Role Overview:The NSX Security Engineer is responsible for the architecture, deployment, configuration, and day-to-day administration of network virtualization and security policies within our VMware infrastructure. This role bridges the gap between traditional networking, cloud infrastructure, and cybersecurity. The primary objective is to enforce a zero-trust network posture by configuring advanced logical routing, distributed firewalls, and micro-segmentation strategies across hybrid cloud workloads.
Key Responsibilities:- Design and enforce granular distributed firewall (DFW) and Gateway Firewall rules. Isolate virtual machines and applications to prevent lateral "east-west" threat propagation.
- Deploy and manage logical switching, tier-0/tier-1 routing, distributed load balancers, and VPNs within VMware NSX environments.
- Handle regular maintenance, component scaling, software upgrades, patches, and configurations of NSX Managers, Edge Nodes, and Transport Nodes.
- Develop infrastructure-as-code (IaC) and automation scripts to streamline security rule deployment and ensure consistent disaster recovery readiness.
- Audit infrastructure health, capacity, and security event logs utilizing tools like VMware Aria Operations (formerly vRealize), Network Insight, or third-party SIEM platforms like Splunk.
- Work alongside systems engineers, traditional network administrators, and the Security Operations Center (SOC) to troubleshoot physical-to-virtual network overlays.
- Assist security incident teams by performing deep-packet inspection, tracing network flows, and applying emergency isolation rules during an active breach.
Required Skills:- VMware Ecosystem: Deep hands-on experience with VMware vSphere, ESXi, vCenter, and comprehensive NSX-T/NSX architecture.
- Core Networking Protocols: Expert-level knowledge of BGP, OSPF, Geneve/VXLAN overlay encapsulation, VLANs, and TCP/IP stack.
- Firewalling & Security: Strong understanding of Layer 4-7 firewall rules, intrusion detection/prevention systems (IDS/IPS), and zero-trust concepts.
- Automation/Scripting: Proficiency with PowerShell/PowerCLI, Python, Terraform, or interacting directly with NSX REST APIs.
- Third-Party Integration: Familiarity with integrating NSX with physical next-gen firewalls (e.g., Palo Alto Networks, Check Point) or cloud networking environments like AWS and Azure.
Qualifications:Preferred Skills:- VMware Certified Professional Network Virtualization (VCP-NV)
- VMware Certified Advanced Professional Network Virtualization (VCAP-NV Design or Deploy)
- Cisco Certified Network Associate (CCNA) or Professional (CCNP)