Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
CACI International Inc. is seeking a Cisco Identity Services Engine (ISE) Lead to provide senior engineering and operational leadership for enterprise network access control.
You will drive design, testing, implementation, and sustainment of Cisco ISE policies enforcing Comply-to-Connect across wired, remote, and device-management environments. The role supports the ECS3 program for intelligence customers across CONUS/OCONUS, collaborating with network, cybersecurity, and identity teams to
Job Title: Cisco Identity Services Engineer (ISE) Lead
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI with Polygraph
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Outside Continental US
CACI is seeking a Cisco Identity Services Engine (ISE) Lead to provide senior engineering, operations, and technical leadership for enterprise network access control. The successful candidate will lead the development, testing, implementation, and sustainment of Cisco ISE policies that enforce Comply-to-Connect (C2C) requirements across wired, remote-access, and network-device-administration environments.
The ECS3 program supports our intelligence customer across CONUS and OCONUS locations through the design, transition, operations, modernization, technology refresh, and continual improvement of enterprise LAN, Unified Communications, and cybersecurity services. The Tier 3 ISE Lead will work with network, cybersecurity, endpoint-management, and identity teams to translate approved access-control requirements into scalable, supportable ISE policy and operational capabilities.
Design, create, test, implement, document, and sustain ISE authentication and authorization policies, authorization profiles, identity source sequences, endpoint groups, profiling rules, posture policies, and exception workflows.
Engineer and support 802.1X, EAP-TLS, MAB, RADIUS, TACACS+, guest access, contractor access, certificate-based authentication, and network-device administration.
Implement policy actions using dynamic VLAN assignment, downloadable ACLs, Security Group Tags, Change of Authorization, reauthentication, restricted-access controls, quarantine actions, and endpoint-remediation workflows.
Integrate and sustain ISE connections with Active Directory, PKI and certificate authorities, endpoint-management tools, endpoint-security platforms, vulnerability-management tools, SIEMs, pxGrid clients, switches, VPN infrastructure, and other approved security services.
Resolve complex authentication, authorization, certificate, profiling, posture, endpoint, CoA, RADIUS, TACACS+, and network-device issues. Analyze ISE Live Logs, session traces, alarms, packet captures, switch logs, support bundles, and endpoint data to determine root cause and corrective actions.
Administer and troubleshoot the distributed ISE deployment, including PAN, secondary Administration node, PSNs, MnT, pxGrid, node groups, replication, backups, restores, certificates, performance, capacity, and disaster‑recovery procedures.
Support ISE upgrades, patches, certificate renewals, policy migrations, technology refresh, node recovery, backup validation, and approved maintenance activities. Develop implementation, test, validation, rollback, and post‑change review plans.
Develop and maintain policy naming standards, configuration baselines, test procedures, implementation checklists, rollback procedures, SOPs, and knowledge articles. Review proposed policy changes for operational impact, dependencies, and access risk.
Support pilot efforts, site onboarding, phased rollout, transition to operations, recurring‑incident reduction, and continuous improvement of C2C policy and service delivery.
Mentor teammates; provide technical guidance to engineering and operations teams; coordinate Cisco TAC cases; and produce complete escalation packages, root‑cause analyses, and after‑action reports.