Cisco Network Engineer Job at Milestone Technologies, Inc., Santa Clara, CA

R3B4bGhtUTIwWmcrRTZCbk41N2JaNXhSZEE9PQ==
  • Milestone Technologies, Inc.
  • Santa Clara, CA

Job Description

Job Description

Milestone is seeking a Senior Cisco Identity Services Engine (ISE) Network Engineer to drive the day-to-day operations, maintenance, and continuous improvement of a client’s Cisco ISE infrastructure.

This role will focus on ensuring secure, policy-based access control across wired, wireless, and VPN endpoints in a highly distributed enterprise network.

LOCAL CANDIDATES ONLY, PLEASE. This is a 12-month contract that is on-site in Santa Clara, CA.

W2 only - $60.00 an hour - NO C2C please.

The ideal candidate will have hands-on experience with Cisco ISE in production environments, advanced troubleshooting capabilities, and a comprehensive understanding of NAC, RADIUS/TACACS+, posture, profiling, and endpoint compliance integrations.

Key Responsibilities:

  • Cisco ISE Operations & Maintenance
  • Perform regular operational health checks and system diagnostics for multi-node ISE deployments (PAN, MnT, PSNs).
  • Apply system updates, cumulative patches, and hotfixes per Cisco’s recommended practices.
  • Conduct backups, restore testing, and disaster recovery validation.
  • Authentication & Authorization
  • Configure and manage 802.1X, MAB, and authentication methods.
  • Design and implement downloadable ACLs (dACLs), VLAN assignment, and dynamic policy enforcement.
  • Develop and maintain device profiling policies using SNMP, DHCP, and NMAP probes.
  • Integration & Automation
  • Integrate ISE with external identity sources (Active Directory, LDAP, SAML IdPs).
  • Connect ISE to third-party tools
  • Automate policy deployment and configuration using REST APIs, Python scripting, or Ansible playbooks.
  • Visibility & Compliance
  • Configure posture assessments using Cisco AnyConnect modules and HostScan packages.
  • Create robust guest access workflows (sponsored and self-service) and BYOD onboarding using MyDevices portal.
  • Monitor logs and alarms via ISE logging system, MnT, and external SIEM platforms.
  • Infrastructure Design & Optimization
  • Provide design input for scalable, highly available ISE topologies across data centers.
  • Analyze network traffic flow, policy hits/misses, and system utilization for performance tuning.
  • Coordinate with wireless and switching teams to ensure consistent policy enforcement across platforms.
  • Documentation & Knowledge Sharing
  • Maintain detailed configuration guides, topology diagrams, change control records, and knowledge base articles.
  • Mentor junior engineers and serve as escalation point for complex access control issues.

Qualifications:

Required: Preferred:

  • 5+ years of experience with Cisco ISE (including versions 3.x and above), HA clustering and distributed deployment models.
  • Deep understanding of AAA protocols (RADIUS, TACACS+), EAP types, and Cisco TrustSec architecture.
  • Hands-on experience with Cisco Catalyst and Nexus switches, WLCs, and wireless APs in ISE-integrated environments.
  • Familiarity with certificate management, including PKI integration, SCEP, and certificate-based auth.
  • Strong command of ISE’s policy sets, authentication/authorization rules, and profiling mechanisms.
  • Cisco CCNP certification.
  • Experience with pxGrid, ERS APIs, and integrations with Cisco DNA Center, AMP for Endpoints, and SecureX.
  • Proficiency in Linux CLI and familiarity with ISE CLI-level administration (e.g., troubleshooting logs, interface configs).
  • Working knowledge of segmentation technologies (VLAN, SGT, VRF) and micro/macro segmentation strategies.
  • Experience with large enterprise deployments (10,000+ endpoints).

Job Tags

Contract work, Local area,

Similar Jobs

Investors Title Insurance Company

Title Agency Manager Job at Investors Title Insurance Company

Title Agency Manager TrustPoint Title Lansing, MI (in office) TrustPoint Title, an Investors Title Managed Agency, is looking for an Agency Manager to join our new team in Lansing. Youll oversee all aspects of agency production, client relations, and business growth... 

Sanford Health

Head of Audit Assurance Job at Sanford Health

 ...8, USA Shift: 8 Hours - Day Shifts Job Schedule: Full time Weekly Hours: 40.00 Job Summary The Head of Audit Assurance will plan, direct and coordinate the audit activities of staff and/or contracted auditors on projects at different stages... 

Robert Half

Graphic Designer (New York) Job at Robert Half

 ...Graphic Designer (Production) Location: New York, NY (2 days onsite, 3 days remote) Duration: contract until September (approx. 3 months...  ...projects simultaneously and meet deadlines with quick turnaround times Stay updated on industry trends and incorporate innovative... 

Soccer Shots Central Virginia

Sports Management Internship Job at Soccer Shots Central Virginia

 ...Always wanted to coach and learn about the sports world? Join Soccer Shots and be the best...  ...and best coaching practices. Management Shadowing Gain hands-on practice in the...  ...coaching, work, and personal life Company Events - Seasonal parties, team outings, staff... 

Core Medical-Perm

Staff - Registered Nurse (RN) - Flight Nurse or Critical Care Flight Nurse - $31-52 per hour Job at Core Medical-Perm

 ...Core Medical-Perm is seeking a Registered Nurse (RN) Flight Nurse or Critical Care Flight Nurse for a nursing job in Garden City, Kansas. Job Description & Requirements ~ Specialty: Flight Nurse or Critical Care Flight Nurse ~ Discipline: RN ~ Start Date: ASAP...