Enterprise Network Engineer
Job Details
- Requisition #:
- 677848
- Location:
- Johns Hopkins Health System, Baltimore, MD 21201
- Category:
- Information Technology
- Schedule:
- Day Shift
- Employment Type:
- Full Time
JOB SUMMARY:
The Enterprise Network Engineer is a senior technical contributor responsible for designing, implementing, operating, and continuously improving secure access and segmentation services across enterprise wired networks. The engineer will translate security and business requirements into scalable authentication, authorization, policy-enforcement, and least-privilege segmentation designs while maintaining reliable user and device connectivity. This role requires strong analytical judgment, clear communication, disciplined change practices, and effective collaboration across network, cybersecurity, identity, endpoint, application, and operations teams.
QUALIFICATIONS:
- Bachelor's Degree computer science, information technology, network engineering, or a related field (Required)
- One year of relevant education may be substituted for one year of required work experience or one year of relevant professional-level work experience may be substituted for one year of required education.
- Minimum 5 Years of Experience in network engineering or IT required (Required)
- Support the design, deployment, and lifecycle management of enterprise network access control solutions across wired, guest, contractor, BYOD, and device-access use cases.
- Develop and maintain identity- and context-based access policies using platforms such as Aruba ClearPass, AGNI, Cisco Identity Services Engine (ISE), Forescout, and Easy NAC.
- Design and implement network segmentation and microsegmentation controls using roles, VLANs, ACLs, security-group constructs, downloadable policy, dynamic authorization, and firewall policy enforcement.
- Engineer and support wired 802.1X, EAP-TLS, MAC Authentication Bypass, RADIUS, TACACS+, certificate-based authentication, device profiling, posture assessment, and guest onboarding.
- Integrate NAC platforms with identity directories, PKI and certificate services, endpoint-management platforms, firewalls, switching platforms, SIEM solutions, and other security tools.
- Configure and troubleshoot Cisco and Arista switching and routing functions required for secure access, including VLANs, trunks, spanning tree, Layer 3 routing, DHCP relay, access controls, and RADIUS-based policy enforcement.
- Partner with firewall and security teams to align access decisions with internal segmentation, least-privilege, Zero Trust, and lateral-movement reduction objectives.
- Perform advanced troubleshooting using authentication logs, packet captures, RADIUS transactions, certificate-chain validation, switch and wireless-controller diagnostics, endpoint supplicant logs, and firewall events.
- Develop high-level and low-level designs, standards, implementation plans, test plans, migration procedures, rollback plans, operational runbooks, diagrams, and knowledge articles.
- Participate in pilot deployments and phased production rollouts; coordinate maintenance windows, validate outcomes, manage risk, and communicate status, impact, and remediation plans to technical and nontechnical stakeholders.
- Monitor service health, authentication success rates, policy outcomes, capacity, availability, certificate expiration, and operational trends; recommend corrective and preventive improvements.
- Support incident response, root-cause analysis, audit evidence, security assessments, and remediation of access-control or segmentation findings.
- Provide technical leadership, facilitate design reviews, and serve as an escalation point for complex NAC, authentication, segmentation, and connectivity issues.
- Evaluate emerging products and features through structured proofs of concept, documented test criteria, and evidence-based recommendations.
- Advanced networking or security certification such as CCNP Enterprise, CCNP Security, CCIE, CISSP, or a relevant vendor NAC certification.
- Experience integrating NAC with Active Directory, LDAP, MDM/UEM, SIEM, vulnerability-management, endpoint-security, and certificate-enrollment services.
- Knowledge of Zero Trust architecture, network policy automation, infrastructure as code, APIs, Python, PowerShell, or other scripting and orchestration methods.
- Experience in regulated, high-availability, healthcare, government, financial, or similarly complex enterprise environments.
Salary Range: Minimum 46.66/hour - Maximum 81.67/hour. Compensation will be commensurate with equity and experience for roles of similar scope and responsibility. In cases where the range is displayed as a $0 amount, salary discussions will occur during candidate screening calls, before any subsequent compensation discussion is held between the candidate and any hiring authority.
The Hospital reserves the right to modify employee schedules as needed.
We are committed to creating a welcoming and inclusive environment, where we embrace and celebrate our differences, where all employees feel valued, contribute to our mission of serving the community, and engage in equitable healthcare delivery and workforce practices.
Johns Hopkins Health System and its affiliates are drug-free workplace employers.
Johns Hopkins Health System and its affiliates are an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, mental or physical disability, genetic information, veteran status, or any other status protected by federal, state, or local law.
The University of Vermont Medical Center Glassdoor Reviews and Ratings