Technical Skills Technical domain Required capability NSX architecture Design and operate NSX Manager clusters, transport zones, transport nodes, Edge clusters, segments, gateways, and security policies Routing Troubleshoot and configure BGP, static routes, ECMP, route redistribution, Tier-0/Tier-1 routing, and physical-network integration Network security Implement microsegmentation, Distributed Firewall, Gateway Firewall, dynamic groups, tagging, rule analysis, and least-privilege policies vSphere Deep vCenter, ESXi, VDS, VMkernel, vmnic, port-group, cluster, and host-networking knowledge Troubleshooting Use traceflow, NSX CLI, ESXi packet capture, flow data, logs, BGP diagnostics, and packet-level analysis Operations Execute upgrades, backup/recovery, certificate replacement, lifecycle management, and maintenance-window changes DoD compliance Support RMF, STIGs, ATO packages, vulnerability remediation, change control, audit evidence, and continuous monitoring Automation Build repeatable workflows using PowerCLI, Ansible, REST APIs, Git, or equivalent tooling Documentation Produce and maintain diagrams, runbooks, firewall matrices, test plans and backout plans Engineer and maintain NSX management, control, and data planes, including NSX Managers, transport nodes, transport node profiles, host and edge transport zones, uplink profiles, N-VDS or VDS-backed configurations as applicable, and NSX Edge clusters.