Senior Secure Access Engineer – Network Products
bupa · Salford Quays · Hybrid
Posted Oct 7, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Job Description:
Senior Secure Access Engineer – Network Products
Salary: From £60,000+ (depending on exp.) Plus 10% yearly bonus and benefits
Contract type: Permanent
Shift pattern: Full-time – 37.5 hours per week
Location : Salford (M50 3SP), Staines (TW18 3DZ), Leeds (LS5 3BF), London (EC2R 7HJ), Brighton (BN1 4FY) Hybrid Working: 2 Days in office
We make health happen
At Bupa, we’re passionate about technology. With colleagues, customers, patients and residents in mind you’ll have the opportunity to work on innovative projects and make a real impact on their lives.
Right from the start you’ll become part of our digital strategy, joining us on our journey and developing yourself along the way.
Role Overview
The Senior Secure Access Engineer role will be responsible for the design, implementation, administration, and continuous improvement of Bupa's Cisco Identity Services Engine (ISE) platform and associated Network Access Control (NAC) services.
The role will ensure the availability, performance, security, and ongoing enhancement of the Cisco ISE estate, supporting secure access to wired, wireless, and remote network services across the organisation. Working within the IP&P Product stack, the engineer will be responsible for developing and maintaining authentication, authorisation, profiling, posture assessment, and network segmentation policies while ensuring alignment with Bupa's security standards and Zero Trust principles.
The successful candidate will act as a subject matter expert for Cisco ISE, providing technical leadership, operational support, service improvement, and project delivery capabilities, whilst maintaining comprehensive documentation and demonstrating measurable service enhancements.
How you'll help us make health happen
Design, implement, configure, and support Cisco ISE infrastructure and associated Network Access Control (NAC) services.
Develop and maintain authentication, authorisation and accounting (AAA) services using RADIUS and TACACS+.
Design, implement and manage 802.1X authentication solutions across wired, wireless and remote access environments.
Create, maintain and optimise Cisco ISE policy sets, authorisation rules, endpoint groups, profiling policies and posture policies.
Implement and manage device profiling, posture assessment and compliance validation to ensure only authorised and compliant devices gain network access.
Design and maintain network segmentation policies using VLAN assignments, downloadable ACLs, Security Group Tags (SGTs) and TrustSec capabilities.
Support guest access services, self-registration portals and third-party onboarding workflows within Cisco ISE.
Monitor and maintain the health, performance, resilience and capacity of the Cisco ISE platform, ensuring timely patching, upgrades and lifecycle management.
Troubleshoot complex authentication, authorisation and network access issues, working closely with Network, EUC, Security and Infrastructure…