Senior Cybersecurity Engineer (Network Security)
Tech Stack / Keywords
Wymagania
- Bachelor’s degree in Computer Science, Software Engineering, Information Security, or related field.
- 5+ years hands-on experience designing, implementing, and managing enterprise-grade NAC solutions, specifically Cisco ISE.
- Proven experience deploying, configuring, and maintaining Palo Alto Next-Generation Firewalls (NGFW) including SSL decryption and threat prevention.
- Experience with automation tools such as Ansible, Terraform, and scripting in Python.
- Experience managing security controls at scale in complex global environments with diverse device profiles (IoT, Medical, Corporate).
- Knowledge of Cisco ISE features: TrustSec, Dot1x, MAB, Profiling, Guest Portals, REST APIs, complex enterprise policies, EAP-TLS, EAP-TEAP.
- Strong understanding of RADIUS, TACACS+, Enterprise PKI, and certificate lifecycle management.
- Proficiency in network segmentation technologies: TrustSec, SGTs, VRFs.
- Experience with Palo Alto Firewalls in HA environments (Active/Active and Active/Passive).
- Ability to architect "Defense in Depth" flows linking device identity to network permissions.
Nice to have:
- Proficiency in Terraform and GitHub for Infrastructure as Code.
- Experience building CI/CD pipelines with GitLab/GitHub.
- Scripting skills in PowerShell, Bash for API integrations.
- Advanced knowledge of enterprise networking protocols (BGP, OSPF) and switching (VLANs, VXLAN).
- Strong communication and stakeholder management skills.
- Ability to mentor junior cybersecurity engineers and promote operational excellence.
- Experience in regulated industries such as Pharmaceuticals, Healthcare, or Finance.
Obowiązki
Product Ownership and Technical Leadership:
- Act as primary Subject Matter Expert (SME) for Secure Access technologies.
- Drive the technical roadmap aligned with Zero Trust security architecture.
- Translate security requirements into scalable technical initiatives.
- Mentor and provide technical leadership to junior engineers.
Identity-Based Access and Authentication:
- Design, deploy, and maintain authentication solutions using 802.1X, EAP-TLS, EAP-TEAP, RADIUS, TACACS+, SAML, and MFA.
- Integrate security platforms with enterprise Identity Providers (IdPs).
- Architect and manage highly available authentication services.
Network Access Control (NAC) and Segmentation:
- Lead lifecycle management of Cisco ISE deployments.
- Develop endpoint profiling techniques for corporate, medical, and IoT devices.
- Implement Dot1x, MAC Authentication Bypass (MAB), Guest Access, and posture-based authorization.
- Design and implement Cisco TrustSec and Scalable Group Tag (SGT)-based micro-segmentation.
Operational Excellence and Automation:
- Serve as escalation point for complex technical incidents with root-cause analysis.
- Develop monitoring and reporting dashboards for platform health and compliance.
- Implement Infrastructure-as-Code (IaC) and security automation.
- Build API-driven integrations and self-service capabilities.
Global Operations:
- Ensure secure connectivity across diverse global regions.
- Collaborate with global product squads and stakeholders for integrated security solutions.
Benefity
- Participation in interesting and demanding projects.
- Flexible working hours.
- Possibility to work remote or hybrid (2 days per week from the office).
- Opportunities for development and promotion.
- Attractive package of benefits.
- A great, non-corporate atmosphere.
Inne informacje
Informujemy, że administratorem danych jest Transition Technologies MS S.A. z siedzibą w Warszawie, ul. Chmielna 69, (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
Transition Technologies MS
18 aktywnych ofert