Senior Nsx Engineer

Select Search Associates
  • Springfield, Virginia
  • Autofill and Review
8 days ago

Job Description

  • Springfield, VA
  • Information Technology

SSA LLC has a need for a Senior NSX Engineerto support a Federal Program in Springfield, VA.  This is a direct-hire role with our client, a fast-growing Federal Integrator.  An active TS/SCI Clearance is required, will sponsor for CI Polygraph within first year.

Senior NSX Engineer — DoD Environment We are seeking a Senior NSX Engineer to design, implement, operate, secure, and troubleshoot VMware NSX-based network virtualization in a mission-critical U.S. Department of Defense environment. The ideal candidate brings at least 5 years of hands-on VMware NSX engineering experience, strong vSphere/VCF integration knowledge, and a proven record working within DoD security, compliance, and operational processes. This role is suited to an engineer who can own the full NSX lifecycle—from architecture and deployment through operational support, hardening, automation, upgrades, and incident resolution—while collaborating effectively with network, cybersecurity, systems, storage, and program teams.Core responsibilities
  • Design, deploy, configure, and sustain VMware NSX-T / VCF Networking solutions supporting production, development, test, and mission environments.
  • Engineer and maintain NSX management, control, and data planes, including NSX Managers, transport nodes, transport node profiles, host and edge transport zones, uplink profiles, N-VDS or VDS-backed configurations as applicable, and NSX Edge clusters.
  • Design and administer logical networking services, including overlay segments, VLAN-backed segments, Tier-0 and Tier-1 gateways, distributed routing, BGP, static routing, ECMP, north-south connectivity, and east-west traffic flows.
  • Implement and maintain microsegmentation and zero-trust-aligned controls using NSX Distributed Firewall, Gateway Firewall, groups, tags, service insertion, context profiles, and policy-based security controls.
  • Develop and manage firewall rulesets in coordination with cybersecurity, ISSO/ISSM, RMF, application, and network teams; ensure policies follow least-privilege principles and are documented, reviewed, approved, and auditable.
  • Integrate NSX with VMware vCenter Server, vSphere clusters, VMware Cloud Foundation, vSAN, VMware Aria Operations/Logs, identity platforms, PKI/certificate services, SIEM platforms, vulnerability-management tools, and enterprise monitoring systems.
  • Troubleshoot complex issues across virtual and physical networking layers, including routing adjacency failures, BGP peering, MTU mismatches, tunnel endpoint connectivity, Geneve encapsulation, multicast or unicast replication behavior, firewall rule processing, asymmetric routing, packet loss, performance degradation, and Edge-node failures.
  • Perform packet-level troubleshooting using NSX CLI, nsxcli, ESXi commands, vmkping, pktcap-uw, tcpdump-uw, distributed firewall rule analysis, logical-port inspection, traceflow, flow monitoring, and physical-switch diagnostics.
  • Lead planning and execution for NSX upgrades, patches, certificate replacement, configuration changes, migrations, backup/restore validation, and lifecycle-management activities while minimizing operational risk and service interruption.
  • Develop implementation plans, maintenance-window procedures, backout plans, test plans, validation checklists, and post-change documentation for production changes.
  • Support migration efforts from legacy NSX-V, traditional VLAN-based networks, legacy firewall architectures, or standalone NSX environments into VMware Cloud Foundation and modern NSX-based architectures.
  • Build and maintain standardized NSX configuration baselines, naming conventions, network diagrams, IP address-management documentation, firewall-policy matrices, operational runbooks, and as-built documentation.
  • Participate in architecture reviews, design discussions, technical interchange meetings, engineering change reviews, compliance assessments, and operational readiness reviews.
  • Provide Tier 3 escalation support for NSX, vSphere networking, distributed firewalling, routing, and virtual network security incidents.
  • Mentor junior engineers and administrators; establish repeatable engineering standards and operational procedures for NSX support.
Required qualifications
  • Bachelor’s degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related discipline; equivalent relevant experience may be substituted.
  • At least 5 years of hands-on experience designing, implementing, operating, or supporting VMware NSX in enterprise-scale environments.
  • At least 5 years of experience with VMware vSphere, including ESXi, vCenter Server, vSphere Distributed Switches, virtual networking, cluster operations, host lifecycle management, and troubleshooting.
  • Demonstrated expertise with NSX-T / VMware Cloud Foundation Networking capabilities, including:*
    • Overlay and VLAN-backed segments
    • Tier-0 and Tier-1 gateways
    • Distributed routing and centralized services
    • NSX Edge Nodes and Edge clusters
    • BGP, static routing, ECMP, and route redistribution
    • Distributed Firewall and Gateway Firewall
    • Security groups, dynamic membership, tagging, and policy automation
    • North-south and east-west traffic design
    • VPN, NAT, load-balancing, DHCP, DNS forwarding, and other NSX services as applicable
    • NSX Manager clustering, backups, certificates, upgrades, and recovery procedures
  • Strong understanding of enterprise networking fundamentals, including TCP/IP, DNS, DHCP, ARP, VLANs, VXLAN/Geneve, MTU, routing, BGP, OSPF, VRFs, link aggregation, firewalling, NAT, load balancing, and network troubleshooting.
  • Hands-on experience operating in DoD, federal civilian, intelligence community, or other heavily regulated environments with formal change control, documentation, security approval, and audit requirements.
  • Working knowledge of DoD cybersecurity processes and terminology, including RMF, ATO, STIGs, POA&Ms, vulnerability management, DISA guidance, security controls, and continuous monitoring.
  • Ability to review, interpret, and remediate applicable DISA STIGs and security findings for VMware components, operating systems, and supporting infrastructure.
  • Strong written and verbal communication skills, including the ability to create technical diagrams, implementation plans, security documentation, standard operating procedures, and executive-ready status updates.
Required certifications The final certification requirement should align with the contract’s assigned DoD Cyber Workforce Framework role and component-specific guidance. A practical baseline for this role is:
  • Current CompTIA Security+ CE or another approved DoD 8140-aligned baseline certification appropriate to the assigned work role.
  • One current VMware/Broadcom networking, security, or cloud-foundation certification, such as:*
    • VMware Certified Professional – Network Virtualization / VCP-NV, if held and applicable
    • VMware Certified Professional – VMware Cloud Foundation Administrator
    • VMware Certified Professional – VMware Cloud Foundation Architect
    • Comparable current Broadcom/VMware certification focused on NSX, VCF networking, or network virtualization
Preferred qualifications
  • 5+ years of enterprise network virtualization, virtual infrastructure, network security, or cloud-platform engineering experience.
  • Experience designing or supporting VMware Cloud Foundation environments, including VCF lifecycle management, SDDC Manager, workload domains, vSphere, and NSX integration.
  • Experience integrating NSX with physical enterprise networks, including Cisco Nexus, Juniper, Palo Alto Networks, F5, or similar technologies.
  • Familiarity with data-center architectures such as VXLAN, BGP underlay/overlay routing, multi-rack design, and high-availability network services.
  • Experience with automation and infrastructure as code using PowerShell/PowerCLI,  Ansible, VMware Aria Automation, REST APIs, Git, YAML, and JSON.
  • Experience integrating NSX telemetry and logs with Splunk and Elastic.
  • Experience with enterprise PKI, certificate lifecycle management, Active Directory, LDAP, identity federation, RBAC, privileged-access management, and multifactor authentication.
  • Experience supporting disconnected, air-gapped, tactical edge, or classified environments.
  • Experience with Dell PowerEdge, Cisco UCS, HPE and storage/network performance troubleshooting.
  • Familiarity with DISA STIG Viewer, SCAP scanning, ACAS/Nessus and POA&M remediation workflows.
Technical Skills
Technical domainRequired capability
NSX architectureDesign and operate NSX Manager clusters, transport zones, transport nodes, Edge clusters, segments, gateways, and security policies
RoutingTroubleshoot and configure BGP, static routes, ECMP, route redistribution, Tier-0/Tier-1 routing, and physical-network integration
Network securityImplement microsegmentation, Distributed Firewall, Gateway Firewall, dynamic groups, tagging, rule analysis, and least-privilege policies
vSphereDeep vCenter, ESXi, VDS, VMkernel, vmnic, port-group, cluster, and host-networking knowledge
TroubleshootingUse traceflow, NSX CLI, ESXi packet capture, flow data, logs, BGP diagnostics, and packet-level analysis
OperationsExecute upgrades, backup/recovery, certificate replacement, lifecycle management, and maintenance-window changes
DoD complianceSupport RMF, STIGs, ATO packages, vulnerability remediation, change control, audit evidence, and continuous monitoring
AutomationBuild repeatable workflows using PowerCLI, Ansible, REST APIs, Git, or equivalent tooling
DocumentationProduce and maintain diagrams, runbooks, firewall matrices, test plans  and backout plans

Numbers & Facts

LocationSpringfield, Virginia

Skills

  • Address Managementunmatched
  • Analysis Skillsunmatched
  • Ansibleunmatched
  • Application Programming Interface (API)unmatched
  • Authenticationunmatched
  • Automationunmatched
  • BGPunmatched
  • Change Controlunmatched
  • Cisco Nexus Switchesunmatched
  • Cisco Unified Computing System (UCS)unmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Component Frameworksunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • DHCP (Dynamic Host Configuration Protocol)unmatched
  • DNS (Domain Name System)unmatched
  • Data Recoveryunmatched
  • Defense Information Systems Agency (DISA)unmatched
  • Dell Computersunmatched
  • Digital Certificatesunmatched
  • DoD Directive 8140unmatched
  • DoD Directive 8570unmatched
  • Document Managementunmatched
  • Documentationunmatched
  • Documentation Planunmatched
  • Documentation Standardsunmatched
  • Engineeringunmatched
  • F5 Network Softwareunmatched
  • Firewallsunmatched
  • Gitunmatched
  • High Availabilityunmatched
  • Identify Issuesunmatched
  • Identity Federationunmatched
  • Information Technology & Information Systemsunmatched
  • Intellectual Property (IP)unmatched
  • Intelligence Communityunmatched
  • Internet Securityunmatched
  • JSONunmatched
  • Juniper Networks Product Familyunmatched
  • Knowledge Managementunmatched
  • LDAP (Lightweight Directory Access Protocol)unmatched
  • Load Balancingunmatched
  • Machine Toolunmatched
  • Mentoringunmatched
  • Microsoft Active Directoryunmatched
  • Multicastunmatched
  • NAT (Network Address Translation)unmatched
  • Nessusunmatched
  • Network Administration/Managementunmatched
  • Network Integrationunmatched
  • Network Operations Centerunmatched
  • Network Performance/Analysisunmatched
  • Network Routingunmatched
  • Network Securityunmatched
  • Network Switchingunmatched
  • Operating Systemsunmatched
  • Operational Auditunmatched
  • Operational Supportunmatched
  • Operations Processesunmatched
  • Presentation/Verbal Skillsunmatched
  • Production Supportunmatched
  • Public Key Infrastructure (PKI)unmatched
  • REST (Representational State Transfer)unmatched
  • Replication and Remote Mirroringunmatched
  • Risk Managementunmatched
  • Security Auditingunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Policyunmatched
  • Sensitive Compartmented Information (SCI)unmatched
  • Server Clustersunmatched
  • Software Patchesunmatched
  • Splunkunmatched
  • Standard Operating Procedures (SOP)unmatched
  • Technical Drawingunmatched
  • Technical/Engineering Designunmatched
  • Telemetryunmatched
  • Test Plan/Scheduleunmatched
  • Top Secret Clearanceunmatched
  • Transportation and Traffic Designunmatched
  • United States Department of Defense (DoD)unmatched
  • VLAN (Virtual Local Area Network)unmatched
  • VMWareunmatched
  • VMWare Certificationsunmatched
  • VMWare Certified Professional (VCP)unmatched
  • VMWare ESX/ESXiunmatched
  • VMWare vCenterunmatched
  • VMWare vSphereunmatched
  • VPN (Virtual Private Network)unmatched
  • Validation Planunmatched
  • Validation Testingunmatched
  • Virtualizationunmatched
  • Web Application Frameworkunmatched
  • Windows PowerShellunmatched
  • Writing Skillsunmatched
  • tcpdumpunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder