Senior Network Security Engineer - Cisco ISE & Zero Trust...

KonnectIT
Chicago, IL

We are seeking a Senior Network Security Engineer with deep expertise in Cisco Identity Services Engine (ISE) and identity-driven network segmentation to support and enhance a modern enterprise security architecture. This role will focus on designing, implementing, and operating network access control (NAC) and TrustSec-based segmentation across wired, wireless, and data center environments.

The ideal candidate will have extensive hands-on experience deploying and managing Cisco ISE platforms and will play a key role in advancing Zero Trust Network Access (ZTNA) strategies. This position requires strong technical depth across authentication protocols, identity-based policy enforcement, and enterprise networking fundamentals. This position requires regular onsite presence at client locations within the Chicago metropolitan area (3–4 days per week). Candidates must currently reside within commuting distance of Chicago and be able to attend onsite meetings, deployments, and troubleshooting activities on short notice.

**** Applicants who are not currently located in the Chicago area will not be considered. ****

Key Responsibilities

  • Design, deploy, and operate Cisco ISE (2.x and 3.x) environments supporting enterprise NAC and identity-based policy enforcement.

  • Develop and manage ISE policy sets, profiling policies, posture assessment, and guest/BYOD access workflows.

  • Implement and maintain 802.1X and MAB authentication across wired and wireless environments.

  • Integrate ISE with Active Directory, PKI infrastructures, certificate-based authentication, and MDM platforms.

  • Configure and maintain TACACS+ device administration for network infrastructure access control.

  • Support pxGrid integrations to enable identity and context sharing across security platforms.

  • Design and implement TrustSec segmentation architectures using Security Group Tags (SGTs) and SGACL policies.

  • Enable identity-to-role mapping and enforce segmentation policies across Catalyst switches, Nexus platforms, and wireless controllers.

  • Lead the design and implementation of microsegmentation strategies across campus and data center environments.

  • Perform advanced troubleshooting using ISE live logs, session directory, packet captures, and switch/WLC debugging tools.

  • Collaborate with network and security teams to implement Zero Trust principles, minimizing lateral movement and enforcing least-privilege access.

  • Manage network security changes through structured implementation plans, pilot deployments, and staged rollouts.

  • Develop testing procedures and rollback strategies to ensure stable production operations.

  • Travel to multiple sites within the city of Chicago as needed and work onsite 3–4 days per week to support network deployments and troubleshooting activities.

Mandatory Skills

  • 5+ years of hands-on experience deploying and operating Cisco Identity Services Engine (ISE).

  • Strong expertise in:

    • ISE Policy Sets

    • Profiling and Posture Assessment

    • Guest and BYOD access workflows

    • pxGrid integrations

    • TACACS+ device administration

  • Deep understanding of 802.1X and MAB authentication for wired and wireless networks.

  • Strong knowledge of supplicant behavior, Change of Authorization (CoA), and EAP methods such as PEAP and EAP-TLS.

  • Experience integrating ISE with:

    • Active Directory / Identity Providers

    • PKI and certificate-based authentication

    • Mobile Device Management (MDM) platforms

  • Hands-on experience with Cisco TrustSec:

    • SGT classification and propagation

    • SGACL policy design and enforcement

  • Experience implementing segmentation across Catalyst switches, Nexus platforms, and wireless controllers.

  • Advanced troubleshooting skills using ISE logs, packet captures, session directory, and network device debugging tools.

  • Strong knowledge of Layer 2 and Layer 3 networking fundamentals.

  • Experience with routing protocols including OSPF and BGP.

  • Experience with ACLs, QoS, NAT, Spanning Tree, and wireless networking (WLC / 802.11).

  • Familiarity with enterprise network services including NTP, DNS, and DHCP.

  • Proven experience supporting enterprise campus and data center network architectures.

Desirable Skills

  • Experience designing or supporting Zero Trust Network Access (ZTNA) architectures.

  • Strong understanding of identity-driven access control and least-privilege security models.

  • Knowledge of north–south vs. east–west traffic patterns in enterprise environments.

  • Experience performing threat modeling and lateral movement analysis within segmented networks.

  • Experience implementing data center or host-based microsegmentation.

  • Experience with large-scale network policy orchestration and automation.

  • Cisco certifications such as CCNP Security, CCIE Security, or Cisco ISE Specialist.

Additional Requirements

• Candidates must currently reside in the Chicago metropolitan area.
• Identity will be verified during the interview process.
• Candidates should expect live technical interviews and onsite verification meetings as part of the hiring process.
• This role cannot be performed fully remotely.

Compensation

$90–$100 per hour (1099/W2)

Posted 2026-05-06

Recommended Jobs

Risk and Safety Consultant (Oak Brook)

BBSI
Oak Brook, IL

Our focus is business owners. Is yours? Everything we do at BBSI is in support of business owners. We facilitate conversations around a broad range of organizational areas that allow business owner…

View Details
Posted 2026-04-27

AI Lead (Rolling Meadows)

Associated Insurance and Risk Management Advisors
Rolling Meadows, IL

AI Lead Hybrid Remote • Rolling Meadows, IL Description Associated is one of the top privately held insurance and risk management firms in the country. We assist businesses and individu…

View Details
Posted 2026-04-27

Project Surveyor

V3 Companies Ltd
Woodridge, IL

Job Description Job Description V3 Companies, a multidisciplinary AEC firm, is seeking a Project Surveyor, where you will contribute to career-defining projects that reimagine our built and natur…

View Details
Posted 2026-04-11

Customer Support Manager (Oak Brook)

RHM Staffing Solutions
Oak Brook, IL

Position: Customer Support Manager Reports to: Operations Manager Job Summary: The Customer Support Manager (CSM) is responsible for providing timely and value-adding customer service to…

View Details
Posted 2026-04-27

Warehouse Personnel

Furniture Row
Peoria, IL

Our Furniture Row Center in Peoria, IL is now hiring. We are looking for driven individuals to join our part-time Warehouse team in our store! Job Requirements: # Willing and able to work weekend…

View Details
Posted 2026-05-07

Server

The Warbler
Chicago, IL

The Warbler, a wonderful high volume neighborhood restaurant in Lincoln Square with a beautifully appointed 125-seat patio including a full outdoor bar, as well as our open-air dining rooms are prepa…

View Details
Posted 2026-04-12

CATERING MANAGER - NAPERVILLE, IL

Eurest USA
Naperville, IL

Position Title: CATERING MANAGER - NAPERVILLE, IL Salary: $75,000 - $80,000 /year As the leader in business and industry dining, Eurest is the company to join if you want a rewarding care…

View Details
Posted 2026-05-03

Civil Associate Engineering Technician - Water

Dynamics ATS
New, IL

Civil  Associate Engineering Technician - Water   JOB-10045943   Anticipated Start Date 4/20/2026   Location Charlotte, NC   Type of Employment Contract Hire   Employer Info…

View Details
Posted 2026-04-06

Physician

Innovative Care
Chicago, IL

Medical Assistant Innovative Care is a medical group that brings primary care, urgent care and therapy to serve our patients better. We are looking for an experienced full time Medical Assistant to w…

View Details
Posted 2026-01-29

Investment Funds Associate (Chicago)

Sonder Consultants
Chicago, IL

A leading US firm known for its distinctive one-firm culture and deep bench across the US is hiring a senior investment funds associate into its Chicago office. The funds practice here advises major …

View Details
Posted 2026-04-27