Cisco Network Security Engineer/ Senior Consultant Job at Deloitte, New York, NY

M0VyK2xNNDlwTXEvR1NDUzExUWlCcDlhSnc9PQ==
  • Deloitte
  • New York, NY

Job Description

Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and Transformation

Deloitte's Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative approach. We collaborate with teams from across our organization in order to bring the full breadth of Deloitte, its commercial and public sector expertise, to best support our clients.

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Senior Consultant, Strategy, Growth, and Transformation on the Cyber team, you will be responsible for...

  • Designing, deploying, and managing Cisco Firepower Threat Defense (FTD) and Firepower Management Center (FMC) solutions across enterprise environments, including physical, virtual, and cloud-delivered deployments
  • Implementing and supporting Cisco Identity Services Engine (ISE) capabilities, including 802.1X network access control, device profiling, guest lifecycle management, TrustSec segmentation, and integration with enterprise identity stores
  • Configuring and tuning advanced Cisco security features, including intrusion prevention system (IPS), malware protection, URL filtering, Domain Name System (DNS)-based security, Security Intelligence, and Secure Sockets Layer/Transport Layer Security (SSL/TLS) decryption policies
  • Deploying and integrating Cisco Secure Firewall solutions in cloud environments, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), while supporting centralized policy management and secure connectivity across hybrid infrastructures
  • Developing client-facing security architectures, integrating Cisco platforms with security information and event management (SIEM) tools and automation solutions, and delivering recommendations that align technical requirements, compliance needs, and business objectives

A successful candidate would possess these skills:

  • Ability to design, assess, and troubleshoot enterprise network security environments using Cisco security technologies
  • Ability to implement and manage Cisco Firepower Threat Defense (FTD), Firepower Management Center (FMC), and Identity Services Engine (ISE) solutions
  • Ability to support 802.1X network access control, profiling, guest access, TrustSec segmentation, and policy enforcement requirements
  • Ability to analyze and tune firewall, intrusion prevention system (IPS), Secure Sockets Layer/Transport Layer Security (SSL/TLS) decryption, and threat prevention controls
  • Ability to support secure network and firewall deployments across on-premises, campus, data center, and cloud environments
  • Ability to produce technical assessments, target-state architectures, implementation roadmaps, and executive-ready deliverables
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Ability to provide clear guidance to others

The team

Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.

Qualifications

Required Qualifications

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent work experience)
  • CCNP Security or CCIE Security certification required
  • 5+ years of experience in network security engineering with Cisco security technologies
  • 5+ years of experience designing, deploying, and managing Cisco Firepower Threat Defense (FTD) and Firepower Management Center (FMC) in enterprise environments, including physical appliances, virtual instances, and cloud-delivered Firewall Management Center (cdFMC)
  • 5+ years of experience designing and implementing Cisco Identity Services Engine (ISE), including distributed node architectures, high availability configurations, patch management, and upgrade planning
  • 3+ years of experience with Cisco Identity Services Engine (ISE) 802.1X Network Access Control (NAC), guest lifecycle management, profiling policies, TrustSec segmentation, and Cisco Firepower capabilities including intrusion prevention system (IPS), malware protection, Uniform Resource Locator (URL) filtering, Domain Name System (DNS)-based security, Secure Sockets Layer/Transport Layer Security (SSL/TLS) decryption, and cloud firewall deployments in Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP)
  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred Qualifications

  • Additional cybersecurity certifications such as Certified Information Systems Security Professional (CISSP), GIAC Security Essentials (GSEC), or GIAC Certified Enterprise Defender (GCED)
  • Experience with Cisco Secure Access, Cisco Umbrella, Cisco Secure Client, or Duo Security in Zero Trust architectures
  • Experience with Cisco Extended Detection and Response (XDR), Cisco SecureX, or integration of Firepower and Identity Services Engine (ISE) telemetry for threat detection, investigation, and response
  • Experience using Representational State Transfer application programming interfaces (REST APIs), Ansible, Terraform, or Python for policy provisioning, compliance checks, configuration drift detection, or network security automation
  • Experience with Cisco Catalyst Center and Cisco Identity Services Engine (ISE) integration for Software-Defined Access (SD-Access) deployments and segmentation policy enforcement
  • Experience delivering network security, network access control, segmentation, or Zero Trust engagements in consulting environments

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Job Tags

Full time, Work experience placement, Visa sponsorship

Similar Jobs

Sanbell

Professional Land Surveyor / Survey Manager Job at Sanbell

 ...Professional Land Surveyor (PLS) / Survey Manager Billings, MT We welcome you to consider Sanbell as the next step in your exciting career as a Professional Land Surveyor/Survey Manager. Sanbell is a multi-disciplinary engineering, community planning,... 

Michael Hsu Office of Architecture

Interior Designer (Austin) Job at Michael Hsu Office of Architecture

 ...Michael Hsu Office of Architecture is an award-winning, fully integrated architecture and interior design practice with offices in Austin and Houston. Our work is rooted in hospitality and placemaking and includes diverse projects that range from large mixed-use developments... 

IDEMIA

Enrollment Agent I Job at IDEMIA

 ...employment without regard to age, race, color, sex, sexual orientation, gender identity, national origin, religion, disability status, or protected veteran status. VEVRRA Federal Contractor Emergency Response: Responding to emergency situations to meet customers' needs... 

201 LYONS AVENUE

Medical Technologist BloodBank Job at 201 LYONS AVENUE

 ...Job Title: Medical Technologist BloodBank Location: Newark Beth Israel Medical Ctr Department Name: Lab NBI Req #: 0000228063 Status: Hourly Shift: Night Pay Range: $49.35 - $49.35 per hour Pay Transparency: The above reflects the anticipated hourly... 

East Central District Health Department/Good Neighbor Commun...

Community Health Worker Job at East Central District Health Department/Good Neighbor Commun...

 ...POSITION SUMMARY: The Community Health Worker (CHW) is a trusted connection between the community and local health and social service...  ..., and support. The CHW works closely with healthcare providers, public health programs, and community organizations to ensure...