1

Cisco Ise Security Engineer Jobs (NOW HIRING)

Our team is seeking an experienced Cisco Identity Services Engine (ISE) Engineer to support a ... Collaborate with network, security, server, and application teams to resolve operational issues.

Our team is seeking an experienced Cisco Identity Services Engine (ISE) Engineer to support a ... Collaborate with network, security, server, and application teams to resolve operational issues.

Job#: 3046849 Cisco Wireless/ISE Engineer Location: Tampa, Florida (very minimal on-site in Tampa ... Manage and audit the Catalyst Center, where ISE is run, to track devices for security purposes.

$95K - $130K/yr

... security compliance requirements. โ€ข Development of radius policies for dynamic assignment of ... Cisco ISE Engineer creating design documentation, building ISE rules, policies, implementing ISE ...

$95K - $130K/yr

As a Network Security Engineer , you will be at the forefront of designing, deploying, and ... Design and manage enterprise NAC solutions administer Cisco ISE clusters, develop RADIUS and TACACS ...

Serve as the primary engineer responsible for daily Cisco ISE operations and support ... Collaborate with network, security, server, and application teams to resolve operational issues.

ISE Engineer

Merrifield, VA ยท Remote

$107K - $146K/yr

This role is for a Cisco Identity Services Engine (ISE) Network Access Control (NAC) Engineer with 5-10 years of overall IT/network security experience and 3-5 years of hands-on Cisco ISE experience.

ISE Engineer

Merrifield, VA ยท Remote

$107K - $146K/yr

This role is for a Cisco Identity Services Engine (ISE) Network Access Control (NAC) Engineer with 5-10 years of overall IT/network security experience and 3-5 years of hands-on Cisco ISE experience.

ISE Engineer

Merrifield, VA ยท Remote

$107K - $146K/yr

This role is for a Cisco Identity Services Engine (ISE) Network Access Control (NAC) Engineer with 5-10 years of overall IT/network security experience and 3-5 years of hands-on Cisco ISE experience.

ISE Engineer

Merrifield, VA ยท Remote

$107K - $146K/yr

This role is for a Cisco Identity Services Engine (ISE) Network Access Control (NAC) Engineer with 5-10 years of overall IT/network security experience and 3-5 years of hands-on Cisco ISE experience.

next page

Showing results 1-20

Cisco Ise Security Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do cisco ise security engineer jobs pay per year?

As of Sep 12, 2026, the average yearly pay for cisco ise security engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What are popular job titles related to Cisco Ise Security Engineer jobs?

For Cisco Ise Security Engineer jobs, the most frequently searched job titles are:

Network Engineer 3 - Forescout/Cisco ISE

Suitland, MD โ€ข On-site

Tria Federal
IT Servicesย โ€ขย 501 - 1,000 employees

$112K - $154K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 14 days ago


Job description

Senior Network Security Engineer

Tria Federal is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy ForeScout CounterACT NAC/NAM system and adopts Cisco Identity Services Engine (ISE) as the new accesscontrol platform. The engineer will help configure and manage Cisco ISE across the environment, handling AAA services, wired and wireless 802.1X authentication, device administration, and posture checks for users and devices.

This role also supports the agency's modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from ForeScout to Cisco ISE.

Basic Requirements

  • Senior Network Security Engineer responsible for designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform, including TACACS+/RADIUS services, device administration policies, and wired/wireless 802.1X authentication.
  • Experience working with Cisco ISE deployed on Cisco SNS3715 appliances, preferably in a twonode clustered, highavailability setup.
  • Understanding of ForeScout CounterACT, including legacy NAC/NAM policies, device classification, and access workflows, to support the migration to Cisco ISE.
  • Experience providing general wireless network support, including basic troubleshooting, controller interactions, and wireless access workflows.
  • Handson experience integrating Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, groupbased policy decisions, and directorybased authentication.
  • Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE with expertise in:
  • Authentication and authorization policies (RADIUS/TACACS+)
  • 1X/EAP methods for wireless and wired access
  • Device profiling, posture checks, and endpoint compliance
  • Certificatebased authentication (EAPTLS) and PKI integration
  • AAA integrations for switches, appliances, firewalls, and wireless controllers
  • Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers, including guest/registration page redirection and wireless onboarding.
  • Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE while aligning with Zero Trust principles.
  • Four (4) years of experience supporting identitycentric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls.
  • Solid understanding of telecommunications, network security, and Zero Trust best practices.
  • Strong communication skills with the ability to explain Cisco ISE, NAC/NAM, and AAA concepts to both technical and nontechnical audiences.
  • Bachelor's degree in Information Technology, Cybersecurity, or a related field.
  • Preferred certifications: Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certifications.

Responsibilitiesย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย ย 

  • Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication.
  • Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS3715 appliances, ensuring high availability and consistent policy enforcement.
  • Support the agency's migration from ForeScout CounterACT to Cisco ISE, including reviewing legacy ForeScout policies, device groups, and access rules and mapping them into ISE policy sets.
  • Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams.
  • Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policydriven access control.
  • Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, groupbased authorization, and directorybased authentication workflows.
  • Deploy, configure, and maintain Cisco ISE components, including:
  • Policy Sets, Authorization Profiles, and Authentication Rules
  • TACACS+ device administration
  • 1X for wired and wireless networks
  • Profiling, posture, and compliance policies
  • Certificatebased authentication and PKI integrations
  • Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues.
  • Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience.
  • Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures.
  • Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts.

Benefits and Perks:ย 

  • Medical, dental, and vision insurance - Multiple plan options through Cigna and VSP Vision Care with employer contributions.ย ย 
  • 401(k) retirement plan - 5% employer match with immediate vesting.ย ย 
  • Paid time off (PTO) - Accrual-based PTO with 11 paid federal holidays and 1 floating holiday.ย ย 
  • Parental & maternity leave - 20 days paid parental leave and 12 weeks fully paid maternity leave.ย ย Disability & life insurance - Company-paid short-term & long-term disability, basic life insurance, and AD&D.ย ย 
  • Tuition & certification reimbursement - Support for career growth with up to $5,250 per year for tuition and certificationย assistance.ย ย 
  • Commuter benefits -ย Pre-taxย savings for public transit and rideshare expenses.ย ย 
  • Employee referral bonus - Reward program for successful candidate referrals.ย 

Public Trust Clearance:ย 

US Citizenship is a MUST given the nature of the work. Many of our roles require the hired candidate to go through public trust clearance. A minimum of 3 years of stay in the U.S. within the last 5 years is required to be eligible to qualify for public trust clearance sponsorship.ย ย 

Work Location:ย 

For this specifc role, it's essential that candidates are able to work onsite. Start time for the day onsite has to be between 7 AM- 9 AM ET and it will be a standard 8 hour day.

Tria Federal, operates primarily in the Eastern Time Zone, with standard work hours from 9 AM - 5 PM ET and flexibility around start and end times based on team and customer needs. We have open-collaboration offices in Arlington, VA, and Baltimore, MD for those who prefer to work on-site.ย 

EEO Statement:ย 

Tria Federal is an affirmative action and equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.ย Triaย is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, or toย participateย in the job application or interview process, contact the Talent Acquisition Team atย recruiting@triafed.comย ย ย 

Know your rights poster:ย https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdfย ย