Cisco Identity Services Engineer/Administrator

Bowhead / UIC Technical Services

Dahlgren, VA

JOB DETAILS
SKILLS
802.1, 802.11, Access Control, Analysis Skills, Apple Macs, Authentication, Best Practices, CCNA - Cisco Certified Network Associate, CCNP - Cisco Certified Network Professional, Certification & Accreditation Process (C&A), Cisco ASA (Adaptive Security Appliance), Cisco Network Systems, Cryptography, DHCP (Dynamic Host Configuration Protocol), DNS (Domain Name System), Data Recovery, Database Backup, Detail Oriented, DoD Directive 8140, DoD Directive 8570, DoD Information Assurance - IA, Documentation, File Management, File Systems, Firewalls, IAT - Information Assurance Technical, Identify Issues, Identity Data Management, Lift/Move 20 Pounds, Load Balancing, Manufacturing Data Management, Microsoft Active Directory, Network Administration/Management, Network Performance/Analysis, Network Routers, Network Routing, Network Security, Network Switching, Network Systems, Operational Support, Performance Analysis, Performance Management, Performance Tuning/Optimization, Policy Development, Policy Implementation, Problem Solving Skills, Progress Reports, Public Key Infrastructure (PKI), Requirements Management, SSL-TLS (Secure Socket Layer - Transport Layer Security), Security Analysis, Security Compliance, Security Infrastructure, Software Installation, Software Patches, Standard Operating Procedures (SOP), Standards Development, Status Reports, Systems Administration/Management, Systems Maintenance, TACACS+ (Terminal Access Controller Access Control System Plus), Technical/Engineering Design, Test Plan/Schedule, VLAN (Virtual Local Area Network), VPN (Virtual Private Network), Wireless Communications, Writing Skills
LOCATION
Dahlgren, VA
POSTED
Today

Overview

CISCO IDENTITY SERVICES ENGINEER (RDTE)

Bowhead is seeking a Cisco Identity Services Engineer (ISE) Administrator to provide Design and Engineering Operation and Maintenance support for ISE systems on the classified and unclassified Research, Development, Test and Evaluation (RDTE) networks at Dahlgren, VA. As an Cisco ISE Administrator, you will identify endpoints, and enable the creation and enforcement of security and access policies for endpoint devices connected to the company’s routers and switches, in order to simplify identity management across diverse devices and applications.

Responsibilities

  • Configure, implement, and troubleshoot ISE.
  • Build and analyze ISE rules to comply with client network security policies.
  • Create policies for unseen network devices in a mixed environment, to include profiling devices, defining Downloadable Access Control Lists (DACL’s), and assigning Virtual Local Area Network (VLAN) to endpoints.
  • Implement 802.1x solutions to all “supplicant-enabled” devices via AnyConnect software and Network Access Manager (NAM) profiles using EAP-MSCHAPv2/TLS encryption methods.
  • Integrate with wired data, wireless infrastructure, and Virtual Private Network (VPN), as well as posture and client provisioning.
  • Configure and implement TACACS+ policies for network device administration.
  • Manage firewall and network security systems by establishing and enforcing approved policies
  • Analyze network security requirements and implement perimeter security changes
  • Serve as a subject matter expert in coordinating and troubleshooting with customers, other infrastructure support activities and business units
  • Develop network documentation of security infrastructure
  • Monitor network performance and implement performance tuning as necessary
  • Responsible for installing software, applying patches, managing file systems, and monitoring performance of ISE systems
  • Performs data backups and restoration of managed systems
  • Assist in the certification and accreditation process for managed systems and networks
  • Install and deploy of new ISE hardware and software
  • Review daily logs for managed systems and report on unusual activity
  • Participate in the development and maintenance of Standard Operating Procedures (SOPs) associated with managed systems and applications
  • Collaborate with IT staff on projects and initiatives
  • Provide input for a monthly progress and status report

Qualifications

  • Ten (10) years of experience in networking, IT, or other related fields preferred 
  • Bachelors Degree degree required
  • Solid experience configuring and troubleshooting routing and switched infrastructure
  • Experience in network security including: Device Hardening and patching
  • Experience with Cisco AnyConnect or related supplicants.
  • Experience with Public Key Infrastructure (PKI) to assist, maintain and troubleshoot 802.1X EAP-TLS issues
  • Experience with MAC Authentication Bypass (MAB) and 802.1X troubleshooting concepts.
  • Knowledge of Cisco AnyConnect Modules – (VPN, Posture, NAM)
  • Diagnose and resolve complex network problems and improve network performance and reliability
  • Must currently hold a DoD 8570 Information Assurance Technical Level (IAT) II certification (CCNA) and have the ability to obtain and maintian an IAT Level III (CCNP) certification within 12 months of hire. 

  • Position requires a strong understanding of ISE functions and operations (e.g. endpoint identification, authentication, authorization)
  • Familiarity with researching communication networks 
  • Must have strong troubleshooting and critical thinking skills 
  • Strong attention to detail, good documentation skills, ability to write clear, concise project reports 
  • Ability to function with minimal instruction or supervision, or as a part of larger team reporting to formal project management 

Desired Skills

  • Cisco Access Control System (ACS), specifically with “role-based” TACACS+ commands/profiles
  • PxGrid, ThreatGrid and Security Group Tags(SGT’s) for back-end communication between Cisco Firepower and ISE server
  • Cisco Prime, MDM, ASA, DNS/DHCP, Network Load-Balancing, and 802.11a/b/g/n Wireless technologies and industry best practices.
  • Active Directory knowledge(e.g. Organizational Unit(OU) identification, domain “trusts”, Domain Name System(DNS), identity resolution)

Physical Demands:

  • Must be able to lift up to 10-20 pounds 
  • Must be able to stand and walk for prolonged amounts of time 
  • Must be able to twist, bend and squat periodically

SECURITY CLEARANCE REQUIREMENTS: Must currently hold a security clearance at the Top Secret level. US Citizenship is a requirement for this contract.

#LI-JR1

About the Company

B

Bowhead / UIC Technical Services

UIC Government Services (UICGS) and its Bowhead family of companies are a division of Ukpeaġvik Iñupiat Corporation (UIC), an Alaskan Native Corporation (ANC). UIC is one of the largest ANC’s in Alaska, and combined with UICGS/Bowhead, we offer a wide variety of services to defense and civilian government agencies that reach across multiple disciplines, the U.S., and the world. With our excellent management team and great range of services in the areas of Information Technology, Logistics & Marine, Manufacturing & Products, Program Management and Operations, and Systems & Technology, we perform over 250 contracts worldwide with innovative business solutions in areas such as engineering, maintenance services, manufacturing, information technology, program support, logistics/base support, and procurement. Collectively, our 3,500+ employees of the Bowhead family of companies, UIC, UIC Government Services, UIC Government Construction, and UIC Commercial remain committed to delivering quality results to ensure our customers’ success. Headquartered in Virginia, we are a fast-growing, multi-million-dollar corporation consistently recognized as one of the top 25 8(a) certified small business companies for government contracting.

COMPANY SIZE
2,500 to 4,999 employees
INDUSTRY
Real Estate/Property Management
EMPLOYEE BENEFITS
Employee Referral Program, Flexible Spending Accounts, Tuition Reimbursement, Life Insurance, Military Leave, Professional Development, 401K
FOUNDED
1999
WEBSITE
https://www.bowheadsupport.com/