Enterprise Network Engineer

Johns Hopkins Medicine

Baltimore (MD)

On-site

USD 64,000 - 113,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Johns Hopkins Medicine in Baltimore, MD is seeking an Enterprise Network Engineer to design, implement, and operate secure access and segmentation across enterprise networks. You will translate security and business requirements into scalable authentication, authorization, policy enforcement, and least-privilege designs while maintaining reliable connectivity for users and devices.

This senior role demands strong analytical judgment, clear communication, and disciplined change control.

Qualifications

  • Bachelor's Degree in computer science, information technology, network engineering, or related field.
  • Minimum 5 Years of Experience in network engineering or IT.
  • Experience with NAC platforms and lifecycle management.
  • Healthcare or regulated enterprise experience preferred.

Responsibilities

  • Design, implement, operate, and continuously improve secure access and segmentation across enterprise networks.
  • Translate security and business requirements into scalable authentication, authorization, policy-enforcement, and least-privilege segmentation designs.
  • Collaborate across network, cybersecurity, identity, endpoint, application, and operations teams.
  • Monitor service health and perform advanced troubleshooting of NAC and network access components.

Skills

Network engineering
Security segmentation
NAC integration
Policy enforcement
Troubleshooting
Documentation

Education

Bachelor's degree

Tools

Aruba ClearPass
AGNI
Cisco ISE
Forescout
Easy NAC
RADIUS

Job description

JOB SUMMARY:
The Enterprise Network Engineer is a senior technical contributor responsible for designing, implementing, operating, and continuously improving secure access and segmentation services across enterprise wired networks. The engineer will translate security and business requirements into scalable authentication, authorization, policy-enforcement, and least-privilege segmentation designs while maintaining reliable user and device connectivity. This role requires strong analytical judgment, clear communication, disciplined change practices, and effective collaboration across network, cybersecurity, identity, endpoint, application, and operations teams.

QUALIFICATIONS:

  • Bachelor's Degree computer science, information technology, network engineering, or a related field (Required)
  • One year of relevant education may be substituted for one year of required work experience or one year of relevant professional-level work experience may be substituted for one year of required education.
  • Minimum 5 Years of Experience in network engineering or IT required (Required)
  • Support the design, deployment, and lifecycle management of enterprise network access control solutions across wired, guest, contractor, BYOD, and device-access use cases.
  • Develop and maintain identity- and context-based access policies using platforms such as Aruba ClearPass, AGNI, Cisco Identity Services Engine (ISE), Forescout, and Easy NAC.
  • Design and implement network segmentation and microsegmentation controls using roles, VLANs, ACLs, security-group constructs, downloadable policy, dynamic authorization, and firewall policy enforcement.
  • Engineer and support wired 802.1X, EAP-TLS, MAC Authentication Bypass, RADIUS, TACACS+, certificate-based authentication, device profiling, posture assessment, and guest onboarding.
  • Integrate NAC platforms with identity directories, PKI and certificate services, endpoint-management platforms, firewalls, switching platforms, SIEM solutions, and other security tools.
  • Configure and troubleshoot Cisco and Arista switching and routing functions required for secure access, including VLANs, trunks, spanning tree, Layer 3 routing, DHCP relay, access controls, and RADIUS-based policy enforcement.
  • Partner with firewall and security teams to align access decisions with internal segmentation, least-privilege, Zero Trust, and lateral-movement reduction objectives.
  • Perform advanced troubleshooting using authentication logs, packet captures, RADIUS transactions, certificate-chain validation, switch and wireless-controller diagnostics, endpoint supplicant logs, and firewall events.
  • Develop high-level and low-level designs, standards, implementation plans, test plans, migration procedures, rollback plans, operational runbooks, diagrams, and knowledge articles.
  • Participate in pilot deployments and phased production rollouts; coordinate maintenance windows, validate outcomes, manage risk, and communicate status, impact, and remediation plans to technical and nontechnical stakeholders.
  • Monitor service health, authentication success rates, policy outcomes, capacity, availability, certificate expiration, and operational trends; recommend corrective and preventive improvements.
  • Support incident response, root-cause analysis, audit evidence, security assessments, and remediation of access-control or segmentation findings.
  • Provide technical leadership, facilitate design reviews, and serve as an escalation point for complex NAC, authentication, segmentation, and connectivity issues.
  • Evaluate emerging products and features through structured proofs of concept, documented test criteria, and evidence-based recommendations.
  • Advanced networking or security certification such as CCNP Enterprise, CCNP Security, CCIE, CISSP, or a relevant vendor NAC certification.
  • Experience integrating NAC with Active Directory, LDAP, MDM/UEM, SIEM, vulnerability-management, endpoint-security, and certificate-enrollment services.
  • Knowledge of Zero Trust architecture, network policy automation, infrastructure as code, APIs, Python, PowerShell, or other scripting and orchestration methods.
  • Experience in regulated, high-availability, healthcare, government, financial, or similarly complex enterprise environments.

Salary Range: Minimum 46.66/hour - Maximum 81.67/hour. Compensation will be commensurate with equity and experience for roles of similar scope and responsibility. In cases where the range is displayed as a $0 amount, salary discussions will occur during candidate screening calls, before any subsequent compensation discussion is held between the candidate and any hiring authority.

The Hospital reserves the right to modify employee schedules as needed.

We are committed to creating a welcoming and inclusive environment, where we embrace and celebrate our differences, where all employees feel valued, contribute to our mission of serving the community, and engage in equitable healthcare delivery and workforce practices.

Johns Hopkins Health System and its affiliates are drug-free workplace employers.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Network Engineer
Network Engineer

HealthEdge Software, Inc. • Northern (KY)

On-site
USD 84,000 - 89,000
Network Engineer
Network Engineer

Talentify • United States

Remote
USD 84,000 - 89,000
Network Engineer - 173230
Network Engineer - 173230

ZP Group • Columbia (MD)

On-site
USD 90,000 - 115,000
PTO
Paid Holidays
Medical
+4
Network Engineer - 173230
Network Engineer - 173230

Zachary Piper Solutions • Columbia (MD)

On-site
USD 90,000 - 115,000
PTO
Paid Holidays
Medical
+4
Network Administrator
Network Administrator

Southeast Mississippi Rural Health Initiative, Inc. • Mississippi

On-site
USD 65,000 - 90,000
Network Engineer
Network Engineer

Tyler Regional Hospital • Tyler (TX)

On-site
USD 85,000 - 115,000
Senior Network Engineer
Senior Network Engineer

Banner Life family of companies • Urbana (MD)

On-site
USD 127,500 - 175,350
Health insurance
401(k) with company match
20 vacation days
Network Engineer - 173230
Network Engineer - 173230

Piper Companies • Columbia (MD)

On-site
USD 90,000 - 115,000
PTO
Paid Holidays
Medical Insurance
+4
Network Engineer 3
Network Engineer 3

Boston Medical Center, Corp. • Boston (MA), Northern (KY)

On-site
USD 90,000 - 130,000
Senior Network Engineer
Senior Network Engineer

Banner Life Insurance Company • Frederick (MD)

On-site
USD 127,500 - 175,350
401K with company match
20 vacation days
Competitive health, life, and dental insurance