Loading open roles
Loading open roles
Loading role

Connect Pro Management Consultants · posted 5 months ago
Role: Wireless Network & Cisco ISE Operations SME
The Wireless Network & Cisco ISE Operations SME is responsible for the
reliable
operation, optimization, and incident resolution of enterprise wireless, wired
LAN,
and authentication services. This role is the primary escalation point for
complex
wireless and authentication issues and drives operational excellence,
security,
and continuous improvement across network access services.
Key Responsibilities
Operate and optimize wireless and wired LAN infrastructure, including:
Cisco Catalyst Wireless (9800 series WLCs / IOS XE)
Meraki Wireless controlled via Meraki Dashboard
Cisco Catalyst wired LAN switching environments
Own day-to-day operations, capacity planning, tuning, and lifecycle
activities
(patching, upgrades, certificate management, backup validation) for Cisco ISE
and network controllers.
Act as the primary escalation contact for advanced wireless and
authentication incidents; apply structured troubleshooting methodologies and
collaborate with vendors as needed.
Design, implement, and maintain Cisco ISE policies for network access,
including:
802.1X (wired and wireless)
MAC Authentication Bypass (MAB)
Guest access workflows
BYOD onboarding and device onboarding flows
Profiling, posture compliance, and authorization profiles
Integrate and maintain identity and authentication integrations:
Active Directory / LDAP / Entra ID integrations
PKI integration for certificate-based authentication (EAP-TLS)
Maintain hybrid deployments of Cisco ISE (on-premises and AWS EC2),
ensuring secure, resilient connectivity and consistent policy enforcement
across locations.
Monitor system health and authentication performance; proactively identify
and remediate risks and single points of failure.
Produce and maintain runbooks, troubleshooting guides, checklists, and
operational documentation to enable tier-one support and reduce mean time
to resolution (MTTR).
Collaborate with cross-functional teams (Identity, Endpoint, Compute,
Security, Cloud, and Application teams) to align network access services with
business objectives and security requirements.
Identify opportunities to automate repetitive operational tasks and to
improve
efficiency, scalability, and reliability.
Share knowledge and best practices across the team; coach and mentor
peers to elevate overall team capability.
Expectations / Behavioural Competencies
Deliver secure, reliable, and high-performing wireless and authentication
services that support business needs.
Demonstrate principled entrepreneurship: proactively identify improvements
and drive projects to completion.
Foster a collaborative, accountable, and knowledge-sharing culture.
Exercise sound judgment and uphold organizational values in all decisions
and interactions.
Communicate clearly with technical and non-technical stakeholders,
document decisions and outcomes.
Requirements (Mandatory)
Proven experience operating large, multi-node Cisco Identity Services Engine
(ISE) environments.
Hands-on experience configuring and managing Cisco ISE policy constructs,
including policy sets, authorization profiles, profiling policies, and posture
compliance checks.
Demonstrated ability to configure and support 802.1X (wired &
wireless),
MAB, guest access, and BYOD onboarding flows using Cisco ISE.
Experience integrating Cisco ISE with directory services and identity
providers: Active Directory, LDAP, and Entra ID.
Experience with PKI and certificate-based authentication (EAP-TLS) and
managing certificate lifecycle in ISE and network devices.
Experience supporting hybrid ISE deployments with nodes on-premises and
on Amazon EC2 (AWS).
Operational experience performing upgrades, patching, certificate renewals,
backup validation, and routine system maintenance for ISE and wireless
controllers.
Strong troubleshooting skills using logs and diagnostics from ISE, Cisco
WLCs, network switches, and endpoints to resolve authentication and access
issues.
Proven operational support experience, including handling escalations within
network access and authentication environments.
Demonstrated experience operating wireless networks controlled by:
Cisco Catalyst WLCs (IOS XE — e.g., 9800 series)
Meraki Dashboard–controlled APs
Demonstrated experience operating Cisco LAN switching environments
(Catalyst).
Broad familiarity across related IT domains: Identity, Compute, Endpoint,
and
Firewalls (to enable effective cross-domain collaboration).
Preferred Qualifications / Extras
Experience with AireOS-based Cisco WLCs (legacy environments).
Experience with Cisco Catalyst / DNA Center for lifecycle and assurance
workflows.
Familiarity with Cisco SD-WAN concepts and integration points.
Practical experience with AWS networking and EC2 management, including
VPC, routing, security groups, and hybrid connectivity patterns.
Industry certifications such as:
CCNP Enterprise or CCNP Security
CCIE (Enterprise or Security) — preferred but not required
Cisco Certified Specialist in relevant tracks
Relevant cloud or security certifications (e.g., AWS, CISSP) are a plus
Experience authoring operational runbooks, knowledge-based articles, and
training materials.
Deliverables / Success Metrics (examples)
High availability and uptime of wireless and authentication services
(measured via SLAs/availability metrics).
Reduced MTTR for authentication and wireless incidents.
Successful, documented implementation of EAP-TLS and certificate lifecycle
processes.
Clear, up-to-date runbooks and troubleshooting guides enabling tier-one
teams to handle routine incidents.
Demonstrable automation or process improvements that reduce manual effort
or improve response times.
Working Conditions
On-call rotation for escalations and major incidents may be required.
Collaboration with remote and on-site teams, occasional travel may be
required depending on deployment topology.