Flexon Technologies Talent360.ai logo

VMware NSX Security Engineer

Flexon Technologies Talent360.ai

On-siteSpring, TXmidPosted 1h ago

Job description

Job Summary:

The NSX Security Engineer is responsible for the architecture| deployment| configuration| and day-to-day administration of network virtualization and security policies within our VMware infrastructure.

This role bridges the gap between traditional networking| cloud infrastructure| and cybersecurity.

The primary objective is to enforce a zero-trust network posture by configuring advanced logical routing| distributed firewalls| and micro-segmentation strategies across hybrid cloud workloads.

Key Responsibilities:

Security Architecture & Micro-segmentation: Design and enforce granular distributed firewall (DFW) and Gateway Firewall rules. Isolate virtual machines and applications to prevent lateral "east-west" threat propagation.

Network Virtualization Management: Deploy and manage logical switching| tier-0/tier-1 routing| distributed load balancers| and VPNs within VMware NSX environments.

Lifecycle Management: Handle regular maintenance| component scaling| software upgrades| patches| and configurations of NSX Managers| Edge Nodes| and Transport Nodes.

Infrastructure Automation: Develop infrastructure-as-code (IaC) and automation scripts to streamline security rule deployment and ensure consistent disaster recovery readiness.

Monitoring & Log Analysis: Audit infrastructure health| capacity| and security event logs utilizing tools like VMware Aria Operations (formerly vRealize)| Network Insight| or third-party SIEM platforms like Splunk.

Cross-Team Collaboration: Work alongside systems engineers| traditional network administrators| and the Security Operations Center (SOC) to troubleshoot physical-to-virtual network overlays.

Incident Response Support: Assist security incident teams by performing deep-packet inspection| tracing network flows| and applying emergency isolation rules during an active breach.

Technical Requirements & Skills VMware Ecosystem: Deep hands-on experience with VMware vSphere| ESXi| vCenter| and comprehensive NSX-T/NSX architecture.

Core Networking Protocols: Expert-level knowledge of BGP| OSPF| Geneve/VXLAN overlay encapsulation| VLANs| and TCP/IP stack.

Firewalling & Security: Strong understanding of Layer 4-7 firewall rules| intrusion detection/prevention systems (IDS/IPS)| and zero-trust concepts.

Automation/Scripting: Proficiency with PowerShell/PowerCLI| Python| Terraform| or interacting directly with NSX REST APIs.

Third-Party Integration: Familiarity with integrating NSX with physical next-gen firewalls (e.g.| Palo Alto Networks| Check Point) or cloud networking environments like AWS and Azure.

Preferred Certifications:

VMware Certified Professional Network Virtualization (VCP-NV)VMware Certified Advanced Professional Network Virtualization (VCAP-NV Design or Deploy)

Cisco Certified Network Associate (CCNA) or Professional (CCNP) [1| 2]