29 Aug
|
CGvak Software Exports
|
Bengaluru
29 Aug
CGvak Software Exports
Bengaluru
Roles & Responsibilities
Key Responsibilities NAC Design &
• Architecture • Design and implement scalable, highly available NAC solutions across campus, branch, data centre, and remote-access environments.
• Develop NAC architecture standards, policy frameworks, HLD/LLD design documents, and deployment runbooks.
• Lead identity-driven access and energetic segmentation initiatives aligned with Zero Trust Network Access (ZTNA) principles.
• Define authentication, authorization, and enforcement models for wired (802.1X/MAB), wireless, and VPN access. 1 ClearPass / ISE Expertise (Core) • Deep hands-on expertise in at least one platform: ◦ Aruba ClearPass – Policy Manager, OnGuard (posture), OnBoard (BYOD / certificate provisioning), Guest, and Insight. ◦ Cisco ISE – policy sets, profiling, posture, TrustSec/SGT, pxGrid, and Adaptive Network Control (ANC).
• Build and tune service/policy logic, enforcement profiles, and role-mapping for complex multi-site environments.
• Manage platform upgrades, clustering/redundancy, certificate lifecycle, and licensing. Authentication, Authorization &
• Policy • Implement 802.1X (EAP-TLS, PEAP, EAP-TTLS), MAC Authentication Bypass (MAB), and web/captive-portal authentication.
• Configure and operate RADIUS and TACACS+ for network access and device administration (AAA).
• Design role-based access using dynamic VLAN assignment, downloadable ACLs (dACLs), and security group tags (SGT/role).
• Integrate with identity stores: Active Directory, LDAP, Azure AD / Entra ID, and certificate authorities (PKI). Profiling, Posture &
• Endpoint Compliance • Implement device profiling and fingerprinting to classify managed, unmanaged, and IoT/OT endpoints.
• Configure posture / compliance assessment and remediation workflows for endpoint health.
• Integrate with MDM/UEM (Intune, Jamf, Workspace ONE) and EDR/AV for compliance signals. Guest, BYOD &
• Device Onboarding • Design and operate guest access, sponsor approval, and self-registration portals.
• Implement BYOD onboarding and certificate-based provisioning (EAP-TLS).
• Manage IoT/headless device onboarding and segmentation. Integrations &
• Ecosystem • Integrate NAC with firewalls, SIEM/SOAR, ITSM, and threat-intelligence platforms for closed-loop response.
• Enable contextual data sharing (pxGrid, REST APIs, syslog) across the security stack.
• Coordinate with wired/wireless infrastructure (Aruba, Cisco, Juniper Mist) for consistent enforcement. Multi-Vendor &
• Emerging NAC (added advantage) • Working knowledge of cloud-native / agentless NAC such as Arista Agni, Forescout, Portnox, or FortiNAC.
• Ability to compare, position, and migrate between on-prem and cloud-delivered NAC models. 2 Operations &
• Support • Provide L3 support for complex NAC authentication, policy, and connectivity issues.
• Troubleshoot RADIUS/802.1X failures, certificate issues, and policy mis-hits across environments.
• Perform health checks, capacity planning, and performance tuning of NAC infrastructure. Governance &
• Documentation • Maintain policy matrices, NAC design documents, configurations, and SOPs.
• Ensure compliance with enterprise security policies and regulatory standards.
• Support audits, access reviews, and risk assessments.
📌 NAC Security Engineer (Bengaluru)
🏢 CGvak Software Exports
📍 Bengaluru