understand endpoint access control at the mechanism and architecture level.
Key Responsibilities
- Engineer, deploy, and operationalize Forescout NAC across enterprise environments, including endpoint discovery, agentless device visibility, profiling, and policy enforcement
- Configure and maintain Cisco Client for 802.1X authentication, RADIUS authorization, dynamic VLAN assignment, and downloadable ACLs
- Design and support the coexistence and integration of Forescout and Cisco Client within a unified NAC architecture
- Define and uplift NAC engineering standards, policies, and operational documentation
- Handle non-802.1X-capable endpoints (printers, cameras, IoT, legacy equipment) using MAC Authentication Bypass (MAB), profiling-based classification, and restricted-access policy
- Integrate NAC with firewall platforms to align identity/device context with network segmentation and access enforcement
- Support Zero Trust initiatives, including continuous posture/compliance verification and least-privilege access design
- Identify and implement automation opportunities for NAC policy management and operations, using Python, Ansible, and related tooling
- Collaborate with engineering, architecture, operations, and security teams to deliver integrated infrastructure solutions
- Participate in incident response, troubleshooting, and root cause analysis for NAC and access-control issues
- Ensure adherence to change management, compliance, and operational governance processes
- Develop deployment documentation, implementation procedures, operational runbooks, and knowledge-transfer materials
Required Qualifications
- Hands-on Forescout experience: deployment, endpoint/device discovery, agentless profiling, policy creation and enforcement, posture/compliance assessment, and unmanaged device identification
- Hands-on Cisco Client experience: 802.1X, RADIUS, EAP-TLS, certificate-based authentication, profiling, posture, and policy design
- Strong understanding of NAC architecture end-to-end — from endpoint connection through discovery, authentication, profiling, posture/compliance, authorization, access decisioning, and continuous monitoring
- Demonstrated experience handling non-802.1X devices via MAB, profiling, and restricted-access strategies (not simply MAC whitelisting)
- Working knowledge of Zero Trust principles: identity-based access, continuous verification, least privilege, and segmentation
- Understanding of how NAC and firewall platforms integrate to jointly enforce identity-, device-, and posture-based access control
- Ability to speak to specific, personally-built or personally-modified NAC/Forescout policies
- Experience working within formal change-management and incident-management processes
Preferred Qualifications
- Experience with Forescout and Cisco Client coexistence/integration in a production environment
- PKI/certificate management and Active Directory integration experience
- Experience with Security Group Tags (SGT), Cisco Trust Sec, and pxGrid
- Automation/scripting experience (Python, Ansible, REST APIs, Terraform, Git Lab CI/CD)
- Complementary firewall experience (Palo Alto, Fortinet, Check Point, Cisco) — valuable as a secondary skill, not a substitute for NAC/Forescout depth
- SIEM/security operations exposure (Splunk, QRadar) for alerting and incident correlation
Tools and Technologies
- Forescout Platform (device visibility, profiling, policy enforcement, compliance)
- Cisco Client (802.1X, RADIUS, Trust Sec, pxGrid)
- Firewall platforms (Palo Alto, Fortinet, Check Point, Cisco) for NAC integration
- Zero Trust / segmentation frameworks
- Python, Ansible, Git Lab CI/CD, REST APIs
- Service Now / ITIL-based change and incident management
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).