TEKsystems is a leading provider of business and technology services, and they are seeking a Principal Network Security Engineer to safeguard the organization's infrastructure. The role involves architecting, deploying, and managing advanced network security platforms while leading the strategic direction and operational excellence of these technologies.
Responsibilities:
- Partner with cross-functional stakeholders to architect and deliver secure, scalable solutions tailored to evolving business and security requirements
- Lead global deployment and configuration of NAC appliances and Identity Services platforms across data centers, ensuring consistency, reliability, and compliance
- Implement advanced profiling techniques to identify and classify all network-connected devices, enforcing access only for authorized and trusted endpoints
- Define and enforce granular access control policies based on device posture, driving network segmentation and strengthening the organization’s security posture
- Monitor for anomalous device behavior and orchestrate automated responses to mitigate potential threats in real time
- Leverage platform capabilities to ensure continuous compliance with internal standards and external regulatory requirements through robust reporting and audit trails
- Seamlessly integrate NAC and Identity platforms with next-gen firewalls, SIEMs, endpoint protection, and other security tools to create a unified defense strategy
- Provide expert-level support to internal teams, manage escalations, and deliver training to promote platform adoption and operational readiness
- Utilize modern development tools and GitOps practices to automate deployment, configuration, and lifecycle management of security platforms
- Establish architectural patterns, define operational standards, and maintain comprehensive documentation using Confluence and draw.io to ensure transparency and repeatability
Requirements:
- Expert Level experience in network security
- Experience with NAC and Forescout
- Strong understanding of authentication and public key infrastructure
- Proficiency in scripting and Infrastructure as Code (IAC)
- Experience with log analysis, DNS, and DHCP
- Familiarity with Active Directory
- Ability to architect and deliver secure, scalable solutions
- Experience in global deployment and configuration of NAC appliances and Identity Services platforms
- Ability to implement advanced profiling techniques for device discovery
- Experience in defining and enforcing access control policies
- Ability to monitor for anomalous device behavior and orchestrate automated responses
- Experience in compliance management and reporting
- Ability to integrate security tools into a unified defense strategy
- Experience in providing expert-level support and training to internal teams
- Proficiency in automation and orchestration using modern development tools and GitOps practices
- Ability to establish architectural patterns and maintain comprehensive documentation
- Previous experience at a financial organization is a plus
- FSCA - Forescout Certified Administrator
- FSAA - Forescout Advanced Administrator
- FSCE - Forescout Certified Engineer