Senior Cybersecurity engineer for Secure Access Network
⚲ Warszawa
25 200 - 30 240 PLN netto (B2B)
Wymagania
- Cisco ISE
- IaC
Opis stanowiska
Craftware is a technology company of over 500 experts, empowering large organizations to solve complex business challenges with modern IT solutions - from sales systems and automation to data platforms and AI. We operate where technology must be reliable, secure, and scalable. We deliver end-to-end projects: from analysis and architecture through implementation to development and maintenance. We are a trusted partner of industry leaders such as Salesforce, Veeva, UiPath, and Databricks.
Model: remote (Poland)Employment type: full-time / B2B
Role summary
We're looking for a Senior Cybersecurity Engineer (Network Security) to join a global pharmaceutical leader's Network Security Product area. You'll act as the primary Subject Matter Expert for Secure Access Network Services, driving the evolution of Network Access Control, identity-driven security, segmentation, and authentication across a global enterprise environment. Your mission: strengthen the organization's "Defense in Depth" strategy and ensure resilient, compliant, and secure network access for tens of thousands of endpoints worldwide.
Responsibilities
• Act as the primary SME for Secure Access technologies, evaluating and selecting emerging security tools and driving the long-term technical roadmap aligned with Zero Trust architecture.
• Design, deploy, and maintain authentication solutions using 802.1X, EAP-TLS, EAP-TEAP, RADIUS, TACACS+, SAML, and MFA, integrated with enterprise Identity Providers.
• Lead end-to-end lifecycle management of Cisco ISE deployments, including upgrades, capacity planning, and platform optimization.
• Implement advanced access control mechanisms (Dot1x, MAB, Guest Access, posture-based authorization) and design Cisco TrustSec / SGT-based micro-segmentation.
• Serve as senior escalation point for complex incidents, performing root-cause analysis and building observability/monitoring dashboards.
• Advocate for and implement Infrastructure-as-Code and security automation, building API-driven integrations and self-service capabilities.
• Mentor junior engineers and collaborate with globally distributed product squads and stakeholders.
Requirements
Must-have:
• 5+ years of hands-on experience designing, implementing, and managing enterprise-grade NAC solutions, specifically Cisco ISE (TrustSec, Dot1x, MAB, Profiling, Guest Portals, REST APIs, EAP-TLS, EAP-TEAP).
• Proven experience deploying, configuring, and maintaining Palo Alto NGFW (SSL decryption, threat prevention, HA Active/Active and Active/Passive).
• Strong understanding of RADIUS, TACACS+, identity-based access control, and enterprise PKI / certificate lifecycle management.
• Proficiency in network virtualization and segmentation (TrustSec, SGTs, VRFs).
• Experience using Ansible/Terraform and Python to manage network security infrastructure at scale.
• Solid foundation in enterprise networking (L2/L3), including BGP, OSPF, VLANs, VXLAN.
• Excellent communication and stakeholder management skills; fluent English.
Nice-to-have:
• Experience in highly regulated environments (Pharma, Healthcare, Finance).
• Proficiency in Terraform and GitHub for reproducible, version-controlled security configurations.
• Experience building CI/CD pipelines (GitLab/GitHub) and automated security workflows.
• Scripting skills in Python, PowerShell, or Bash for self-service tools and custom API integrations.
• Experience mentoring junior cybersecurity engineers.
Employment conditions:
• B2B contract, 150-180 pln/h
• Daily support from team leaders
• Dedicated certification budget
• Assistance in defining and support in your development path
• Benefits package
• Integration trips/events
Model: remote (Poland)Employment type: full-time / B2B
Role summary
We're looking for a Senior Cybersecurity Engineer (Network Security) to join a global pharmaceutical leader's Network Security Product area. You'll act as the primary Subject Matter Expert for Secure Access Network Services, driving the evolution of Network Access Control, identity-driven security, segmentation, and authentication across a global enterprise environment. Your mission: strengthen the organization's "Defense in Depth" strategy and ensure resilient, compliant, and secure network access for tens of thousands of endpoints worldwide.
Responsibilities
• Act as the primary SME for Secure Access technologies, evaluating and selecting emerging security tools and driving the long-term technical roadmap aligned with Zero Trust architecture.
• Design, deploy, and maintain authentication solutions using 802.1X, EAP-TLS, EAP-TEAP, RADIUS, TACACS+, SAML, and MFA, integrated with enterprise Identity Providers.
• Lead end-to-end lifecycle management of Cisco ISE deployments, including upgrades, capacity planning, and platform optimization.
• Implement advanced access control mechanisms (Dot1x, MAB, Guest Access, posture-based authorization) and design Cisco TrustSec / SGT-based micro-segmentation.
• Serve as senior escalation point for complex incidents, performing root-cause analysis and building observability/monitoring dashboards.
• Advocate for and implement Infrastructure-as-Code and security automation, building API-driven integrations and self-service capabilities.
• Mentor junior engineers and collaborate with globally distributed product squads and stakeholders.
Requirements
Must-have:
• 5+ years of hands-on experience designing, implementing, and managing enterprise-grade NAC solutions, specifically Cisco ISE (TrustSec, Dot1x, MAB, Profiling, Guest Portals, REST APIs, EAP-TLS, EAP-TEAP).
• Proven experience deploying, configuring, and maintaining Palo Alto NGFW (SSL decryption, threat prevention, HA Active/Active and Active/Passive).
• Strong understanding of RADIUS, TACACS+, identity-based access control, and enterprise PKI / certificate lifecycle management.
• Proficiency in network virtualization and segmentation (TrustSec, SGTs, VRFs).
• Experience using Ansible/Terraform and Python to manage network security infrastructure at scale.
• Solid foundation in enterprise networking (L2/L3), including BGP, OSPF, VLANs, VXLAN.
• Excellent communication and stakeholder management skills; fluent English.
Nice-to-have:
• Experience in highly regulated environments (Pharma, Healthcare, Finance).
• Proficiency in Terraform and GitHub for reproducible, version-controlled security configurations.
• Experience building CI/CD pipelines (GitLab/GitHub) and automated security workflows.
• Scripting skills in Python, PowerShell, or Bash for self-service tools and custom API integrations.
• Experience mentoring junior cybersecurity engineers.
Employment conditions:
• B2B contract, 150-180 pln/h
• Daily support from team leaders
• Dedicated certification budget
• Assistance in defining and support in your development path
• Benefits package
• Integration trips/events
🔍 Dekoder Ogłoszenia
🔴
driving the long-term technical roadmap aligned with Zero Trust architecture
Oznacza to, że będziesz odpowiedzialny za planowanie i wdrażanie strategii bezpieczeństwa sieciowego zgodnej z koncepcją Zero Trust, co może wymagać znaczących zmian i inwestycji.
🟡
Act as the primary Subject Matter Expert
Oznacza, że będziesz głównym ekspertem w swojej dziedzinie, co wiąże się z dużą odpowiedzialnością i koniecznością posiadania bardzo głębokiej wiedzy.
🟢
driving the evolution of Network Access Control, identity-driven security, segmentation, and authentication
Sugestia, że będziesz aktywnie kształtować i ulepszać kluczowe obszary bezpieczeństwa sieciowego, co może oznaczać pracę nad nowymi rozwiązaniami i procesami.
🟡
tens of thousands of endpoints worldwide
Wskazuje na bardzo dużą skalę infrastruktury, którą będziesz zarządzać, co może oznaczać złożoność i wyzwania techniczne.