Role & responsibilities
1. Aruba ClearPass NAC (Core)
1.
Design, deploy, and operate Aruba ClearPass Policy Manager (CPPM).
2.
Architect, implement, and support High Availability (HA) and Disaster Recovery (DR) ClearPass clusters.
3.
Configure ClearPass services, authentication sources, authorization rules, and enforcement policies.
4.
Perform deep tVroubleshooting using Access Tracker, Event Viewer, and system-level logs.
2. Authentication & Access Control
5.
Implement and troubleshoot 802.1X authentication for both wired and wireless networks.
6.
Configure and support EAP methods including EAP-TLS, PEAP, and EAP-TTLS.
7.
Implement and manage MAC Authentication Bypass (MAB).
8.
Possess hands-on experience with RADIUS, TACACS+, and Change of Authorization (CoA RFC 3576).
9.
Design and enforce role-based and identity-based access control policies.
3. Switch & Network Integration
10.
Integrate ClearPass NAC with access switches from Aruba, Cisco, and Juniper.
11.
Configure dynamic VLAN assignment and Downloadable User Roles (DUR).
12.
Troubleshoot switch-side issues including re-authentication loops and fail-open / fail-close scenarios.
4. Endpoint Security & Posture
13.
Configure, deploy, and support ClearPass OnGuard posture assessment.
14.
Validate endpoint compliance including:
o
Antivirus / EDR solutions (Trellix, Microsoft Defender, CrowdStrike, etc.)
o
OS patching, firewall status, and disk encryption.
15.
Design and implement quarantine, remediation, and compliance workflows.
16.
Support posture enforcement for servers, core banking systems, ATMs, kiosks, and IoT devices.
5. Certificate & Identity Integration
17.
Implement certificate-based authentication using EAP-TLS.
18.
Integrate ClearPass with Microsoft Active Directory (AD), LDAP, and AD Certificate Services (PKI).
19.
Troubleshoot certificate lifecycle issues including expiry, trust chain validation, CRL, and OCSP failures.
6. Operations & Integrations
20.
Act as L3 escalation point for NAC-related incidents and critical outages.
21.
Perform root cause analysis (RCA) for authentication, authorization, and posture-related issues.
22.
Integrate ClearPass with SIEM platforms (Splunk, QRadar) and ITSM tools (BMC, ServiceNow).
23.
Plan, execute, and validate ClearPass upgrades, hotfixes, and security patching activities.
Preferred candidate profile
1.
Expert-level knowledge of Aruba ClearPass Policy Manager. (Must)
2.
Strong hands-on experience with NAC technologies including 802.1X, RADIUS, TACACS+, and CoA. (Must)
3.
Experience with switch-based NAC enforcement mechanisms. (Must)
4.
In-depth knowledge of endpoint posture assessment using ClearPass OnGuard. (Must)
5.
Expertise in certificate-based authentication (EAP-TLS). (Must)
6.
Strong understanding of Windows AD, LDAP, DNS, and NTP services. (Must)
7.
Excellent troubleshooting, log analysis, and problem-resolution skills. (Must)
8.
Individual Contributor (L3 Technical) High-availability, production banking environment (Must)

Keyskills: Aruba Aruba Switch Aruba Clearpass NAC
Aforeserve is an integrated service management and support company offering comprehensive and standardized life cycle services for the full spectrum of Information, Communication and Technology (ICT) products, including notebooks, desktops and servers, computer peripherals, surge protection and powe...