Role Summary
The Cybersecurity Engineer is responsible for configuring, managing, and optimizing Comply-to-Connect (C2C) and Network Access Control (NAC) solutions within secure enterprise environments. This role focuses on device discovery, classification, posture assessment, policy enforcement, and remediation. The position collaborates with cross‑functional teams to implement, validate, and support network access control strategies across multiple locations.
Responsibilities
- Configure, test, and optimize device discovery, classification, and interrogation processes within NAC environments.
- Develop, validate, and implement posture checks and automated remediation policies, beginning with controlled pilot groups before broader deployment.
- Integrate NAC solutions with endpoint security tools, Active Directory, SIEM, ticketing systems, and other enterprise security technologies.
- Support monitoring activities, analyze policy failures, and tune configurations to improve enforcement accuracy.
- Support phased enforcement activities and collaborate with network engineering teams to troubleshoot issues and execute rollback procedures when necessary.
- Identify, categorize, and document exception devices and support applicable exception or waiver processes.
- Maintain detailed documentation of configurations, policies, procedures, and operational runbooks.
- Support production environments operating under established change control and security processes.
- Collaborate with cross‑functional teams to support network security and device compliance.
- Travel to multiple locations within the continental United States to support deployment and operational activities.
Qualifications
- 5 to 8 years of experience in cybersecurity or network security, including 2+ years of experience managing NAC policies in production environments.
- This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required.
- Hands‑on experience administering NAC solutions at enterprise scale using platforms such as Forescout or Cisco ISE.
- Strong knowledge of 802.1X, MAB, RADIUS, Active Directory/Group Policy, and PKI/certificate‑based authentication.
- Familiarity with security standards and technologies such as STIGs, SCAP, ACAS/Tenable, and endpoint security solutions.
- Experience with scripting or automation using PowerShell, Python, REST APIs, or similar technologies.
- Experience supporting secure production environments with established change control requirements.
- Ability and willingness to travel up to 75% to location within the continental United States.
- Relevant education, training, certifications, or equivalent practical experience.
Publishing Pay Range:
$75.00 – $85.00 USD Hourly
This is a fully remote role and can be performed from an approved location.