Senior NSX Engineer

GD Information Technology
  • Springfield, Missouri
    3 days ago

    Job Description

    Type of Requisition:

    Regular

    Clearance Level Must Currently Possess:

    Top Secret/SCI

    Clearance Level Must Be Able to Obtain:

    Top Secret SCI + Polygraph

    Public Trust/Other Required:

    None

    Job Family:

    IT Infrastructure and Operations

    Job Qualifications:

    Skills:

    Networking Fundamentals, VMware, VMware NSX

    Certifications:

    None

    Experience:

    5 + years of related experience

    US Citizenship Required:

    Yes

    Job Description:


    We are seeking an experienced Senior NSX Engineer to design, implement, operate, secure, and troubleshoot VMware NSX-based network virtualization solutions supporting a mission-critical U.S. Department of  War environment. Candidates must possess an active Top Secret/SCI (TS/SCI) security clearance with a current CI Polygraph. The ideal candidate brings 5+ years of hands-on VMware NSX engineering experience, strong VMware vSphere and VMware Cloud Foundation (VCF) integration knowledge, and the ability to own the full NSX lifecycle from architecture and deployment through security hardening, automation, upgrades, and Tier 3 incident resolution.


    Key Responsibilities
    •    Design, deploy, configure, operate, and sustain VMware NSX-T / VMware Cloud Foundation Networking across production, development, test, and mission environments.
    •    Engineer NSX Manager clusters, transport nodes/profiles, transport zones, uplink profiles, VDS/N-VDS networking, and NSX Edge clusters.
    •    Design and administer overlay and VLAN-backed segments, Tier-0/Tier-1 gateways, distributed routing, BGP, static routing, ECMP, route redistribution, and north-south/east-west connectivity.
    •    Implement microsegmentation and Zero Trust-aligned controls using Distributed Firewall, Gateway Firewall, security groups, dynamic membership, tags, context profiles, and policy-based security.
    •    Develop auditable, least-privilege firewall policies in coordination with cybersecurity, ISSO/ISSM, RMF, application, and network teams.
    •    Integrate NSX with vCenter, vSphere, VCF, vSAN, VMware Aria Operations/Logs, PKI, identity, SIEM, vulnerability-management, and enterprise monitoring platforms.
    •    Troubleshoot BGP/routing adjacency failures, MTU/TEP/Geneve issues, asymmetric routing, firewall processing, packet loss, performance degradation, and NSX Edge failures.
    •    Perform packet-level analysis using NSX CLI/nsxcli, vmkping, pktcap-uw, tcpdump-uw, Traceflow, flow monitoring, and distributed firewall analysis.
    •    Lead NSX upgrades, patching, certificate replacement, migrations, backup/recovery validation, and lifecycle-management activities with formal implementation, test, validation, and backout plans.
    •    Maintain engineering standards, configuration baselines, diagrams, firewall matrices, runbooks, and as-built documentation; provide Tier 3 escalation support and mentor junior engineers.


    Required Qualifications
    •    Active Top Secret/SCI (TS/SCI) security clearance with current CI Polygraph.
    •    Bachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related discipline; equivalent relevant experience may be substituted.
    •    5+ years of hands-on VMware NSX experience in enterprise-scale environments and 5+ years of VMware vSphere experience, including ESXi, vCenter Server, VDS, virtual networking, cluster operations, and troubleshooting.
    •    Advanced NSX-T / VCF Networking expertise: overlay/VLAN segments, Tier-0/Tier-1 gateways, Edge Nodes/clusters, BGP, static routing, ECMP, route redistribution, Distributed Firewall, Gateway Firewall, dynamic groups/tagging, NAT, VPN, DHCP, and lifecycle operations.
    •    Strong enterprise networking fundamentals: TCP/IP, DNS, DHCP, ARP, VLANs, VXLAN/Geneve, MTU, BGP, OSPF, VRFs, link aggregation, firewalling, NAT, load balancing, and network troubleshooting.
    •    Experience in DoW, federal civilian, intelligence community, or other highly regulated environments with formal change control, security approval, documentation, and audit requirements.
    •    Working knowledge of RMF, ATO, DISA STIGs, POA&Ms, vulnerability management, security controls, continuous monitoring, and remediation of applicable security findings.
    •    Strong written and verbal communication skills, including technical diagrams, implementation plans, SOPs, security documentation, and executive-ready status updates.
     
    Required Certifications
    Certification requirements should align with the assigned DoW Cyber Workforce Framework / DoW 8140 work role and applicable contract requirements.
    •    Current CompTIA Security+ CE or another approved DoW 8140-aligned baseline certification appropriate to the assigned work role.
    •    One current VMware/Broadcom networking, security, or VMware Cloud Foundation certification, such as VCP-NV, VMware Cloud Foundation Administrator, VMware Cloud Foundation Architect, or a comparable current NSX/VCF networking certification.

    Preferred Qualifications
    •    Experience designing or supporting VMware Cloud Foundation, including SDDC Manager, workload domains, lifecycle management, vSphere, and NSX integration.
    •    Experience integrating NSX with Cisco Nexus, Juniper, Palo Alto Networks, F5, or similar enterprise technologies.
    •    Experience with VXLAN/Geneve overlays, BGP underlay/overlay routing, multi-rack architectures, and highly available network services.
    •    Automation / Infrastructure as Code experience using PowerShell/PowerCLI, Ansible, VMware Aria Automation, REST APIs, Git, YAML, and JSON.
    •    Experience integrating NSX telemetry and logs with Splunk, Elastic, or comparable SIEM/observability platforms.
    •    Experience with enterprise PKI, certificate lifecycle management, Active Directory, LDAP, identity federation, RBAC, privileged-access management, and MFA.
    •    Experience supporting classified, disconnected, air-gapped, or tactical-edge environments.
    •    Familiarity with Dell PowerEdge, Cisco UCS, HPE, DISA STIG Viewer, SCAP scanning, ACAS/Nessus, and POA&M remediation workflows.
    Core Technical Competencies
    NSX Architecture: NSX Manager clusters, transport zones/nodes, Edge clusters, segments, gateways, and security policies.
    Routing: BGP, static routing, ECMP, route redistribution, Tier-0/Tier-1 routing, and physical-network integration.
    Network Security: Microsegmentation, Distributed/Gateway Firewall, dynamic groups, tagging, rule analysis, and least-privilege policies.
    vSphere Networking: vCenter, ESXi, VDS, VMkernel, vmnic, port groups, cluster networking, and host-level troubleshooting.
    Advanced Troubleshooting: Traceflow, NSX CLI, ESXi packet capture, BGP diagnostics, flow analysis, logs, and packet-level troubleshooting.
    Operations & Compliance: Upgrades, backup/recovery, certificates, lifecycle management, RMF, STIGs, ATO support, vulnerability remediation, and change control.
    Automation & Documentation: PowerCLI, Ansible, REST APIs, Git; diagrams, runbooks, firewall matrices, test plans, validation procedures, and backout plans.


    Ideal Candidate
    A senior-level engineer who combines deep VMware NSX expertise with strong traditional networking fundamentals and experience operating within classified DoW environments. The successful candidate can independently own complex NSX issues while collaborating across virtualization, networking, cybersecurity, systems, storage, application, and program teams.


    Location: Customer Site

    US Citizenship Required 



    The likely salary range for this position is $125,800 - $170,200. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

    Scheduled Weekly Hours:

    40

    Travel Required:

    None

    Telecommuting Options:

    Onsite

    Work Location:

    USA VA Springfield

    Additional Work Locations:

    Total Rewards at GDIT:

    Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

     

     


    Our Identity Verification Process:

    As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

     

     

    About Our Work:

    We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

    Join our Talent Community to stay up to date on our career opportunities and events at

    gdit.com/tc.

    Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

    Numbers & Facts

    LocationSpringfield, Missouri
    Websitegdit.com/tc

    Skills

    • Accidental Death and Dismemberment (AD&D)unmatched
    • Analysis Skillsunmatched
    • Ansibleunmatched
    • Application Programming Interface (API)unmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • BGPunmatched
    • Biometricsunmatched
    • Change Controlunmatched
    • Cisco Nexus Switchesunmatched
    • Cisco Unified Computing System (UCS)unmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Contract Requirementsunmatched
    • DHCP (Dynamic Host Configuration Protocol)unmatched
    • Data Recoveryunmatched
    • Defense Information Systems Agency (DISA)unmatched
    • Defense Intelligenceunmatched
    • Dell Computersunmatched
    • Digital Certificatesunmatched
    • Documentationunmatched
    • EDGE (Enhanced Data for GSM Evolution)unmatched
    • Engineeringunmatched
    • F5 Network Softwareunmatched
    • Firewallsunmatched
    • Gitunmatched
    • Governmentunmatched
    • Health Planunmatched
    • High Availabilityunmatched
    • Identify Issuesunmatched
    • Identity Federationunmatched
    • Information Technology & Information Systemsunmatched
    • Insuranceunmatched
    • Intelligence Communityunmatched
    • Internet Securityunmatched
    • JSONunmatched
    • Juniper Networks Product Familyunmatched
    • Knowledge Managementunmatched
    • LDAP (Lightweight Directory Access Protocol)unmatched
    • Mentoringunmatched
    • Microsoft Active Directoryunmatched
    • NAT (Network Address Translation)unmatched
    • Nessusunmatched
    • Network Integrationunmatched
    • Network Routingunmatched
    • Network Securityunmatched
    • Presentation/Verbal Skillsunmatched
    • Procedure Implementationunmatched
    • Professional Servicesunmatched
    • Public Key Infrastructure (PKI)unmatched
    • REST (Representational State Transfer)unmatched
    • Security Clearanceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Policyunmatched
    • Sensitive Compartmented Information (SCI)unmatched
    • Software Developmentunmatched
    • Software Patchesunmatched
    • Splunkunmatched
    • Technical Deliveryunmatched
    • Technical Drawingunmatched
    • Telemetryunmatched
    • Test Plan/Scheduleunmatched
    • Top Secret Clearanceunmatched
    • United States Citizenunmatched
    • VLAN (Virtual Local Area Network)unmatched
    • VMWareunmatched
    • VMWare Certificationsunmatched
    • VMWare Certified Professional (VCP)unmatched
    • VMWare ESX/ESXiunmatched
    • VMWare vCenterunmatched
    • VMWare vSphereunmatched
    • VPN (Virtual Private Network)unmatched
    • Validation Planunmatched
    • Validation Testingunmatched
    • Virtualizationunmatched
    • Willing to Travelunmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched
    • tcpdumpunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder