Sr. NSX Engineer

Location: Springfield, VA, US
Job ID: ATR 18088
Apply Now Back to Results

Job Description

Job Title: Sr. NSX Engineer
Job Location: Springfield, VA
Compensation: $160,000 - $180,000
Eligibility/Clearance: Candidate must possess an active TS/SCI clearance
and be willing to obtain a CI Polygraph
Job Description:
We are seeking a Senior NSX Engineer to design, implement, operate,
secure, and troubleshoot VMware NSX-based network virtualization in a
mission-critical U.S. Department of Defense environment. The ideal
candidate brings at least 5 years of hands-on VMware NSX engineering
experience, strong vSphere/VCF integration knowledge, and a proven
record working within DoD security, compliance, and operational
processes.
This role is suited to an engineer who can own the full NSX
lifecycle—from architecture and deployment through operational support,
hardening, automation, upgrades, and incident resolution—while
collaborating effectively with network, cybersecurity, systems, storage,
and program teams.
Key Responsibilities
· · Design, deploy, configure, and sustain VMware NSX-T / VCF Networking
solutions supporting production, development, test, and mission
environments.
· Engineer and maintain NSX management, control, and data planes,
including NSX Managers, transport nodes, transport node profiles, host
and edge transport zones, uplink profiles, N-VDS or VDS-backed
configurations as applicable, and NSX Edge clusters.
· Design and administer logical networking services, including overlay
segments, VLAN-backed segments, Tier-0 and Tier-1 gateways, distributed
routing, BGP, static routing, ECMP, north-south connectivity, and
east-west traffic flows.
· Implement and maintain microsegmentation and zero-trust-aligned
controls using NSX Distributed Firewall, Gateway Firewall, groups, tags,
service insertion, context profiles, and policy-based security controls.
· Develop and manage firewall rulesets in coordination with
cybersecurity, ISSO/ISSM, RMF, application, and network teams; ensure
policies follow least-privilege principles and are documented, reviewed,
approved, and auditable.
· Integrate NSX with VMware vCenter Server, vSphere clusters, VMware
Cloud Foundation, vSAN, VMware Aria Operations/Logs, identity platforms,
PKI/certificate services, SIEM platforms, vulnerability-management
tools, and enterprise monitoring systems.
· Troubleshoot complex issues across virtual and physical networking
layers, including routing adjacency failures, BGP peering, MTU
mismatches, tunnel
endpoint connectivity, Geneve encapsulation, multicast or unicast
replication behavior, firewall rule processing, asymmetric routing,
packet loss, performance degradation, and Edge-node failures.
· Perform packet-level troubleshooting using NSX CLI, nsxcli, ESXi
commands, vmkping, pktcap-uw, tcpdump-uw, distributed firewall rule
analysis, logical-port inspection, traceflow, flow monitoring, and
physical-switch diagnostics.
· Lead planning and execution for NSX upgrades, patches, certificate
replacement, configuration changes, migrations, backup/restore
validation, and lifecycle-management activities while minimizing
operational risk and service interruption.
· Develop implementation plans, maintenance-window procedures, backout
plans, test plans, validation checklists, and post-change documentation
for production changes.
· Support migration efforts from legacy NSX-V, traditional VLAN-based
networks, legacy firewall architectures, or standalone NSX environments
into VMware Cloud Foundation and modern NSX-based architectures.
· Build and maintain standardized NSX configuration baselines, naming
conventions, network diagrams, IP address-management documentation,
firewall-policy matrices, operational runbooks, and as-built
documentation.
· Participate in architecture reviews, design discussions, technical
interchange meetings, engineering change reviews, compliance
assessments, and operational readiness reviews.
· Provide Tier 3 escalation support for NSX, vSphere networking,
distributed firewalling, routing, and virtual network security
incidents.
· Mentor junior engineers and administrators; establish repeatable
engineering standards and operational procedures for NSX support.
Skills/Qualifications:
Required:
· Bachelor’s degree in Information Technology, Computer Science,
Engineering, Cybersecurity, or a related discipline; equivalent
relevant experience may be substituted.
· At least 5 years of hands-on experience designing, implementing,
operating, or supporting VMware NSX in enterprise-scale environments.
· At least 5 years of experience with VMware vSphere, including ESXi,
vCenter Server, vSphere Distributed Switches, virtual networking,
cluster operations, host lifecycle management, and troubleshooting.
· Demonstrated expertise with NSX-T / VMware Cloud Foundation
Networking capabilities, including:
o Overlay and VLAN-backed segments
o Tier-0 and Tier-1 gateways
o Distributed routing and centralized services
o NSX Edge Nodes and Edge clusters
o BGP, static routing, ECMP, and route redistribution
o Distributed Firewall and Gateway Firewall
o Security groups, dynamic membership, tagging, and policy automation
o North-south and east-west traffic design
o VPN, NAT, load-balancing, DHCP, DNS forwarding, and other NSX
services as applicable
o NSX Manager clustering, backups, certificates, upgrades, and
recovery procedures
· Strong understanding of enterprise networking fundamentals,
including TCP/IP, DNS, DHCP, ARP, VLANs, VXLAN/Geneve, MTU, routing,
BGP, OSPF, VRFs, link aggregation, firewalling, NAT, load balancing,
and network troubleshooting.
· Hands-on experience operating in DoD, federal civilian, intelligence
community, or other heavily regulated environments with formal change
control, documentation, security approval, and audit requirements.
· Working knowledge of DoD cybersecurity processes and terminology,
including RMF, ATO, STIGs, POA&Ms, vulnerability management, DISA
guidance, security controls, and continuous monitoring.
· Ability to review, interpret, and remediate applicable DISA STIGs
and security findings for VMware components, operating systems, and
supporting infrastructure.
· Strong written and verbal communication skills, including the
ability to create technical diagrams, implementation plans, security
documentation, standard operating procedures, and executive-ready
status updates.
Required certifications
The final certification requirement should align with the contract’s
assigned DoD Cyber Workforce Framework role and component-specific
guidance. A practical baseline for this role is:
· Current CompTIA Security+ CE or another approved DoD 8140-aligned
baseline certification appropriate to the assigned work role.
· One current VMware/Broadcom networking, security, or
cloud-foundation certification, such as:
o VMware Certified Professional – Network Virtualization / VCP-NV, if
held and applicable
o VMware Certified Professional – VMware Cloud Foundation
Administrator
o VMware Certified Professional – VMware Cloud Foundation Architect
o Comparable current Broadcom/VMware certification focused on NSX, VCF
networking, or network virtualization
Desired:
· 5+ years of enterprise network virtualization, virtual
infrastructure, network security, or cloud-platform engineering
experience.
· Experience designing or supporting VMware Cloud Foundation
environments, including VCF lifecycle management, SDDC Manager,
workload domains, vSphere, and NSX integration.
· Experience integrating NSX with physical enterprise networks,
including Cisco Nexus, Juniper, Palo Alto Networks, F5, or similar
technologies.
· Familiarity with data-center architectures such as VXLAN, BGP
underlay/overlay routing, multi-rack design, and high-availability
network services.
· Experience with automation and infrastructure as code using
PowerShell/PowerCLI, Ansible, VMware Aria Automation, REST APIs, Git,
YAML, and JSON.
· Experience integrating NSX telemetry and logs with Splunk and
Elastic.
· Experience with enterprise PKI, certificate lifecycle management,
Active Directory, LDAP, identity federation, RBAC, privileged-access
management, and multifactor authentication.
· Experience supporting disconnected, air-gapped, tactical edge, or
classified environments.
· Experience with Dell PowerEdge, Cisco UCS, HPE and storage/network
performance troubleshooting.
· Familiarity with DISA STIG Viewer, SCAP scanning, ACAS/Nessus and
POA&M remediation workflows.
Education:
Bachelors Degree in Computer Science or a related field
ATR is an Equal Opportunity Employer (EOE) who will provide equal
employment opportunity to employees and applicants for employment
without regard to race, ethnicity, religion, color, sex, pregnancy,
national origin, age, veteran status, ancestry, sexual orientation,
gender identity or expression, marital status, family structure, genetic
information, or mental or physical disability
Apply Now Back to Results

Apply Now

Required
Required
Required

Resume

Required, maximum file size is 512KB, allowed file types are doc, docx, pdf, odf, and txt

Send Us Your Information

We are always looking for passionate and dedicated people to join our team.

Send us your resume and if a job opens up and we find a good match, we’ll be in touch!

Your Information

Please ensure all fields have been filled.

Your Information

Upload your Resume

Please note only files with .pdf, .docx , .rtf or .doc file extensions are accepted.

Max file weight: 512KB.

Please attach your resume, ensure it is in the correct format and smaller than 512KB.

×