Senior Network Security Engineer - Cisco ISE & Zero Trust Segmentation
$90 - $100 per hourKonnectIT
Job Description
Job Description
We are seeking a Senior Network Security Engineer with deep expertise in Cisco Identity Services Engine (ISE) and identity-driven network segmentation to support and enhance a modern enterprise security architecture. This role will focus on designing, implementing, and operating network access control (NAC) and TrustSec-based segmentation across wired, wireless, and data center environments.
The ideal candidate will have extensive hands-on experience deploying and managing Cisco ISE platforms and will play a key role in advancing Zero Trust Network Access (ZTNA) strategies. This position requires strong technical depth across authentication protocols, identity-based policy enforcement, and enterprise networking fundamentals. This position requires regular onsite presence at client locations within the Chicago metropolitan area (3–4 days per week). Candidates must currently reside within commuting distance of Chicago and be able to attend onsite meetings, deployments, and troubleshooting activities on short notice.
**** Applicants who are not currently located in the Chicago area will not be considered. ****
Key Responsibilities
Design, deploy, and operate Cisco ISE (2.x and 3.x) environments supporting enterprise NAC and identity-based policy enforcement.
Develop and manage ISE policy sets, profiling policies, posture assessment, and guest/BYOD access workflows.
Implement and maintain 802.1X and MAB authentication across wired and wireless environments.
Integrate ISE with Active Directory, PKI infrastructures, certificate-based authentication, and MDM platforms.
Configure and maintain TACACS+ device administration for network infrastructure access control.
Support pxGrid integrations to enable identity and context sharing across security platforms.
Design and implement TrustSec segmentation architectures using Security Group Tags (SGTs) and SGACL policies.
Enable identity-to-role mapping and enforce segmentation policies across Catalyst switches, Nexus platforms, and wireless controllers.
Lead the design and implementation of microsegmentation strategies across campus and data center environments.
Perform advanced troubleshooting using ISE live logs, session directory, packet captures, and switch/WLC debugging tools.
Collaborate with network and security teams to implement Zero Trust principles, minimizing lateral movement and enforcing least-privilege access.
Manage network security changes through structured implementation plans, pilot deployments, and staged rollouts.
Develop testing procedures and rollback strategies to ensure stable production operations.
Travel to multiple sites within the city of Chicago as needed and work onsite 3–4 days per week to support network deployments and troubleshooting activities.
Mandatory Skills
5+ years of hands-on experience deploying and operating Cisco Identity Services Engine (ISE).
Strong expertise in:
ISE Policy Sets
Profiling and Posture Assessment
Guest and BYOD access workflows
pxGrid integrations
TACACS+ device administration
Deep understanding of 802.1X and MAB authentication for wired and wireless networks.
Strong knowledge of supplicant behavior, Change of Authorization (CoA), and EAP methods such as PEAP and EAP-TLS.
Experience integrating ISE with:
Active Directory / Identity Providers
PKI and certificate-based authentication
Mobile Device Management (MDM) platforms
Hands-on experience with Cisco TrustSec:
SGT classification and propagation
SGACL policy design and enforcement
Experience implementing segmentation across Catalyst switches, Nexus platforms, and wireless controllers.
Advanced troubleshooting skills using ISE logs, packet captures, session directory, and network device debugging tools.
Strong knowledge of Layer 2 and Layer 3 networking fundamentals.
Experience with routing protocols including OSPF and BGP.
Experience with ACLs, QoS, NAT, Spanning Tree, and wireless networking (WLC / 802.11).
Familiarity with enterprise network services including NTP, DNS, and DHCP.
Proven experience supporting enterprise campus and data center network architectures.
Desirable Skills
Experience designing or supporting Zero Trust Network Access (ZTNA) architectures.
Strong understanding of identity-driven access control and least-privilege security models.
Knowledge of north–south vs. east–west traffic patterns in enterprise environments.
Experience performing threat modeling and lateral movement analysis within segmented networks.
Experience implementing data center or host-based microsegmentation.
Experience with large-scale network policy orchestration and automation.
Cisco certifications such as CCNP Security, CCIE Security, or Cisco ISE Specialist.
Additional Requirements
• Candidates must currently reside in the Chicago metropolitan area.
• Identity will be verified during the interview process.
• Candidates should expect live technical interviews and onsite verification meetings as part of the hiring process.
• This role cannot be performed fully remotely.
Compensation
$90–$100 per hour (1099/W2)
- ..., Zscaler ZIA/ZPA and Zero Trust Architecture - Overview... ...Zscaler (ZIA/ZPA) and secure access transformation.... ..., eliminating legacy network assumptions, and delivering... ...forwarding and ZPA segmentation. Design, implement,... ...best practices. Mentor engineers and elevate client...SuggestedShift work
$170k - $200k
...perspectives at AHEAD. Senior Technical... ...firewall, network access control... ...deployment (Cisco Secure Firewall, Palo... ...Networks), Cisco ISE‑based network... ..., and SASE/Zero Trust architectures... ...Design network segmentation architectures... ...Identity Services Engine (ISE) for 802....SeniorWork at officeRemote work$150k - $300k
...technology company is seeking a Principal Consultant to spearhead Zero Trust architecture solutions with a focus on Zscaler (ZIA/ZPA). The role requires a minimum of 8 years of experience in network security, expertise in Zero Trust frameworks, and proven skills in...Suggested$110k - $150k
...Job Description Sr. Network Security Engineer – Direct Hire/Local... ...Healthcare Infrastructure | Zero Trust | Multi‑Vendor |... ...4 is looking for a Senior Network Security... ...Meraki, Cambium, Aruba, Cisco, Ruckus).... ...Control (NAC) Micro‑segmentation VPN reduction & identity...SeniorLocal areaRemote workNight shift- ...Title: Senior Cyber Recovery Engineer Location: Chicago, IL Hybrid - onsite 3 days per week Duration: 12+ months... ...recovery automation. ~ Strong understanding of network segmentation, identity isolation, and zero-trust concepts as applied to clean room...SeniorFor contractors3 days per week
$140k - $165k
...to hear from you. The Role As a Senior Security Engineer, you'll harden the security posture... ...services, reducing risk across IAM, network segmentation, container security, secrets, and data... ...: Wiz, Cloudflare (WAF, Gateway, Zero Trust), GitHub Advanced Security,...SeniorFull time$117k - $158k
...Senior Network Security Engineer Wintrust provides community and commercial banking, specialty finance... ...IPS, DNS, IPAM, enterprise proxy and Zero Trust principles are core for helping... ...architectures, and utilizing DNS Filtering (Cisco Umbrella) and ability to evaluate...SeniorTemporary workFlexible hours$172k - $225.7k
...Senior Security Architect At Snowflake, we are powering... ...AI as a high-trust collaborator that is... ...Security Applied Field Engineering (AFE) organization is... ...in Data, Security, Networking, Infrastructure or AI... ...architectures, including micro-segmentation, zero-trust principles,...SeniorFlexible hours$80k - $92k
...are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business... ...(Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing... .../FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec...SeniorLocal areaRemote work$220k - $275k
...us, and build real world value. THE WORK: As a Senior Staff Security Engineer, you will be one of Ripple's most senior... ...for Treasury across Azure and AWS, including IAM, network segmentation, encryption, zero trust controls, Kubernetes traffic policies, and DDoS...SeniorFull timeWork at officeLocal area$170.6k - $390k
...career in information security! The opportunity The Senior Network Security... ...in Cybersecurity Engineering, where you will play... ...technical experience in Zero Trust and Network... ...standards for firewalls, segmentation, VPNs, secure... ...Experience with Cisco, Palo Alto...SeniorSummer holidayRemote workFlexible hours$122.4k - $228k
...design and maturity of end-to-end cloud security across multi-cloud environments (AWS... ...cloud architecture aligned to Zero Trust principles Act as enterprise SME... ...key management, data protection Network Security - segmentation, private access, WAF, DDoS Workload...SeniorContract workPart timeLocal areaImmediate start- ...Title: Senior Security Architect - SaaS / Cloud Platforms Location... ...platforms Deep hands-on engineering work Important... ...Very strong understanding of network architecture concepts... ...Very good understanding of zero-trust architecture and working experience...SeniorWork experience placementWork at office
$175k - $195k
Huron Consulting Group Inc. is hiring a Senior AI Security Architect in Chicago, Illinois, to design and secure enterprise AI solutions. This role focuses on security and governance across the AI lifecycle, addressing emerging security threats. The candidate should possess...Senior$115k - $135k
Auria is seeking a Senior Network Engineer to manage and optimize enterprise network infrastructure in Chicago, IL. The role involves leading troubleshooting efforts and collaborating on cybersecurity initiatives to ensure high availability across all sites. Qualified candidates...Senior$124k - $280k
...vulnerabilities, develop secure systems, and... ..., and network to deliver... ...Cyber Defense and Engineering team, you will... ...engineering, segmentation, and security... ...transformation. As a Senior Manager, you... ...serve as a trusted advisor to... ...certifications - Cisco CCNP Security,...Senior- AgileEngine, LLC. in Chicago is seeking a Senior Site Reliability Engineer to ensure operational stability across multi-cloud security environments including Azure, AWS, and GCP. The ideal candidate will have over 5 years of experience, expertise in multi-cloud defense...SeniorRemote jobWork at officeFlexible hours
$131k - $169k
...magazine's Best Small Workplaces™ List. Senior Security Engineer Our Engineering Standards at Karbon... ...Engineers who are confident in network & security fundamentals, driven to grow... ...understand the need to build relationships and trust across the organization to enhance...SeniorWork at officeWork from homeFlexible hoursDay shift$130k - $170k
...of Openings: 1 Auria is seeking a Senior Cloud Security Engineer to support the security architecture... ...identity, encryption, logging, and network security withing AWS environments.... ...security monitoring tools Knowledge of Zero Trust Architecture principles DoD 8570 /...SeniorContract workWork at officeRemote workFlexible hours$164.6k - $288k
Northern Trust in Chicago is seeking a Senior Relationship/Trust Advisor in Wealth Management to manage complex client relationships, particularly high net worth (HNW) and ultra-high net worth (UHNW) clients. This role requires 12-15 years of experience in trust administration...Senior$115.5k - $150k
Plante-Moran in Chicago seeks a qualified candidate to administer trusts and provide holistic financial planning services. The role involves collaborating with clients and colleagues, overseeing trust activities, and contributing to practice development. A Bachelor's degree...Senior- Larson Maddox in Chicago seeks a Senior Trusts & Estates Attorney focused on high net worth estate planning. This role involves advising clients, drafting complex documents, and partnering with a collaborative team. The ideal candidate has significant experience in trusts...Senior
$160k - $200k
..., Paze, and so much more. As a trusted name in payments, we partner with... ..., Product Development and Engineering teams to enable them to build and enhance security in EWS products and Services in... ...operating system, application, network, and database security architectures...SeniorHourly payWork at officeImmediate startVisa sponsorshipWork visaFlexible hours$100k - $202k
Plante-Moran is seeking a Tax Manager to oversee advanced trust tax operations, ensuring compliance with IRS regulations and managing the PMT tax requirements. The ideal candidate will have a Bachelor's degree in accounting or finance, CPA certification, and 8-10 years...Senior- ...Principal Cloud Security Architect About the Role What... ...Level : Principal / Senior What You'll Do Assess... ...configurations, permission models, network segmentation, and resource policies... ...Familiarity with zero-trust architecture principles and...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...fiduciary and investment management role focused on high-net-worth clients in Chicago. The position requires a strong background in trust administration and estate planning, along with excellent client engagement skills. Key responsibilities include managing accounts, ensuring...Senior
- Verital Advisory Search is seeking a Senior Trusts & Estates Attorney for its Chicago office. This role involves drafting estate planning documents and advising ultra-high-net-worth clients in a collaborative environment. The ideal candidate has over 6 years of experience...SeniorWork at office
$175k - $200k
A mid-sized law firm in Chicago is looking for a seasoned legal professional to enhance their Trusts & Estates practice. The ideal candidate will have over 10 years of experience serving high-net-worth clients, licensed to practice in Illinois, and possess extensive knowledge...SeniorFlexible hours$180k - $250k
...planning, compliance, and advisory functions across complex structures. This role requires profound knowledge of individual, partnership, trust, gift, and investment taxation, along with 10+ years of experience. The Tax Director will collaborate with internal leadership,...Senior- SAGE Integration is looking for a Senior Systems Engineer in Chicago to develop solutions and support... ...candidate will have over 10 years in security technologies, excellent problem-solving... ...team that values empowerment and trust. Enjoy competitive pay, paid vacations...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Network Security Engineer - Cisco ISE & Zero Trust Segmentation. Be the first to apply!
- security infrastructure engineer Chicago, IL
- senior cloud security engineer Chicago, IL
- senior application security engineer Chicago, IL
- lead security engineer Chicago, IL
- physical security engineer Chicago, IL
- security engineering manager Chicago, IL
- endpoint security engineer Chicago, IL
- sr information security engineer Chicago, IL
- senior security operations engineer Chicago, IL
- IT security engineer Chicago, IL


