Cisco Network Security Engineer/ Senior Consultant
Job Description
Deloitte's Cyber team seeks a seasoned Cisco Network Security Engineer to guide the design, deployment, and ongoing management of Cisco security technologies across large, multi-environment deployments. The role centers on Cisco Firepower, ISE, and related controls, with SIEM and automation integrations to support secure, scalable operations in on-prem, cloud, and hybrid infrastructures. This on-site role is based in Philadelphia, PA.
Location
Location: Philadelphia, PA (onsite)
Salary
Salary: USD 105,400 - 207,800 per year
Responsibilities
- Design, deploy, and maintain Cisco Firepower Threat Defense (FTD) and Firepower Management Center (FMC) across physical, virtual, and cloud-delivered deployments
- Implement and support Cisco Identity Services Engine (ISE) capabilities, including 802.1X network access control, device profiling, guest lifecycle management, TrustSec segmentation, and integration with enterprise identity stores
- Configure and tune advanced security features such as intrusion prevention, malware protection, URL filtering, DNS-based security, Security Intelligence, and SSL/TLS decryption policies
- Deploy and integrate Cisco Secure Firewall solutions in cloud environments (AWS, Azure, GCP) with centralized policy management and secure connectivity across hybrid infrastructures
- Develop client-facing security architectures that integrate Cisco platforms with SIEM and automation tools, delivering recommendations aligned with technical, compliance, and business objectives
Requirements
- BA/BS degree in Computer Science, Cyber Security, Information Technology or equivalent work experience
- CCNP Security or CCIE Security certification required
- 5+ years of experience in network security engineering with Cisco security technologies
- 5+ years designing, deploying, and managing Cisco FTD and FMC in enterprise environments, including physical appliances, virtual instances, and cdFMC
- 5+ years designing and implementing Cisco ISE, including distributed node architectures, high availability configurations, patch management, and upgrade planning
- 3+ years of experience with Cisco ISE 802.1X NAC, guest lifecycle management, profiling, TrustSec, and Cisco FTD capabilities including IPS, malware protection, URL filtering, DNS-based security, SSL/TLS decryption, and cloud firewall deployments in AWS, Azure, or GCP
- Ability to travel up to 50%, on average, based on client needs
- Limited immigration sponsorship may be available
Technologies
- Cisco Firepower Threat Defense (FTD)
- Firepower Management Center (FMC)
- Cisco Identity Services Engine (ISE)
- 802.1X Network Access Control
- TrustSec
- IPS
- URL filtering
- DNS-based security
- SSL/TLS decryption
- Security Intelligence
- Cisco Secure Firewall
- AWS
- Microsoft Azure
- Google Cloud Platform (GCP)
- SIEM
- cdFMC (Cloud-delivered Firewall Management Center)
- Cisco Catalyst Center
- SD-Access
- REST APIs
- Ansible
- Terraform
- Python
- Duo Security
- Cisco Umbrella
- Cisco Secure Client
- Cisco SecureX
- Cisco Secure Access
Benefits
- Discretionary annual incentive program eligibility
The Team
Our Enterprise Security offering weaves security into every facet of digital transformation, protecting a client’s technical backbone while enabling secure innovation. The practice covers security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.