Senior Nsx Engineer; Ts/Sci Clearance Required
Listed on 2026-09-12
-
IT/Tech
Systems Engineer, Cybersecurity, Network Engineer, Network Security
SENIOR NSX ENGINEER (TS/SCI CLEARANCE REQUIRED)
- Springfield, VA
- Information Technology
North Hill Technology Resources has a need for a
Senior NSX Engineer
to support a Federal Program in
Springfield, VA
.This is a direct-hire role with our client, a fast-growing Federal Integrator.
An active TS/SCI Clearance is required
, will sponsor for CI Polygraph within first year.
We are seeking a Senior NSX Engineer to design, implement, operate, secure, and troubleshoot VMware NSX-based network virtualization in a mission-critical U.S. Department of Defense environment. The ideal candidate brings at least 5 years of hands-on VMware NSX engineering experience, strong vSphere/VCF integration knowledge, and a proven record working within DoD security, compliance, and operational processes. This role is suited to an engineer who can own the full NSX lifecycle—from architecture and deployment through operational support, hardening, automation, upgrades, and incident resolution—while collaborating effectively with network, cybersecurity, systems, storage, and program teams.
Coreresponsibilities
- Design, deploy, configure, and sustain VMware NSX-T / VCF Networking solutions supporting production, development, test, and mission environments.
- Engineer and maintain NSX management, control, and data planes, including NSX Managers, transport nodes, transport node profiles, host and edge transport zones, uplink profiles, N-VDS or VDS-backed configurations as applicable, and NSX Edge clusters.
- Design and administer logical networking services, including overlay segments, VLAN-backed segments, Tier-0 and Tier-1 gateways, distributed routing, BGP, static routing, ECMP, north-south connectivity, and east-west traffic flows.
- Implement and maintain microsegmentation and zero-trust-aligned controls using NSX Distributed Firewall, Gateway Firewall, groups, tags, service insertion, context profiles, and policy-based security controls.
- Develop and manage firewall rulesets in coordination with cybersecurity, ISSO/ISSM, RMF, application, and network teams; ensure policies follow least-privilege principles and are documented, reviewed, approved, and auditable.
- Integrate NSX with VMware vCenter Server, vSphere clusters, VMware Cloud Foundation, vSAN, VMware Aria Operations/Logs, identity platforms, PKI/certificate services, SIEM platforms, vulnerability-management tools, and enterprise monitoring systems.
- Troubleshoot complex issues across virtual and physical networking layers, including routing adjacency failures, BGP peering, MTU mismatches, tunnel endpoint connectivity, Geneve encapsulation, multicast or unicast replication behavior, firewall rule processing, asymmetric routing, packet loss, performance degradation, and Edge-node failures.
- Perform packet-level troubleshooting using NSX CLI, nsxcli, ESXi commands, vmkping, pktcap-uw, tcpdump-uw, distributed firewall rule analysis, logical-port inspection, traceflow, flow monitoring, and physical-switch diagnostics.
- Lead planning and execution for NSX upgrades, patches, certificate replacement, configuration changes, migrations, backup/restore validation, and lifecycle-management activities while minimizing operational risk and service interruption.
- Develop implementation plans, maintenance-window procedures, backout plans, test plans, validation checklists, and post-change documentation for production changes.
- Support migration efforts from legacy NSX-V, traditional VLAN-based networks, legacy firewall architectures, or standalone NSX environments into VMware Cloud Foundation and modern NSX-based architectures.
- Build and maintain standardized NSX configuration baselines, naming conventions, network diagrams, IP address-management documentation,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).