Sr. NSX Engineer
Arena Technical Resources, LLC
Springfield, VAJob$160–180K/yrSeen todaySeen in employer's feed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Springfield, VA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Requirements
Credentials this posting asks for.
Job overview
The Sr. NSX Engineer will design, implement, operate, secure, and troubleshoot VMware NSX network virtualization for mission-critical Department of Defense environments, collaborating with network, cybersecurity, systems, and program teams while managing the full NSX lifecycle and ensuring compliance with DoD security standards.
Skills & qualifications
Skills
Qualifications
Full job description
Sr. NSX Engineer
Location: Springfield, VA, US
Job ID: ATR 18088
Job Description
Job Title: Sr. NSX Engineer
Job Location: Springfield, VA
Compensation: $160,000 - $180,000
Eligibility/Clearance: Candidate must possess an active TS/SCI clearance
and be willing to obtain a CI Polygraph
Job Description:
We are seeking a Senior NSX Engineer to design, implement, operate,
secure, and troubleshoot VMware NSX-based network virtualization in a
mission-critical U.S. Department of Defense environment. The ideal
candidate brings at least 5 years of hands-on VMware NSX engineering
experience, strong vSphere/VCF integration knowledge, and a proven
record working within DoD security, compliance, and operational
processes.
This role is suited to an engineer who can own the full NSX
lifecycle—from architecture and deployment through operational support,
hardening, automation, upgrades, and incident resolution—while
collaborating effectively with network, cybersecurity, systems, storage,
and program teams.
Key Responsibilities
- · Design, deploy, configure, and sustain VMware NSX-T / VCF Networking
solutions supporting production, development, test, and mission
environments.
- Engineer and maintain NSX management, control, and data planes,
including NSX Managers, transport nodes, transport node profiles, host
and edge transport zones, uplink profiles, N-VDS or VDS-backed
configurations as applicable, and NSX Edge clusters.
- Design and administer logical networking services, including overlay
segments, VLAN-backed segments, Tier-0 and Tier-1 gateways, distributed
routing, BGP, static routing, ECMP, north-south connectivity, and
east-west traffic flows.
- Implement and maintain microsegmentation and zero-trust-aligned
controls using NSX Distributed Firewall, Gateway Firewall, groups, tags,
service insertion, context profiles, and policy-based security controls.
- Develop and manage firewall rulesets in coordination with
cybersecurity, ISSO/ISSM, RMF, application, and network teams; ensure
policies follow least-privilege principles and are documented, reviewed,
approved, and auditable.
- Integrate NSX with VMware vCenter Server, vSphere clusters, VMware
Cloud Foundation, vSAN, VMware Aria Operations/Logs, identity platforms,
PKI/certificate services, SIEM platforms, vulnerability-management
tools, and enterprise monitoring systems.
- Troubleshoot complex issues across virtual and physical networking
layers, including routing adjacency failures, BGP peering, MTU
mismatches, tunnel
endpoint connectivity, Geneve encapsulation, multicast or unicast
replication behavior, firewall rule processing, asymmetric routing,
packet loss, performance degradation, and Edge-node failures.
- Perform packet-level troubleshooting using NSX CLI, nsxcli, ESXi
commands, vmkping, pktcap-uw, tcpdump-uw, distributed firewall rule
analysis, logical-port inspection, traceflow, flow monitoring, and
physical-switch diagnostics.
- Lead planning and execution for NSX upgrades, patches, certificate
replacement, configuration changes, migrations, backup/restore
validation, and lifecycle-management activities while minimizing
operational risk and service interruption.
- Develop implementation plans, maintenance-window procedures, backout
plans, test plans, validation checklists, and post-change documentation
for production changes.
- Support migration efforts from legacy NSX-V, traditional VLAN-based
networks, legacy firewall architectures, or standalone NSX environments
into VMware Cloud Foundation and modern NSX-based architectures.
- Build and maintain standardized NSX configuration baselines, naming
conventions, network diagrams, IP address-management documentation,
firewall-policy matrices, operational runbooks, and as-built
documentation.
- Participate in architecture reviews, design discussions, technical
interchange meetings, engineering change reviews, compliance
assessments, and operational readiness reviews.
- Provide Tier 3 escalation support for NSX, vSphere networking,
distributed firewalling, routing, and virtual network security
incidents.
- Mentor junior engineers and administrators; establish repeatable
engineering standards and operational procedures for NSX support.
Skills/Qualifications:
Required:
- Bachelor’s degree in Information Technology, Computer Science,
Engineering, Cybersecurity, or a related discipline; equivalent
relevant experience may be substituted.
- At least 5 years of hands-on experience designing, implementing,
operating, or supporting VMware NSX in enterprise-scale environments.
- At least 5 years of experience with VMware vSphere, including ESXi,
vCenter Server, vSphere Distributed Switches, virtual networking,
cluster operations, host lifecycle management, and troubleshooting.
- Demonstrated expertise with NSX-T / VMware Cloud Foundation
Networking capabilities, including:
o Overlay and VLAN-backed segments
o Tier-0 and Tier-1 gateways
o Distributed routing and centralized services
o NSX Edge Nodes and Edge clusters
o BGP, static routing, ECMP, and route redistribution
o Distributed Firewall and Gateway Firewall
o Security groups, dynamic membership, tagging, and policy automation
o North-south and east-west traffic design
o VPN, NAT, load-balancing, DHCP, DNS forwarding, and other NSX
services as applicable
o NSX Manager clustering, backups, certificates, upgrades, and
recovery procedures
- Strong understanding of enterprise networking fundamentals,
including TCP/IP, DNS, DHCP, ARP, VLANs, VXLAN/Geneve, MTU, routing,
BGP, OSPF, VRFs, link aggregation, firewalling, NAT, load balancing,
and network troubleshooting.
- Hands-on experience operating in DoD, federal civilian, intelligence
community, or other heavily regulated environments with formal change
control, documentation, security approval, and audit requirements.
- Working knowledge of DoD cybersecurity processes and terminology,
including RMF, ATO, STIGs, POA&Ms, vulnerability management, DISA
guidance, security controls, and continuous monitoring.
- Ability to review, interpret, and remediate applicable DISA STIGs
and security findings for VMware components, operating systems, and
supporting infrastructure.
- Strong written and verbal communication skills, including the
ability to create technical diagrams, implementation plans, security
documentation, standard operating procedures, and executive-ready
status updates.
Required certifications
The final certification requirement should align with the contract’s
assigned DoD Cyber Workforce Framework role and component-specific
guidance. A practical baseline for this role is:
- Current CompTIA Security+ CE or another approved DoD 8140-aligned
baseline certification appropriate to the assigned work role.
- One current VMware/Broadcom networking, security, or
cloud-foundation certification, such as:
o VMware Certified Professional – Network Virtualization / VCP-NV, if
held and applicable
o VMware Certified Professional – VMware Cloud Foundation
Administrator
o VMware Certified Professional – VMware Cloud Foundation Architect
o Comparable current Broadcom/VMware certification focused on NSX, VCF
networking, or network virtualization
Desired:
- 5+ years of enterprise network virtualization, virtual
infrastructure, network security, or cloud-platform engineering
experience.
- Experience designing or supporting VMware Cloud Foundation
environments, including VCF lifecycle management, SDDC Manager,
workload domains, vSphere, and NSX integration.
- Experience integrating NSX with physical enterprise networks,
including Cisco Nexus, Juniper, Palo Alto Networks, F5, or similar
technologies.
- Familiarity with data-center architectures such as VXLAN, BGP
underlay/overlay routing, multi-rack design, and high-availability
network services.
- Experience with automation and infrastructure as code using
PowerShell/PowerCLI, Ansible, VMware Aria Automation, REST APIs, Git,
YAML, and JSON.
- Experience integrating NSX telemetry and logs with Splunk and
Elastic.
- Experience with enterprise PKI, certificate lifecycle management,
Active Directory, LDAP, identity federation, RBAC, privileged-access
management, and multifactor authentication.
- Experience supporting disconnected, air-gapped, tactical edge, or
classified environments.
- Experience with Dell PowerEdge, Cisco UCS, HPE and storage/network
performance troubleshooting.
- Familiarity with DISA STIG Viewer, SCAP scanning, ACAS/Nessus and
POA&M remediation workflows.
Education:
Bachelors Degree in Computer Science or a related field
ATR is an Equal Opportunity Employer (EOE) who will provide equal
employment opportunity to employees and applicants for employment
without regard to race, ethnicity, religion, color, sex, pregnancy,
national origin, age, veteran status, ancestry, sexual orientation,
gender identity or expression, marital status, family structure, genetic
information, or mental or physical disability
First Name
Required
Last Name
Required
Email Address
Required
Phone Number
CountryNoneAfghanistanÅland IslandsAlbaniaAlgeriaAmerican SamoaAndorraAngolaAnguillaAntarcticaAntigua and BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelarusBelgiumBelizeBeninBermudaBhutanBoliviaBonaire, Sint Eustatius and SabaBosnia and HerzegovinaBotswanaBouvet IslandBrazilBritish Indian Ocean TerritoryBritish Virgin IslandsBruneiBulgariaBurkina FasoBurundiCabo VerdeCambodiaCameroonCanadaCayman IslandsCentral African RepublicChadChileChinaChristmas IslandCocos (Keeling) IslandsColombiaComorosCongoCongo-BrazzavilleCook IslandsCosta RicaCôte d'IvoireCroatiaCubaCuraçaoCyprusCzechiaDemocratic People's Republic of KoreaDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEthiopiaFalkland IslandsFaroe IslandsFederated States of MicronesiaFijiFinlandFranceFrench GuianaFrench PolynesiaFrench Southern TerritoriesGabonGambiaGeorgiaGermanyGhanaGibraltarGreeceGreenlandGrenadaGuadeloupeGuamGuatemalaGuernseyGuineaGuinea-BissauGuyanaHaitiHeard Island and McDonald IslandsHondurasHong KongHungaryIcelandIndiaIndonesiaIraqIrelandIslamic Republic of IranIsle of ManIsraelItalyJamaicaJapanJerseyJordanKazakhstanKenyaKiribatiKuwaitKyrgyzstanLao People's Democratic RepublicLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMacedoniaMadagascarMalawiMalaysiaMaldivesMaliMaltaMarshall IslandsMartiniqueMauritaniaMauritiusMayotteMexicoMonacoMongoliaMontenegroMontserratMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNew CaledoniaNew ZealandNicaraguaNigerNigeriaNiueNorfolk IslandNorthern Mariana IslandsNorwayOmanPakistanPalauPanamaPapua New GuineaParaguayPeruPhilippinesPitcairnPolandPortugalPuerto RicoQatarRepublic of KoreaRepublic of MoldovaReunionRomaniaRussiaRwandaSaint BarthelemySaint Helena, Ascension and Tristan da CunhaSaint Kitts and NevisSaint LuciaSaint MartinSaint Pierre and MiquelonSaint Vincent and the GrenadinesSamoaSan MarinoSao Tome and PrincipeSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSint Maarten (Dutch part)SlovakiaSloveniaSolomon IslandsSomaliaSouth AfricaSouth Georgia and the South Sandwich IslandsSouth SudanSpainSri LankaState of PalestineSudanSurinameSvalbard and Jan MayenSwazilandSwedenSwitzerlandSyriaTaiwanTajikistanThailandTimor-LesteTogoTokelauTongaTrinidad and TobagoTunisiaTurkeyTurkmenistanTurks and Caicos IslandsTuvaluU.S. Virgin IslandsUgandaUkraineUnited Arab EmiratesUnited KingdomUnited Republic of TanzaniaUnited StatesUnited States Minor Outlying IslandsUruguayUzbekistanVanuatuVaticanVenezuelaVietnamWallis and FutunaWestern SaharaYemenZambiaZimbabwe
State/ProvinceNoneAlabamaAlaskaArizonaArkansasCaliforniaColoradoConnecticutDelawareFloridaGeorgiaHawaiiIdahoIllinoisIndianaIowaKansasKentuckyLouisianaMaineMarylandMassachusettsMichiganMinnesotaMississippiMissouriMontanaNebraskaNevadaNew HampshireNew JerseyNew MexicoNew YorkNorth CarolinaNorth DakotaOhioOklahomaOregonPennsylvaniaRhode IslandSouth CarolinaSouth DakotaTennesseeTexasUtahVermontVirginiaWashingtonWashington, D.C.West VirginiaWisconsinWyoming
City
ZIP/Postal Code
Resume
Choose File...
Required, maximum file size is 512KB, allowed file types are doc, docx, pdf, odf, and txt
Message
Success!
Your application was successfully sent!
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Engineer IVFairfax County · FAIRFAX (EJ32), VA · $89–155K/yrPosted 3 days agoPosted 3 days ago
Senior Engineer, Operations Analyst (R5831)Shield AI · Washington, DC · $128–192K/yrPosted 6 days agoPosted 6 days ago
Senior Engineer - Quantum Error Correction LibrariesNVIDIA · Santa Clara, CA (Hybrid) · $184–357K/yrPosted 3w agoPosted 3w ago
General EngineerDefense Logistics Agency · Fort Belvoir, VA · $122–158K/yrPosted todayPosted today
Senior Engineer, Human Machine Teaming (R5649)Shield AI · Washington, DC · $140–210K/yrPosted 3w agoPosted 3w ago
You've read the whole posting — now see how you match it.