- Company Name
- HMG AMERICA LLC
- Job Title
- Network Engineer
- Job Description
-
**Job Title:**
Network Engineer
**Role Summary**
Design, deploy, configure, and maintain Cisco Identity Services Engine (ISE) for network access control and policy enforcement, while configuring and troubleshooting enterprise firewalls (Cisco ASA, Firepower, Palo Alto, Fortinet). Ensure secure wired, wireless, and VPN environments, support zero‑trust implementation, and collaborate with security teams on incident response and documentation.
**Expectations**
- Deliver secure, scalable access‑control solutions with minimal downtime.
- Keep ISE and firewall platforms patched, backed up, and upgraded.
- Provide rapid troubleshooting and root‑cause analysis for authentication/authorization failures.
- Maintain comprehensive, up‑to‑date network documentation and SOPs.
**Key Responsibilities**
- Design, configure, and manage Cisco ISE (2.x/3.x): 802.1X, MAB, posture, device profiling, guest portals, BYOD, EAP‑TLS/PEAP.
- Integrate ISE with Active Directory, PKI, and other authentication services.
- Develop and maintain ISE policies, device groups, and authorization profiles.
- Monitor ISE logs, troubleshoot authentication issues, and perform life‑cycle tasks (patching, backup, upgrades).
- Configure, manage, and troubleshoot Cisco ASA, Firepower (FTD), Palo Alto, and Fortinet firewalls: ACLs, NAT, VPNs, security zones.
- Monitor and analyze firewall logs to detect anomalies and potential security breaches.
- Collaborate with security teams to enforce Zero Trust, micro‑segmentation, and compliance requirements.
- Conduct firewall performance tuning and ensure adherence to security standards.
- Support incident response, root‑cause analysis, and remediation for network security events.
- Create and maintain network diagrams, documentation, and SOPs.
**Required Skills**
- ≥5 years of network security engineering experience.
- Hands‑on Cisco ISE deployment and management (2.x/3.x).
- Strong knowledge of RADIUS, TACACS+, EAP, 802.1X, VLANs, and NAC concepts.
- Experience with Cisco ASA, Firepower, or next‑generation firewalls (NGFW).
- Proficiency with Cisco Catalyst switches, wireless controllers, and VPN technologies.
- Familiarity with network monitoring tools (SolarWinds, Splunk, Wireshark).
- Scripting/automation skills (Python, Ansible) for configuration management.
- Understanding of Zero Trust Network Access (ZTNA), SASE, and multi‑vendor firewall platforms (Palo Alto, Fortinet, Check Point).
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, or related field.
- Cisco certifications preferred: CCNP Security, CCIE Security, Cisco ISE Specialist.
- Other relevant Cisco credentials (e.g., CCNA Security) acceptable.
Santa clara, United states
On site
Mid level
05-03-2026