Enterprise Network Engineer
Baltimore, MD - USA
Job Summary
JOB SUMMARY:
The Enterprise Network Engineer is a senior technical contributor responsible for designing implementing operating and continuously improving secure access and segmentation services across enterprise wired networks. The engineer will translate security and business requirements into scalable authentication authorization policy-enforcement and least-privilege segmentation designs while maintaining reliable user and device connectivity. This role requires strong analytical judgment clear communication disciplined change practices and effective collaboration across network cybersecurity identity endpoint application and operations teams.
QUALIFICATIONS:
- Bachelors Degree computer science information technology network engineering or a related field (Required)
- One year of relevant education may be substituted for one year of required work experience or one year of relevant professional-level work experience may be substituted for one year of required education.
- Minimum 5 Years of Experience in network engineering or IT required (Required)
- Support the design deployment and lifecycle management of enterprise network access control solutions across wired guest contractor BYOD and device-access use cases.
- Develop and maintain identity- and context-based access policies using platforms such as Aruba ClearPass AGNI Cisco Identity Services Engine (ISE) Forescout and Easy NAC.
- Design and implement network segmentation and microsegmentation controls using roles VLANs ACLs security-group constructs downloadable policy dynamic authorization and firewall policy enforcement.
- Engineer and support wired 802.1X EAP-TLS MAC Authentication Bypass RADIUS TACACS certificate-based authentication device profiling posture assessment and guest onboarding.
- Integrate NAC platforms with identity directories PKI and certificate services endpoint-management platforms firewalls switching platforms SIEM solutions and other security tools.
- Configure and troubleshoot Cisco and Arista switching and routing functions required for secure access including VLANs trunks spanning tree Layer 3 routing DHCP relay access controls and RADIUS-based policy enforcement.
- Partner with firewall and security teams to align access decisions with internal segmentation least-privilege Zero Trust and lateral-movement reduction objectives.
- Perform advanced troubleshooting using authentication logs packet captures RADIUS transactions certificate-chain validation switch and wireless-controller diagnostics endpoint supplicant logs and firewall events.
- Develop high-level and low-level designs standards implementation plans test plans migration procedures rollback plans operational runbooks diagrams and knowledge articles.
- Participate in pilot deployments and phased production rollouts; coordinate maintenance windows validate outcomes manage risk and communicate status impact and remediation plans to technical and nontechnical stakeholders.
- Monitor service health authentication success rates policy outcomes capacity availability certificate expiration and operational trends; recommend corrective and preventive improvements.
- Support incident response root-cause analysis audit evidence security assessments and remediation of access-control or segmentation findings.
- Provide technical leadership facilitate design reviews and serve as an escalation point for complex NAC authentication segmentation and connectivity issues.
- Evaluate emerging products and features through structured proofs of concept documented test criteria and evidence-based recommendations.
- Advanced networking or security certification such as CCNP Enterprise CCNP Security CCIE CISSP or a relevant vendor NAC certification.
- Experience integrating NAC with Active Directory LDAP MDM/UEM SIEM vulnerability-management endpoint-security and certificate-enrollment services.
- Knowledge of Zero Trust architecture network policy automation infrastructure as code APIs Python PowerShell or other scripting and orchestration methods.
- Experience in regulated high-availability healthcare government financial or similarly complex enterprise environments.
Salary Range: Minimum 46.66/hour - Maximum 81.67/hour. Compensation will be commensurate with equity and experience for roles of similar scope and responsibility. In cases where the range is displayed as a $0 amount salary discussions will occur during candidate screening calls before any subsequent compensation discussion is held between the candidate and any hiring authority.
The Hospital reserves the right to modify employee schedules as needed.
We are committed to creating a welcoming and inclusive environment where we embrace and celebrate our differences where all employees feel valued contribute to our mission of serving the community and engage in equitable healthcare delivery and workforce practices.
Johns Hopkins Health System and its affiliates are an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity and expression age national origin mental or physical disability genetic information veteran status or any other status protected by federal state or local law.
Johns Hopkins Health System and its affiliates are drug-free workplace employers.
Required Experience:
IC
About Company
Johns Hopkins Medicine is a leading health system and academic institution in the U.S. Find information about doctors, locations, appointments, billing, research, education and more.