Lead Cybersecurity – Cisco ISE Engineer
AT&TAbout the role
Job Description:
The Lead Cybersecurity position will be a key member of the Enterprise Remote Access team. The ideal candidate has extensive experience with network access control (NAC) systems and various VPN platforms. The candidate will work with other internal team members, IT partners, and business leads to implement and maintain systems that provide secure access to AT&T networks. The candidate will also work with end users to resolve various connectivity issues. The candidate must possess an extreme discipline for attention to detail and be able to work well in a collaborative environment. The candidate will also support strategic planning, technical proof of concepts, testing, lab work, and various other technical tasks associated with designing, implementing, and supporting the various secure access programs.
This career step requires senior level experience. Responsible for cyber security areas across products, services, infrastructure, networks, and/or applications while providing protection for AT&T, our customers and our vendors/partners. Works with other team members on various projects relating to the secure access to AT&T, protection of devices, assets, data, and networks.
Key Roles & Responsibilities:
Cisco ISE Management and Configuration:
- Implements and integrates Network Access Control (NAC) for wired, wireless, VPN and IoT infrastructures, as well as posturing and profiling of all devices.
- Builds and analyzes ISE policies to comply with security policies and client requirements.
- Implements and maintains security policies, access controls, and NAT rules to meet organizational requirements.
- Optimizes system performance and ensure high availability.
- Establishes processes to test application changes and devices before planned network deployment to validate their performance.
Network Security Monitoring and Troubleshooting:
- Monitor network traffic for anomalies using the various ISE dashboards and other tools to ensure system availability and proactive threat detection.
- Work with technical personnel and/or end users to troubleshoot complex network security issues, connectivity problems, and policy conflicts.
- Perform regular configuration audits to ensure compliance with security standards.
- Willingness to be available to provide 24x7 support during outage or degraded service scenarios.
Collaboration, Documentation:
- Work closely with cross-functional teams to design and implement secure network access architectures that align with business goals.
- Maintain detailed technical documentation, including network diagrams, change logs, and Standard Operating Procedures (SOPs).
System Configuration
- Builds and maintains servers in a virtual environment (e.g., VMWare).
- General understanding of load balancer operations and configuration.
Automation and Optimization:
- Develop Splunk dashboards and queries to enhance platform monitoring.
- General understanding of API-based integrations with Cisco ISE, leveraging REST APIs for communication with other systems.
- Develop scripts to automate network access control processes, security management tasks, and processes (e.g. policy updates, log analysis, migration activities) using APIs (Perl, Python, etc.).
- Identify opportunities for process improvements to enhance operational efficiency.
Required Qualifications:
- A Bachelor’s degree in Information Systems, Engineering, or Cybersecurity.
- Requires 5-8 years of experience as a Cisco ISE engineer.
- Requires Daily Office Presence (5 days a week) at one of the listed locations. No relocation assistance is provided
- Hands-on experience in large-scale enterprise environments with complex network infrastructures.
- Strong understanding of network security protocols (Radius, TACACS+, 802.1x) and zero-trust architectures.
- Ability to analyze complex problems associated with the ISE platform and implement solutions and/or workarounds to comply with network security policies.
- Experience working and collaborating in a diverse, multi-cultural, and inclusive environment.
Preferred Qualifications:
- Familiarity with creating and executing Splunk queries.
- Familiarity with scripting languages (e.g., Perl, Python), Restful APIs, and/or automation tools for managing firewalls at scale.
Supervisory:
No.
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.
#LI-Onsite – Full-time office role
The Lead Cybersecurity earns between $
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s