Skip to content
Craftware

Senior Cybersecurity engineer for Secure Access Network

Craftware Show all offers
Warszawa
Expires Oct 11, 2026
2 months ago

In short

Senior Cybersecurity Engineer (Network Security) needed for global pharma leader. SME for Secure Access, focusing on NAC, identity, segmentation. 5+ years Cisco ISE & Palo Alto NGFW experience. Remote (Poland).

AI-written summary based on the listing content.

Craftware is a technology company of over 500 experts, empowering large organizations to solve complex business challenges with modern IT solutions - from sales systems and automation to data platforms and AI. We operate where technology must be reliable, secure, and scalable. We deliver end-to-end projects: from analysis and architecture through implementation to development and maintenance. We are a trusted partner of industry leaders such as Salesforce, Veeva, UiPath, and Databricks.

Model: remote (Poland)

Employment type: full-time / B2BRole summaryWe're looking for a Senior Cybersecurity Engineer (Network Security) to join a global pharmaceutical leader's Network Security Product area. You'll act as the primary Subject Matter Expert for Secure Access Network Services, driving the evolution of Network Access Control, identity-driven security, segmentation, and authentication across a global enterprise environment. Your mission: strengthen the organization's '

Defense in Depth' strategy and ensure resilient, compliant, and secure network access for tens of thousands of endpoints worldwide.

Responsibilities

Act as the primary SME for Secure Access technologies, evaluating and selecting emerging security tools and driving the long-term technical roadmap aligned with Zero Trust architecture.

Design, deploy, and maintain authentication solutions using 802.1X, EAP-TLS, EAP-TEAP, RADIUS, TACACS+, SAML, and MFA, integrated with enterprise Identity Providers.

Lead end-to-end lifecycle management of Cisco ISE deployments, including upgrades, capacity planning, and platform optimization.

Implement advanced access control mechanisms (Dot1x, MAB, Guest Access, posture-based authorization) and design Cisco TrustSec / SGT-based micro-segmentation.

Serve as senior escalation point for complex incidents, performing root-cause analysis and building observability/monitoring dashboards.

Advocate for and implement Infrastructure-as-Code and security automation, building API-driven integrations and self-service capabilities.

Mentor junior engineers and collaborate with globally distributed product squads and stakeholders.

Requirements

Must-have:5+ years of hands-on experience designing, implementing, and managing enterprise-grade NAC solutions, specifically Cisco ISE (TrustSec, Dot1x, MAB, Profiling, Guest Portals, REST APIs, EAP-TLS, EAP-TEAP).

Proven experience deploying, configuring, and maintaining Palo Alto NGFW (SSL decryption, threat prevention, HA Active/Active and Active/Passive).

Strong understanding of RADIUS, TACACS+, identity-based access control, and enterprise PKI / certificate lifecycle management.

Proficiency in network virtualization and segmentation (TrustSec, SGTs, VRFs).

Experience using Ansible/Terraform and Python to manage network security infrastructure at scale.

Solid foundation in enterprise networking (L2/L3), including BGP, OSPF, VLANs, VXLAN.

Excellent communication and stakeholder management skills; fluent English.

Nice-to-have:

Experience in highly regulated environments (Pharma, Healthcare, Finance).

Proficiency in Terraform and GitHub for reproducible, version-controlled security configurations.

Experience building CI/CD pipelines (GitLab/GitHub) and automated security workflows.

Scripting skills in Python, PowerShell, or Bash for self-service tools and custom API integrations.

Experience mentoring junior cybersecurity engineers.

Employment conditions:

B2B contract, 150-180 pln/hDaily support from team leaders

  • Dedicated certification budget
  • Assistance in defining and support in your development path
  • Benefits package
  • Integration trips/events
Published 2026-07-13
Source