27 Aug
|
CGvak Software Exports
|
Bengaluru
27 Aug
CGvak Software Exports
Bengaluru
Roles & Responsibilities
Key Responsibilities NAC Design & Architecture • Design and implement scalable, highly available NAC solutions across campus, branch, data centre, and remote-access environments. • Develop NAC architecture standards, policy frameworks, HLD/LLD design documents, and deployment runbooks. • Lead identity-driven access and dynamic segmentation initiatives aligned with Zero Trust Network Access (ZTNA) principles. • Define authentication, authorization, and enforcement models for wired (802.1X/MAB), wireless, and VPN access. 1 ClearPass / ISE Expertise (Core) • Deep hands-on expertise in at least one platform: ◦ Aruba ClearPass – Policy Manager, OnGuard (posture), OnBoard (BYOD / certificate provisioning), Guest, and Insight. ◦ Cisco ISE – policy sets, profiling, posture, TrustSec/SGT, pxGrid, and Adaptive Network Control (ANC). • Build and tune service/policy logic, enforcement profiles, and role-mapping for complex multi-site environments. • Manage platform upgrades, clustering/redundancy, certificate lifecycle, and licensing. Authentication, Authorization & Policy • Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), and web/captive-portal authentication. • Configure and operate RADIUS and TACACS+ for network access and device administration (AAA). • Design role-based access using energetic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role). • Integrate with identity stores: Active Directory, LDAP, Azure AD / Entra ID, and certificate authorities (PKI). Profiling,
Posture & Endpoint Compliance • Implement device profiling and fingerprinting to classify managed, unmanaged, and IoT/OT endpoints. • Configure posture / compliance assessment and remediation workflows for endpoint health. • Integrate with MDM/UEM (Intune, Jamf, Workspace ONE) and EDR/AV for compliance signals. Guest, BYOD & Device Onboarding • Design and operate guest access, sponsor approval, and self-registration portals. • Implement BYOD onboarding and certificate-based provisioning (EAP-TLS). • Manage IoT/headless device onboarding and segmentation. Integrations & Ecosystem • Integrate NAC with firewalls, SIEM/SOAR, ITSM, and threat-intelligence platforms for closed-loop response. • Enable contextual data sharing (pxGrid, REST APIs, syslog) across the security stack. • Coordinate with wired/wireless infrastructure (Aruba, Cisco, Juniper Mist) for consistent enforcement. Multi-Vendor & Emerging NAC (added advantage) • Working knowledge of cloud-native / agentless NAC such as Arista Agni, Forescout, Portnox, or FortiNAC. • Ability to compare, position, and migrate between on-prem and cloud-delivered NAC models. 2 Operations & Support • Provide L3 support for complex NAC authentication, policy, and connectivity issues. • Troubleshoot RADIUS/802.1X failures, certificate issues, and policy mis-hits across environments. • Perform health checks, capacity planning, and performance tuning of NAC infrastructure. Governance & Documentation • Maintain policy matrices, NAC design documents, configurations, and SOPs. • Ensure compliance with enterprise security policies and regulatory standards. • Support audits, access reviews, and risk assessments.
📌 NAC Security Engineer (Bengaluru)
🏢 CGvak Software Exports
📍 Bengaluru