Jobs · Information Technology · California

Cisco Network Security Engineer/ Senior Consultant

Deloitte · San Jose, CA · 1 mo ago
HybridInformation Technology$105k–$208k/yrFull-time

About the role

Deloitte's Cyber business delivers industry-leading services through fresh thinking and a creative approach, collaborating across teams to bring comprehensive expertise to clients. As a Senior Consultant in Strategy, Growth, and Transformation, you will design, deploy, and manage Cisco security solutions to help clients navigate the evolving threat landscape with resilience and confidence.

Responsibilities

  • Design, deploy, and manage Cisco Firepower Threat Defense (FTD) and Firepower Management Center (FMC) solutions across enterprise environments, including physical, virtual, and cloud-delivered deployments.
  • Implement and support Cisco Identity Services Engine (ISE) capabilities, including 802.1X network access control, device profiling, guest lifecycle management, TrustSec segmentation, and integration with enterprise identity stores.
  • Configure and tune advanced Cisco security features, including intrusion prevention system (IPS), malware protection, URL filtering, DNS-based security, Security Intelligence, and SSL/TLS decryption policies.
  • Deploy and integrate Cisco Secure Firewall solutions in cloud environments (AWS, Microsoft Azure, GCP) while supporting centralized policy management and secure connectivity across hybrid infrastructures.
  • Develop client-facing security architectures, integrate Cisco platforms with SIEM tools and automation solutions, and deliver recommendations aligning technical requirements, compliance needs, and business objectives.

Skills

  • Ability to design, assess, and troubleshoot enterprise network security environments using Cisco security technologies.
  • Ability to implement and manage Cisco Firepower Threat Defense (FTD), Firepower Management Center (FMC), and Identity Services Engine (ISE) solutions.
  • Ability to support 802.1X network access control, profiling, guest access, TrustSec segmentation, and policy enforcement requirements.
  • Ability to analyze and tune firewall, IPS, SSL/TLS decryption, and threat prevention controls.
  • Ability to support secure network and firewall deployments across on-premises, campus, data center, and cloud environments.
  • Ability to produce technical assessments, target-state architectures, implementation roadmaps, and executive-ready deliverables.
  • Ability to lead projects or workstreams and manage multiple tasks in a fast-paced, dynamic environment.
  • Ability to provide clear guidance to others.

About the team

Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. This includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.

Qualifications

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience.
  • CCNP Security or CCIE Security certification required.
  • 5+ years of experience in network security engineering with Cisco security technologies.
  • 5+ years of experience designing, deploying, and managing Cisco Firepower Threat Defense (FTD) and Firepower Management Center (FMC) in enterprise environments, including physical appliances, virtual instances, and cloud-delivered Firewall Management Center (cdFMC).
  • 5+ years of experience designing and implementing Cisco Identity Services Engine (ISE), including distributed node architectures, high availability configurations, patch management, and upgrade planning.
  • 3+ years of experience with Cisco Identity Services Engine (ISE) 802.1X Network Access Control (NAC), guest lifecycle management, profiling policies, TrustSec segmentation, and Cisco Firepower capabilities including IPS, malware protection, URL filtering, DNS-based security, SSL/TLS decryption, and cloud firewall deployments in AWS, Microsoft Azure, or GCP.
  • Ability to travel up to 50%, on average, based on client and industry needs.

Preferred Qualifications

  • Additional cybersecurity certifications such as CISSP, GIAC Security Essentials (GSEC), or GIAC Certified Enterprise Defender (GCED).
  • Experience with Cisco Secure Access, Cisco Umbrella, Cisco Secure Client, or Duo Security in Zero Trust architectures.
  • Experience with Cisco Extended Detection and Response (XDR), Cisco SecureX, or integration of Firepower and ISE telemetry for threat detection, investigation, and response.
  • Experience using REST APIs, Ansible, Terraform, or Python for policy provisioning, compliance checks, configuration drift detection, or network security automation.
  • Experience with Cisco Catalyst Center and ISE integration for Software-Defined Access (SD-Access) deployments and segmentation policy enforcement.
  • Experience delivering network security, network access control, segmentation, or Zero Trust engagements in consulting environments.

Pay

The wage range for this role is $105,400 to $207,800, taking into account factors such as skill sets, experience, training, licensure, certifications, and business needs. You may also be eligible to participate in a discretionary annual incentive program based on individual and organizational performance.

Similar jobs