What you get to do every day: We are seeking an experienced Senior NSX Engineer to design, implement, operate, secure, and troubleshoot VMware NSX-based network virtualization solutions supporting a mission-critical U.S. Department of War environment. The ideal candidate brings 5+ years of hands-on VMware NSX engineering experience, strong VMware vSphere and VMware Cloud Foundation (VCF) integration knowledge, and the ability to own the full NSX lifecycle from architecture and deployment through security hardening, automation, upgrades, and Tier 3 incident resolution.
Key Responsibilities
- Design, deploy, configure, operate, and sustain VMware NSX-T / VMware Cloud Foundation Networking across production, development, test, and mission environments.
- Engineer NSX Manager clusters, transport nodes/profiles, transport zones, uplink profiles, VDS/N-VDS networking, and NSX Edge clusters.
- Design and administer overlay and VLAN-backed segments, Tier-0/Tier-1 gateways, distributed routing, BGP, static routing, ECMP, route redistribution, and north-south/east-west connectivity.
- Implement microsegmentation and Zero Trust-aligned controls using Distributed Firewall, Gateway Firewall, security groups, dynamic membership, tags, context profiles, and policy-based security.
- Develop auditable, least-privilege firewall policies in coordination with cybersecurity, ISSO/ISSM, RMF, application, and network teams.
- Integrate NSX with vCenter, vSphere, VCF, vSAN, VMware Aria Operations/Logs, PKI, identity, SIEM, vulnerability-management, and enterprise monitoring platforms.
- Troubleshoot BGP/routing adjacency failures, MTU/TEP/Geneve issues, asymmetric routing, firewall processing, packet loss, performance degradation, and NSX Edge failures.
- Perform packet-level analysis using NSX CLI/nsxcli, vmkping, pktcap-uw, tcpdump-uw, Traceflow, flow monitoring, and distributed firewall analysis.
- Lead NSX upgrades, patching, certificate replacement, migrations, backup/recovery validation, and lifecycle-management activities with formal implementation, test, validation, and backout plans.
- Maintain engineering standards, configuration baselines, diagrams, firewall matrices, runbooks, and as-built documentation; provide Tier 3 escalation support and mentor junior engineers.
Core Technical Competencies
- NSX Architecture: NSX Manager clusters, transport zones/nodes, Edge clusters, segments, gateways, and security policies.
- Routing: BGP, static routing, ECMP, route redistribution, Tier-0/Tier-1 routing, and physical-network integration.
- Network Security: Microsegmentation, Distributed/Gateway Firewall, dynamic groups, tagging, rule analysis, and least-privilege policies.
- vSphere Networking: vCenter, ESXi, VDS, VMkernel, vmnic, port groups, cluster networking, and host-level troubleshooting.
- Advanced Troubleshooting: Traceflow, NSX CLI, ESXi packet capture, BGP diagnostics, flow analysis, logs, and packet-level troubleshooting.
- Operations & Compliance: Upgrades, backup/recovery, certificates, lifecycle management, RMF, STIGs, ATO support, vulnerability remediation, and change control.
- Automation & Documentation: PowerCLI, Ansible, REST APIs, Git; diagrams, runbooks, firewall matrices, test plans, validation procedures, and backout plans.