← All jobs
Senior VMware NSX Engineer
Springfield, VA · On-site · D2
Apply well, not just fast
Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.
About the role
REST APIsNetworkingCybersecurityAnsibleGitSIEMObservabilityZero TrustComplianceCommunication
**ACTIVE TS/SCI SECURITY CLEARANCE REQUIRED**
We are seeking an experienced Senior NSX Engineer to design, implement, operate, secure, and troubleshoot VMware NSX-based network virtualization solutions supporting a mission-critical U.S. Department of War environment. Candidates must possess an active Top Secret/SCI (TS/SCI) security clearance with a current CI Polygraph. The ideal candidate brings 5+ years of hands-on VMware NSX engineering experience, strong VMware vSphere and VMware Cloud Foundation (VCF) integration knowledge, and the ability to own the full NSX lifecycle from architecture and deployment through security hardening, automation, upgrades, and Tier 3 incident resolution.
Key Responsibilities
- Design, deploy, configure, operate, and sustain VMware NSX-T / VMware Cloud Foundation Networking across production, development, test, and mission environments.
- Engineer NSX Manager clusters, transport nodes/profiles, transport zones, uplink profiles, VDS/N-VDS networking, and NSX Edge clusters.
- Design and administer overlay and VLAN-backed segments, Tier-0/Tier-1 gateways, distributed routing, BGP, static routing, ECMP, route redistribution, and north-south/east-west connectivity.
- Implement microsegmentation and Zero Trust-aligned controls using Distributed Firewall, Gateway Firewall, security groups, dynamic membership, tags, context profiles, and policy-based security.
- Develop auditable, least-privilege firewall policies in coordination with cybersecurity, ISSO/ISSM, RMF, application, and network teams
- Integrate NSX with vCenter, vSphere, VCF, vSAN, VMware Aria Operations/Logs, PKI, identity, SIEM, vulnerability-management, and enterprise monitoring platforms
- Troubleshoot BGP/routing adjacency failures, MTU/TEP/Geneve issues, asymmetric routing, firewall processing, packet loss, performance degradation, and NSX Edge failures
- Perform packet-level analysis using NSX CLI/nsxcli, vmkping, pktcap-uw, tcpdump-uw, Traceflow, flow monitoring, and distributed firewall analysis
- Lead NSX upgrades, patching, certificate replacement, migrations, backup/recovery validation, and lifecycle-management activities with formal implementation, test, validation, and backout plans.
- Maintain engineering standards, configuration baselines, diagrams, firewall matrices, runbooks, and as-built documentation; provide Tier 3 escalation support and mentor junior engineers.
Required Qualifications
- Active Top Secret/SCI (TS/SCI) security clearance with current CI Polygraph
- Bachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related discipline; equivalent relevant experience may be substitute
- 5+ years of hands-on VMware NSX experience in enterprise-scale environments and 5+ years of VMware vSphere experience, including ESXi, vCenter Server, VDS, virtual networking, cluster operations, and troubleshooting
- Advanced NSX-T / VCF Networking expertise: overlay/VLAN segments, Tier-0/Tier-1 gateways, Edge Nodes/clusters, BGP, static routing, ECMP, route redistribution, Distributed Firewall, Gateway Firewall, dynamic groups/tagging, NAT, VPN, DHCP, and lifecycle operations
- Strong enterprise networking fundamentals: TCP/IP, DNS, DHCP, ARP, VLANs, VXLAN/Geneve, MTU, BGP, OSPF, VRFs, link aggregation, firewalling, NAT, load balancing, and network troubleshooting
- Experience in DoW, federal civilian, intelligence community, or other highly regulated environments with formal change control, security approval, documentation, and audit requirements.
- Working knowledge of RMF, ATO, DISA STIGs, POA&Ms, vulnerability management, security controls, continuous monitoring, and remediation of applicable security findings
- Strong written and verbal communication skills, including technical diagrams, implementation plans, SOPs, security documentation, and executive-ready status updates.
Required Certifications
Certification requirements should align with the assigned DoW Cyber Workforce Framework / DoW 8140 work role and applicable contract requirements.
- Current CompTIA Security+ CE or another approved DoW 8140-aligned baseline certification appropriate to the assigned work role
- One current VMware/Broadcom networking, security, or VMware Cloud Foundation certification, such as VCP-NV, VMware Cloud Foundation Administrator, VMware Cloud Foundation Architect, or a comparable current NSX/VCF networking certification.
Preferred Qualifications
- Experience designing or supporting VMware Cloud Foundation, including SDDC Manager, workload domains, lifecycle management, vSphere, and NSX integration.
- Experience integrating NSX with Cisco Nexus, Juniper, Palo Alto Networks, F5, or similar enterprise technologies
- Experience with VXLAN/Geneve overlays, BGP underlay/overlay routing, multi-rack architectures, and highly available network services
- Automation / Infrastructure as Code experience using PowerShell/PowerCLI, Ansible, VMware Aria Automation, REST APIs, Git, YAML, and JSON
- Experience integrating NSX telemetry and logs with Splunk, Elastic, or comparable SIEM/observability platforms
- Experience with enterprise PKI, certificate lifecycle management, Active Directory, LDAP, identity federation, RBAC, privileged-access management, and MFA
- Experience supporting classified, disconnected, air-gapped, or tactical-edge environments
- Familiarity with Dell PowerEdge, Cisco UCS, HPE, DISA STIG Viewer, SCAP scanning, ACAS/Nessus, and POA&M remediation workflows.
Core Technical Competencies
- NSX Architecture: NSX Manager clusters, transport zones/nodes, Edge clusters, segments, gateways, and security policies
- Routing: BGP, static routing, ECMP, route redistribution, Tier-0/Tier-1 routing, and physical-network integration
- Network Security: Microsegmentation, Distributed/Gateway Firewall, dynamic groups, tagging, rule analysis, and least-privilege policies
- vSphere Networking: vCenter, ESXi, VDS, VMkernel, vmnic, port groups, cluster networking, and host-level troubleshooting
- Advanced Troubleshooting: Traceflow, NSX CLI, ESXi packet capture, BGP diagnostics, flow analysis, logs, and packet-level troubleshooting
- Operations & Compliance: Upgrades, backup/recovery, certificates, lifecycle management, RMF, STIGs, ATO support, vulnerability remediation, and change control
- Automation & Documentation: PowerCLI, Ansible, REST APIs, Git; diagrams, runbooks, firewall matrices, test plans, validation procedures, and backout plans.
Ideal Candidate is a senior-level engineer who combines deep VMware NSX expertise with strong traditional networking fundamentals and experience operating within classified DoW environments. The successful candidate can independently own complex NSX issues while collaborating across virtualization, networking, cybersecurity, systems, storage, application, and program teams.
Additional Information
- All your information will be kept confidential according to EEO guidelines.
- Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically $150-165k. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.
- Highlights of our benefits include Health/Dental/Vision, 401(k) match, Accrued PTO, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and more!
D2 Technical Services is committed to a merit-based recruitment process and encourages applications from all qualified individuals. As a Veteran-Owned Small Business, we particularly welcome applications from veterans who have the requisite skills and experience. Job applicants that are interested in one of our openings and may require a reasonable accommodation to participate in the job application or interview process, should contact us to request an accommodation.