L3 Network Engineer - Aruba ClearPass NAC
Job Description
- \n
- 8-12+ years of networking or security infrastructure experience, including at least 5 years of NAC or identity-services experience. \n
- Strong hands-on experience with Aruba ClearPass Policy Manager administration and complex authentication troubleshooting. \n
- Deep knowledge of 802.1X, RADIUS, TACACS+, EAP methods, certificates, PKI, Active Directory, LDAP, endpoint profiling, and authorization. \n
- Experience with large-scale wired and wireless NAC environments, high availability, upgrades, and security integrations. \n
- Working knowledge of routing, switching, wireless, firewalls, DHCP, DNS, APIs, automation, and ITIL processes. \n
ResponsibilitiesAruba ClearPass NAC - Primary
\n- \n
- Administer and troubleshoot Aruba ClearPass Policy Manager clusters, nodes, services, policies, roles, enforcement profiles, and network device definitions. \n
- Configure and troubleshoot 802.1X, MAC Authentication Bypass, RADIUS, TACACS+, EAP-TLS, PEAP, certificate-based authentication, and authorization flows. \n
- Manage endpoint profiling, posture, device categories, custom fingerprints, role mapping, segmentation, and access enforcement. \n
- Support ClearPass Guest, Onboard, OnGuard, captive portal, BYOD, sponsor workflows, and certificate lifecycle processes where deployed. \n
- Integrate ClearPass with Active Directory, LDAP, PKI, MDM/UEM, SIEM, firewalls, wireless controllers, switches, and ITSM platforms. \n
- Troubleshoot authentication failures using Access Tracker, event viewer, RADIUS attributes, endpoint data, certificates, packet captures, and device logs. \n
- Plan and execute upgrades, patches, cluster maintenance, backups, restores, migrations, certificate renewals, and disaster-recovery tests. \n
- Develop standards, reusable policy designs, APIs, automation, reporting, audit controls, and operational documentation. \n
Operations, Governance & Technical Leadership
\n- \n
- Own or support P1/P2 major incidents, participate in technical bridge calls, and provide timely stakeholder updates. \n
- Execute incident, service request, change, problem, and configuration management activities in line with ITIL practices. \n
- Prepare implementation plans, rollback procedures, risk assessments, validation reports, SOPs, and knowledge articles. \n
- Engage OEM support and technology vendors for complex defects, software issues, and product escalations. \n
- Monitor service health, capacity, availability, performance, and recurring trends; recommend continuous improvement actions. \n
- Mentor L1/L2 engineers, conduct technical reviews, and support transitions, audits, projects, and operational readiness. \n
Qualifications
\nTechnology Area
\nPreferred Platforms
\nExpected Capability
\nWireless
\nAruba, Juniper Mist, Cisco
\nTroubleshoot WLAN authentication, role assignment, guest access, roaming, and controller or cloud integration.
\nLAN Switching
\nAruba CX, Juniper EX, Cisco Catalyst
\nSupport wired 802.1X, MAB, downloadable roles/ACLs, VLAN assignment, and switch-port behavior.
\nIdentity / PKI
\nActive Directory, LDAP, CA, certificates
\nTroubleshoot directory lookup, group mapping, EAP certificates, trust chains, revocation, and renewal.
\nSecurity Integration
\nPalo Alto, firewalls, SIEM
\nSupport context sharing, segmentation, security events, syslog, and enforcement integrations.
\nDDI
\nBlueCat, Infoblox, Microsoft
\nUnderstand DHCP, DNS, IP addressing, endpoint visibility, and profiling dependencies.
\nAutomation
\nClearPass APIs, Python, Ansible
\n- \n
- Automate device onboarding, policy validation, reporting, backups, and operational workflows. \n