Non-Clinical - Information Technology - Engineer
Contract details
There is a Possibility of Contract to Hire. At this time this is 100% Remote. Top 3: Cisco ISE / TrustSec policy design and enforcement (SGTs, SGACLs, SXP) Cisco Secure Workload (CSW) segmentation and dependency validation ORDR discovery and tagging for asset classification and telemetry accurac This role is a hands-on engineering position responsible for designing, implementing, and operating network segmentation across the enterprise using Cisco ISE, TrustSec, NetFlow, and Cisco Secure Workload (CSW).
The engineer works within the "Limit Blast Radius" segmentation program, contributing to both the broader network segmentation rollout (ISE/TrustSec across pilot sites) and the Epic Core CSW pilot (workload-level microsegmentation across onboarded servers). This is a technical execution role, distinct from the data collection and scheduling analyst role, with direct responsibility for architecture, configuration, and validation.
Core Responsibilities Segmentation Architecture and Implementation Design and implement Cisco ISE policy sets and TrustSec Security Group Tag (SGT) taxonomy in alignment with the target segmentation model. Configure and maintain TrustSec enforcement (SGACLs, SXP, inline tagging) across pilot and production network segments. Build and refine Cisco Secure Workload (CSW) segmentation policies, working from monitor-only baselining toward enforced policy states as workload dependencies are validated.
Support onboarding of additional servers and workloads into CSW, ensuring agent deployment, telemetry collection, and policy scoping are done correctly. Traffic Analysis and Dependency Mapping Use NetFlow data to map application and system communication patterns, identifying dependencies that inform segmentation policy and reduce the risk of business disruption during enforcement. Analyze CSW-collected flow data to validate or challenge assumed dependencies before moving segments from monitor-only to enforced.
Collaborate with application and infrastructure owners to confirm or correct traffic flow assumptions. ORDR Discovery and Tagging Perform device discovery through ORDR to identify and classify assets (including OT and unmanaged devices) that fall within segmentation scope. Develop and apply tagging conventions to populate device records in the ORDR database, ensuring tags accurately reflect device type, ownership, criticality, and segmentation grouping.
Use ORDR-derived telemetry and classification data as an input to segmentation policy design, particularly for device types not well covered by ISE profiling alone. Maintain tagging consistency over time as new devices are discovered, correcting or updating tags as device context changes. Testing, Validation, and Rollout Test segmentation policies in lower-risk environments or monitor-only mode before recommending enforcement.
Support phased rollout across pilot sites, coordinating enforcement changes with change management and site stakeholders to minimize disruption. Document policy logic, exceptions, and known dependencies to support ongoing operations and audit needs. Troubleshoot segmentation-related connectivity issues, distinguishing policy misconfiguration from legitimate blocked traffic.
Cross-Team Collaboration Work directly with other Network Protection engineers on shared segmentation initiatives, and coordinate with Endpoint Protection where segmentation intersects with endpoint policy or agent-based enforcement (CSW agents). Provide technical input to program-level reporting and stakeholder updates on segmentation progress. Skills and Qualifications Hands-on experience with Cisco ISE policy administration and TrustSec/SGT design and enforcement.
Working knowledge of Cisco Secure Workload (or comparable microsegmentation platforms) including agent deployment, flow analysis, and policy authoring. Proficiency reading and interpreting NetFlow data to inform segmentation decisions. Familiarity with ORDR (or comparable IoT/OT discovery platforms) for device discovery, classification, and tagging.
Solid understanding of enterprise network architecture, VLANs, firewalls, and access control concepts. Ability to troubleshoot segmentation-related issues methodically, distinguishing policy problems from underlying network issues. Clear communication skills for coordinating with application owners and other engineers during enforcement rollout.