Network Administrator 2

University of Connecticut

Storrs (CT)

Hybrid

USD 110,000 - 140,000

Full time

10 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Retirement options
Health care options
Vacation and holidays
Merit increase
Tuition waivers
Hybrid-work arrangement

Job summary

University of Connecticut’s Information Technology Services seeks an experienced professional to administer and evolve the Cisco Identity Services Engine (ISE) deployment. The role ensures highly available RADIUS and TACACS+ services and leads identity-aware networking through integration with multiple identity and security platforms.

The successful candidate will manage authentication for campus networks, provide technical leadership, and develop automation to improve operations.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Engineering, or related field and four (4) years of progressively responsible experience supporting enterprise network infrastructure; or eight (8) years of equivalent experience.
  • Demonstrated experience administering production enterprise network infrastructure including routing, switching, wireless networking, or network security technologies.
  • Demonstrated experience supporting enterprise authentication services utilizing RADIUS, TACACS+, IEEE 802.1X, or comparable authentication technologies.
  • Experience troubleshooting authentication issues between ISE and Active Directory, Microsoft Entra ID, LDAP, certificate services, or other enterprise identity providers.
  • Experience administering systems on dedicated appliances and/or hosted on virtualization platforms such as VMWare.
  • Experience using enterprise network monitoring, logging, and management systems.
  • Experience preparing technical documentation, operational procedures, and change management documentation.
  • Demonstrated written communication skills with technical and non-technical stakeholders.

Responsibilities

  • Administer and maintain a highly available Cisco Identity Services Engine (ISE) deployment across multiple data centers.
  • Manage enterprise RADIUS authentication supporting secure wireless services for campus users and devices.
  • Administer Cisco ISE TACACS+ for authN, authorization, and accounting across devices.
  • Lead lifecycle management of the Cisco ISE environment including upgrades, patches, licensing, backup, and DR testing.
  • Design, implement, and improve authentication/authorization policies for wired, wireless, VPN, and admin services.
  • Integrate Cisco ISE with Entra ID, Active Directory, PKI, Catalyst Center, wireless controllers, and network infrastructure.
  • Diagnose complex authentication issues involving 802.1X, EAP-TLS, PEAP, RADIUS, certificate services, and AD.
  • Produce and maintain operational docs, DR procedures, diagrams, standards, and knowledge bases.
  • Participate in after-hours maintenance, emergency response, and on-call support for authentication and network services.
  • Other related duties as required.

Skills

Enterprise networking
Auth troubleshooting
RADIUS/TACACS+/802.1X
VMware
Network monitoring
Documentation
Communication
Scripting

Education

Bachelor's degree in CS/IT/Engineering

Tools

Cisco ISE

Job description

Session Management:

Keeping you logged in

Remembering items in a shopping cart

Saving language or theme preferences

Tailoring content or ads based on your previous activity

Tracking & Analytics:

Monitoring browsing behavior for analytics or marketing purposes

Used for things like keeping you logged in during a single session

Stored on your device until they expire or are manually deleted

Used for remembering login credentials, settings, etc.

Set by the website you're visiting directly

Set by other domains (usually advertisers) embedded in the website

Commonly used for tracking across multiple sites

What They Do:

Proves to the website that you're logged in

Prevents you from having to log in again on every page you visit

Can persist across sessions if you select "Remember me"

Typically, it contains:

Optional metadata (e.g., expiration time, security flags)

How users navigate the site

Which pages are most/least visited

How long users stay on each page

What They Track:

Page views and time spent on pages

Click paths (how users move from page to page)

Bounce rate (users who leave without interacting)

Referring websites (how users arrived at the site)

1. Google Chrome

Open Chrome and click the three vertical dots in the top-right corner.

Choose your preferred option:

Open Firefox and click the three horizontal lines in the top-right corner.

Go to Settings > Privacy & Security.

3. Safari

Open Safari and click Safari in the top-left corner of the screen.

Go to Preferences > Privacy.

4. Microsoft Edge

Open Edge and click the three horizontal dots in the top-right corner.

Be Aware:
JOB SUMMARY

This position within the University of Connecticut's Information Technology Services department is responsible for the administration, operation, integration, and lifecycle management of the University's Cisco Identity Services Engine (ISE) deployment. The successful candidate will ensure that this deployment provides highly available RADIUS and TACACS+ services. They will be responsible for leading the continued evolution of identity-aware networking through integrations between various networking and identity services and leveraging the features of ISE or subsequent systems. The successful candidate will possess a broad foundation in enterprise networking while serving as the technical lead for identity-based network access technologies that support academic, research, administrative, and residential computing environments.

Applicants selected for interview should expect to discuss their direct experiences in relation to the below job duties and qualifications. Candidates may also be asked to describe a production issue they resolved, an authentication deployment they implemented, or an enterprise service they have operated.

BENEFITS INCLUDE:
  • Defined contribution with employer match or defined benefit program retirement options.
  • Excellent and affordable health care options.
  • 22 paid vacation days per year, in addition to paid sick leave and (13) paid holidays.
  • Annual merit increase program.
  • Employee and dependent tuition waivers.
  • A highly desirable work environment and work-life balance with opportunities for hybrid-work arrangement.
DUTIES AND RESPONSIBILITIES
  • Administer and maintain a highly available Cisco Identity Services Engine (ISE) deployment consisting of redundant virtual Policy Administration, Monitoring, and Policy Service Nodes located across geographically separated data centers.
  • Manage enterprise RADIUS authentication supporting secure wireless services ensuring reliable authentication for thousands of campus users and devices.
  • Administer Cisco ISE TACACS+ infrastructure providing authentication, authorization, and accounting services for enterprise network infrastructure devices.
  • Lead lifecycle management of the Cisco ISE environment, including software upgrades, patch management, certificate lifecycle management, licensing, backup and recovery, health monitoring, and disaster recovery testing.
  • Design, implement, and continuously improve authentication and authorization policies supporting wired, wireless, VPN, and infrastructure administration services.
  • Integrate Cisco ISE with Microsoft Entra ID, Active Directory, PKI, Cisco Catalyst Center, wireless controllers, network switching infrastructure, and other enterprise identity and security platforms.
  • Diagnose complex authentication issues involving IEEE 802.1X, EAP-TLS, PEAP, RADIUS, TACACS+, certificate services, Active Directory, Microsoft Entra ID, DNS, DHCP, wireless controllers, and campus network infrastructure.
  • Assist with administration of related network services, such as monitoring/management applications, firewalls, load balancers, and DDI infrastructure.
  • Develop automation utilizing REST APIs, Python, PowerShell, or Ansible to improve operational efficiency and reduce repetitive administrative tasks.
  • Produce and maintain operational documentation, disaster recovery procedures, architectural diagrams, standards, and knowledge base documentation.
  • Participate in after-hours maintenance activities, emergency response, and on-call support for critical enterprise authentication and network management services.
  • Other related duties as required or directed.
MINIMUM QUALIFICATIONS
  • Bachelor's degree in Computer Science, Information Technology, Engineering, or related field and four (4) years of progressively responsible experience supporting enterprise network infrastructure; or eight (8) years of equivalent experience.
  • Demonstrated experience administering production enterprise network infrastructure including routing, switching, wireless networking, or network security technologies.
  • Demonstrated experience supporting enterprise authentication services utilizing RADIUS, TACACS+, IEEE 802.1X, or comparable authentication technologies.
  • Experience troubleshooting authentication issues between ISE and Active Directory, Microsoft Entra ID, LDAP, certificate services, or other enterprise identity providers.
  • Experience administering systems on dedicated appliances and/or hosted on virtualization platforms such as VMWare.
  • Experience using enterprise network monitoring, logging, and management systems.
  • Experience preparing technical documentation, operational procedures, and change management documentation.
  • Demonstrated written communication skills with technical and non-technical stakeholders.
PREFERRED QUALIFICATIONS
  • Experience integrating Cisco ISE with Microsoft Entra ID, Active Directory, PKI, Cisco Catalyst Center, or enterprise certificate services.
  • Experience implementing or supporting EAP-TLS onboarding software such as SecureW2 Join Now, EduRoam Configuration Assistance Tool (CAT), or similar.
  • Experience administering Cisco Catalyst and/or Juniper (HPE) Mist wireless infrastructure supporting EduRoam or other federated wireless authentication services.
  • Experience administering Infoblox IPAM, DNS, and DHCP services.
  • Experience administering enterprise network monitoring and management platforms including SNMP, Syslog, telemetry, configuration management, and performance analytics.
  • Experience automating enterprise infrastructure administration utilizing Python, PowerShell, REST APIs, or Ansible.
  • Experience administering or performing policy management on enterprise firewalls such as Palo Alto, Fortinet, or Cisco.
  • Experience with using ISE to implement user security tagging in an enterprise environment.
  • Cisco CCNP Enterprise, CCNP Security, Cisco Certified Specialist – Identity Services, Microsoft Identity and Access Administrator Associate, or comparable professional certifications.
  • Experience supporting large, complex higher education, healthcare, research, or similarly distributed enterprise environments.
APPOINTMENT TERMS

This is a full-time, permanent position. The University offers a competitive salary, and outstanding benefits , including employee and dependent tuition waivers at UConn, and a highly desirable work environment.

Other rights, terms, and conditions of employment are contained in the collective bargaining agreement between the University of Connecticut and the University of Connecticut Professional Employees Association (UCPEA).

TERMS AND CONDITIONS OF EMPLOYMENT

Employment of the successful candidate is contingent upon the successful completion of a pre-employment criminal background check.

TO APPLY

Please apply online atFaculty and Staff Positions , Search #499763 to upload a resume, cover letter, and contact information for three (3) professional references. Applicants must clearly demonstrate how they meet the stated minimum qualifications, and any preferred qualifications they may possess, in their application materials.

This job posting is scheduled to be removed at 11:55 p.m. Eastern time on August

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Engineer and Manager
Senior Network Engineer and Manager

University of Connecticut • Hartford (CT)

On-site
USD 106,474 - 138,416
Defined contribution with employer 1
Excellent healthcare options
35‑hour work week
+2
ISE & Enterprise Identity Networking Specialist
ISE & Enterprise Identity Networking Specialist

University of Connecticut • Storrs (CT)

Hybrid
USD 110,000 - 140,000
Retirement options
Health care options
Vacation and holidays
+3
CEN Chief Technology Officer
CEN Chief Technology Officer

University of Connecticut • Connecticut

Hybrid
USD 140,000 - 175,000
Retirement options
Healthcare
Vacation days
+2
Information Security Engineer 2/3
Information Security Engineer 2/3

University of Connecticut • Storrs (CT)

On-site
USD 95,000 - 125,000
Healthcare options
35-hour work week
Vacation & leave
+3
Enterprise Network Engineer II
Enterprise Network Engineer II

Phase2 Technology • Austin (TX)

On-site
USD 80,000 - 100,000
Competitive health benefits
Training and conference opportunities
Tuition assistance
Network Authentication Administrator Level II
Network Authentication Administrator Level II

Omm IT Solutions • Baltimore (MD)

Hybrid
USD 110,000 - 160,000
Infrastructure and Security Administrator
Infrastructure and Security Administrator

Hocking College • Nelsonville (OH)

On-site
USD 65,000 - 90,000
Network Administrator (Senior Systems Administrator #1356)
Network Administrator (Senior Systems Administrator #1356)

Illinois State Board of Education • Illinois

On-site
USD 68,000 - 103,000
Server Administrator
Server Administrator

Shaw University • Raleigh (NC)

On-site
USD 60,000 - 80,000
Network Analyst and Student Intern Coordinator
Network Analyst and Student Intern Coordinator

The Chronicle Of Higher Education, Inc. • Teaneck Township (NJ)

On-site
USD 54,000 - 88,000