Senior NSX Engineer

Abile Group, Inc.•Springfield, VA
•Onsite

About The Position

Abile Group has an exciting and challenging opportunity for a Senior NSX Engineer on a 10 year contract providing User Facing and Data Center Services supporting an Intelligence Community customer. All the personnel on the team will work together to support innovative design, engineering, procurement, implementation, operations, sustainment and disposal of user facing and data center information technology (IT) services on multiple networks and security domains, at multiple locations worldwide, to support the IC mission. The right candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.

Requirements

  • Clearance Required: TS/SCI with current CI Poly.
  • Bachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related discipline; equivalent relevant experience may be substituted.
  • 5+ years of hands-on VMware NSX experience in enterprise-scale environments.
  • 5+ years of VMware vSphere experience, including ESXi, vCenter Server, VDS, virtual networking, cluster operations, and troubleshooting.
  • 8140.01M IAT Level II certification.
  • Certification requirements should align with the assigned DoW Cyber Workforce Framework / DoW 8140 work role and applicable contract requirements.
  • One current VMware/Broadcom networking, security, or VMware Cloud Foundation certification, such as VCP-NV, VMware Cloud Foundation Administrator, VMware Cloud Foundation Architect, or a comparable current NSX/VCF networking certification.
  • Advanced NSX-T / VCF Networking expertise: overlay/VLAN segments, Tier-0/Tier-1 gateways, Edge Nodes/clusters, BGP, static routing, ECMP, route redistribution, Distributed Firewall, Gateway Firewall, dynamic groups/tagging, NAT, VPN, DHCP, and lifecycle operations.
  • Strong enterprise networking fundamentals: TCP/IP, DNS, DHCP, ARP, VLANs, VXLAN/Geneve, MTU, BGP, OSPF, VRFs, link aggregation, firewalling, NAT, load balancing, and network troubleshooting.
  • Experience in DoW, federal civilian, intelligence community, or other highly regulated environments with formal change control, security approval, documentation, and audit requirements.
  • Working knowledge of RMF, ATO, DISA STIGs, POA&Ms, vulnerability management, security controls, continuous monitoring, and remediation of applicable security findings
  • Strong written and verbal communication skills, including technical diagrams, implementation plans, SOPs, security documentation, and executive-ready status updates.

Nice To Haves

  • Experience designing or supporting VMware Cloud Foundation, including SDDC Manager, workload domains, lifecycle management, vSphere, and NSX integration.
  • Experience with VXLAN/Geneve overlays, BGP underlay/overlay routing, multi-rack architectures, and highly available network services.
  • Automation / Infrastructure as Code experience using PowerShell/PowerCLI, Ansible, VMware Aria Automation, REST APIs, Git, YAML, and JSON.
  • Experience integrating NSX telemetry and logs with Splunk, Elastic, or comparable SIEM/observability platforms.
  • Experience with enterprise PKI, certificate lifecycle management, Active Directory, LDAP, identity federation, RBAC, privileged-access management, and MFA.
  • Experience supporting classified, disconnected, air-gapped, or tactical-edge environments.
  • Familiarity with Dell PowerEdge, Cisco UCS, HPE, DISA STIG Viewer, SCAP scanning, ACAS/Nessus, and POA&M remediation workflows.
  • Experience integrating NSX with Cisco Nexus, Juniper, Palo Alto Networks, F5, or similar enterprise technologies.

Responsibilities

  • Designs, deploys, configures, operates, and sustains VMware NSX-T / VMware Cloud Foundation Networking across production, development, test, and mission environments.
  • Engineers NSX Manager clusters, transport nodes/profiles, transport zones, uplink profiles, VDS/N-VDS networking, and NSX Edge clusters.
  • Designs and administers overlay and VLAN-backed segments, Tier-0/Tier-1 gateways, distributed routing, BGP, static routing, ECMP, route redistribution, and north-south/east-west connectivity.
  • Implements microsegmentation and Zero Trust-aligned controls using Distributed Firewall, Gateway Firewall, security groups, dynamic membership, tags, context profiles, and policy-based security.
  • Develops auditable, least-privilege firewall policies in coordination with cybersecurity, ISSO/ISSM, RMF, application, and network teams.
  • Integrates NSX with vCenter, vSphere, VCF, vSAN, VMware Aria Operations/Logs, PKI, identity, SIEM, vulnerability-management, and enterprise monitoring platforms.
  • Troubleshoots BGP/routing adjacency failures, MTU/TEP/Geneve issues, asymmetric routing, firewall processing, packet loss, performance degradation, and NSX Edge failures.
  • Performs packet-level analysis using NSX CLI/nsxcli, vmkping, pktcap-uw, tcpdump-uw, Traceflow, flow monitoring, and distributed firewall analysis.
  • Leads NSX upgrades, patching, certificate replacement, migrations, backup/recovery validation, and lifecycle-management activities with formal implementation, test, validation, and backout plans.
  • Maintains engineering standards, configuration baselines, diagrams, firewall matrices, runbooks, and as-built documentation; provide Tier 3 escalation support and mentor junior engineers.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service